• Loading ...
  • Loading ...

Attractions Sydney

Latest News Attractions Sydney

Are you looking for a holiday? Get special deals.

 

New email scam uses hidden characters to slip past filters

03 Dec 2025 By foxnews

New email scam uses hidden characters to slip past filters

Cybercriminals keep finding new angles to get your attention, and email remains one of their favorite tools. Over the years, you have probably seen everything from fake courier notices to AI-generated scams that feel surprisingly polished. Filters have improved, but attackers have learned to adapt. The latest technique takes aim at something you rarely think about: the subject line itself. Researchers have found a method that hides tiny, invisible characters inside the subject so automated systems fail to flag the message. It sounds subtle, but it is quickly becoming a serious problem.

Sign up for my FREE CyberGuy Report
Get my best tech tips, urgent security alerts, and exclusive deals delivered straight to your inbox. Plus, you'll get instant access to my Ultimate Scam Survival Guide - free when you join my CYBERGUY.COM newsletter.

NEW SCAM SENDS FAKE MICROSOFT 365 LOGIN PAGES

Researchers recently uncovered phishing campaigns that embed soft hyphens between every letter of an email subject. These are invisible Unicode characters that normally help with text formatting. They do not show up in your inbox, but they completely throw off keyword-based filters. Attackers use MIME encoded-word formatting to slip these characters into the subject. By encoding it in UTF-8 and Base64, they can weave these hidden characters through the entire phrase.

One analyzed email decoded to "Your Password is About to Expire" with a soft hyphen tucked between every character. To you, it looks normal. To a security filter, it looks scrambled, with no clear keyword to match. The attackers then use the same trick in the body of the email, so both layers slide through detection. The link leads to a fake login page sitting on a compromised domain, designed to harvest your credentials.

If you have ever tried spotting a phishing email, this one still follows the usual script. It builds urgency, claims something is about to expire and points you to a login page. The difference is in how neatly it dodges the filters you trust.

Why this phishing technique is super dangerous

Most phishing filters rely on pattern recognition. They look for suspicious words, common phrases and structure. They also scan for known malicious domains. By splitting every character with invisible symbols, attackers break up these patterns. The text becomes readable for you but unreadable for automated systems. This creates a quiet loophole where old phishing templates suddenly become effective again.

The worrying part is how easy this method is to copy. The tools needed to encode these messages are widely available. Attackers can automate the process and churn out bulk campaigns with little extra effort. Since the characters are invisible in most email clients, even tech-savvy users do not notice anything odd at first glance.

Security researchers point out that this method has appeared in email bodies for years, but using it in the subject line is less common. That makes it harder for existing filters to catch. Subject lines also play a key role in shaping your first impression. If the subject looks familiar and urgent, you are more likely to open the email, which gives the attacker a head start.

Phishing emails often look legitimate, but the links inside them tell a different story. Scammers hide dangerous URLs behind familiar-looking text, hoping you will click without checking. One safe way to preview a link is by using a private email service that shows the real destination before your browser loads it.

Our top-rated private email provider recommendation includes malicious link protection that reveals full URLs before opening them. This gives you a clear view of where a link leads before anything can harm your device. It also offers strong privacy features like no ads, no tracking, encrypted messages and unlimited disposable aliases.

For recommendations on private and secure email providers, visit Cyberguy.com

PAYROLL SCAM HITS US UNIVERSITIES AS PHISHING WAVE TRICKS STAFF

You do not need to become a security expert to stay safe. A few habits, paired with the right tools, can shut down most phishing attempts before they have a chance to work.

A password manager helps you create strong, unique passwords for every account. Even if a phishing email fools you, the attacker cannot use your password elsewhere because each one is different. Most password managers also warn you when a site looks suspicious.

Next, see if your email has been exposed in past breaches. Our #1 password manager (see Cyberguy.com) pick includes a built-in breach scanner that checks whether your email address or passwords have appeared in known leaks. If you discover a match, immediately change any reused passwords and secure those accounts with new, unique credentials. 

Check out the best expert-reviewed password managers of 2025 at Cyberguy.com.

Turning on 2FA adds a second step to your login process. Even if someone steals your password, they still need the verification code on your phone. This stops most phishing attempts from going any further.

Strong antivirus software does more than scan for malware. Many can flag unsafe pages, block suspicious redirects and warn you before you enter your details on a fake login page. It is a simple layer of protection that helps a lot when an email slips past filters.

The best way to safeguard yourself from malicious links that install malware, potentially accessing your private information, is to have strong antivirus software installed on all your devices. This protection can also alert you to phishing emails and ransomware scams, keeping your personal information and digital assets safe.

Get my picks for the best 2025 antivirus protection winners for your Windows, Mac, Android & iOS devices at Cyberguy.com.

Attackers often tailor phishing messages using information they find about you. Reducing your digital footprint makes it harder for them to craft emails that feel convincing. You can use personal data removal services to clean up exposed details and old database leaks.

While no service can guarantee the complete removal of your data from the internet, a data removal service is really a smart choice. They aren't cheap, and neither is your privacy. These services do all the work for you by actively monitoring and systematically erasing your personal information from hundreds of websites. It's what gives me peace of mind and has proven to be the most effective way to erase your personal data from the internet. By limiting the information available, you reduce the risk of scammers cross-referencing data from breaches with information they might find on the dark web, making it harder for them to target you.

AI FLAW LEAKED GMAIL DATA BEFORE OPENAI PATCH

Check out my top picks for data removal services and get a free scan to find out if your personal information is already out on the web by visiting Cyberguy.com.

Get a free scan to find out if your personal information is already out on the web: Cyberguy.com

Do not rely on the display name. Always check the full email address. Attackers often tweak domain names by a single letter or symbol. If something feels off, open the site manually instead of clicking any link inside the email.

If you get an email claiming your password will expire, do not click the link. Go to the website directly and check your account settings. Phishing emails rely on urgency. Slowing down and confirming the issue yourself removes that pressure.

Updates often include security fixes that help block malicious scripts and unsafe redirects. Attackers take advantage of older systems because they are easier to trick. Staying updated keeps you ahead of known weaknesses.

Many email providers (Gmail, Outlook, Yahoo) allow you to tighten spam filtering settings. This won't catch every soft-hyphen scam, but it improves your odds and reduces risky emails overall.

Chrome, Safari, Firefox, Brave, and Edge all include anti-phishing checks. This adds another safety net if you accidentally click a bad link.

Phishing attacks are changing fast, and tricks like invisible characters show how creative attackers are getting. It's safe to say filters and scanners are also improving, but they cannot catch everything, especially when the text they see is not the same as what you see. Staying safe comes down to a mix of good habits, the right tools, and a little skepticism whenever an email pushes you to act quickly. If you slow down, double-check the details, and follow the steps that strengthen your accounts, you make it much harder for anyone to fool you.

Do you trust your email filters, or do you double-check suspicious messages yourself? Let us know by writing to us at Cyberguy.com.

Sign up for my FREE CyberGuy Report
Get my best tech tips, urgent security alerts, and exclusive deals delivered straight to your inbox. Plus, you'll get instant access to my Ultimate Scam Survival Guide - free when you join my CYBERGUY.COM newsletter.

Copyright 2025 CyberGuy.com.  All rights reserved.

More News

Booking.com
Smart glasses detector app warns if you're being recorded
Smart glasses detector app warns if you're being recorded
Archaeologists uncover lost medieval city that vanished without a trace: 'True time capsule'
Archaeologists uncover lost medieval city that vanished without a trace: 'True time capsule'
Alec Baldwin's wife turns to Instagram after $20M Hamptons home sits unsold for years
Alec Baldwin's wife turns to Instagram after $20M Hamptons home sits unsold for years
Costco brings back churros, yet shoppers say new version is a 'slap in the face'
Costco brings back churros, yet shoppers say new version is a 'slap in the face'
Bedbug nightmare spreading across South as cases surge in multiple states
Bedbug nightmare spreading across South as cases surge in multiple states
Bryson DeChambeau wins LIV Golf Singapore event, surviving bunker fall and agonizing playoff
Bryson DeChambeau wins LIV Golf Singapore event, surviving bunker fall and agonizing playoff
Whiskey mogul offers free $200M college campus to religious groups, with one major catch
Whiskey mogul offers free $200M college campus to religious groups, with one major catch
California Baptist punches NCAA Tournament ticket as Utah Valley suffers heartbreak
California Baptist punches NCAA Tournament ticket as Utah Valley suffers heartbreak
Mamdani defends wife when confronted on work with anti-Israel author, decries rhetoric
Mamdani defends wife when confronted on work with anti-Israel author, decries rhetoric
US could take Iran's main oil export hub 'at a time of our choosing,' Jack Keane says
US could take Iran's main oil export hub 'at a time of our choosing,' Jack Keane says
Ex-NFL star Troy Aikman drops theory about cause of early season injuries
Ex-NFL star Troy Aikman drops theory about cause of early season injuries
Prince William honors Princess Diana with never-before-seen childhood photo on UK Mother's Day tribute
Prince William honors Princess Diana with never-before-seen childhood photo on UK Mother's Day tribute
DAVID MARCUS: In an age of broken institutions, the filibuster is one relic we can't afford
DAVID MARCUS: In an age of broken institutions, the filibuster is one relic we can't afford
Common vitamin could bring relief from long COVID symptoms, study suggests
Common vitamin could bring relief from long COVID symptoms, study suggests
Rihanna shooting suspect's disturbing posts emerge as star joins growing celebrity list facing fan threats
Rihanna shooting suspect's disturbing posts emerge as star joins growing celebrity list facing fan threats
Iran arrests dozens accused of spying for Israel in new internal crackdown
Iran arrests dozens accused of spying for Israel in new internal crackdown
FCC chair Brendan Carr warns broadcasters must 'correct course' on 'news distortions' before license renewals
FCC chair Brendan Carr warns broadcasters must 'correct course' on 'news distortions' before license renewals
Tori Spelling sets the record straight on 30 years of plastic surgery rumors
Tori Spelling sets the record straight on 30 years of plastic surgery rumors
Oprah Winfrey fires back at internet trolls mocking her '90-year-old' walk at Paris Fashion Week
Oprah Winfrey fires back at internet trolls mocking her '90-year-old' walk at Paris Fashion Week
CarGurus breach linked to ShinyHunters exposes 12.4M records
CarGurus breach linked to ShinyHunters exposes 12.4M records
Latest News

copyright © 2026 Attractions Sydney.   All rights reserved.

A B C D E F G H I J K L M N O P Q R S T U V W X Y Z