Visual Link Masking in 2026: How “l” and “I” Are Used in Phishing Attacks(Fake Slash)
Learn about the return of visual link masking techniques in 2026. Discover how attackers use the letters “l” and “I” to create deceptive, non-clickable links. Essential tips for training users on link safety and phishing prevention.
Fake Slash
An obvious way to visually mask text-based anchorless links has resurfaced in 2026! The trick is that users see a link in an email, but it’s not clickable — they have to copy and paste it into a browser.
We use the letter “l” (lowercase L) and “I” (uppercase i), combined with italic formatting.
Try to visually identify which of these links actually contains a slash:

Since it’s nearly impossible to tell the difference, train your users to check links both before and after clicking them.
Read other articles>>>
https://advisor-bm.com/resources