Phishing Emails Use Invisible Hyphens to Avoid Detection

KnowBe4 Team | Nov 7, 2025

Phishing Emails Small Font SizeA phishing campaign is using invisible characters to evade security filters, according to Jan Kopriva at the SANS Internet Storm Center.

The emails use soft hyphens to break up the subject line “Your Password is About to Expire” so the messages aren’t flagged as malicious. The email client doesn’t render the hyphens, however, so the user sees a normal sentence. 

“Although soft hyphens aren’t – strictly speaking – invisible, Outlook as well as most other e-mail clients don’t render them as visible text in most cases,” Kopriva writes. “The use of the soft hyphen character – combined with splitting the subject into multiple MIME encoded words – was clearly intended as an attempt at bypassing e-mail filtering mechanisms that are supposed to automatically detect potentially malicious messages.”

In addition to the subject line, the entire email body was littered with these invisible hyphens. While the user reads a normal message asking them to reset their password, automated security systems will see random letters separated by hyphens.

“[A]lthough the use of invisible characters in phishing e-mails in general (and of the use of the ‘shy’ character in particular) is quite common when it comes to making the contents of e-mail messages less readable to security solutions, it is quite unusual to see it also applied to the subject of a message,” Kopriva says.

If the user clicks the link in the email, they’ll be taken to a phony login page designed to steal their email account credentials.

Attackers are always looking for ways to bypass technical security measures in order to target humans directly. AI-powered security awareness training can give your organization an essential layer of defense against social engineering attacks. KnowBe4 empowers your workforce to make smarter security decisions every day. Over 70,000 organizations worldwide trust the KnowBe4 HRM+ platform to strengthen their security culture and reduce human risk.

SANS Internet Storm Center has the story.

Discover Your Organization’s Phish-prone™ Percentage

Ninety-one percent of data breaches begin with spear phishing. Launch our Free Phishing Security Test for up to 100 users to uncover your team's vulnerability and see how your security posture stacks up against industry benchmarks.

Get Your Free Phishing Security Test

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.