Threat · curated 16 Jul 2026

Text salting: How hidden text evades AI email security

Coverage timeline

discovered barracuda.com primary 16 Jul 2026darkreading.com 17 Jul 2026theregister.com

Why it matters

Text salting shows that AI-powered email defenses can be systematically evaded by manipulating the raw content LLMs analyze, letting phishing slide into inboxes unless filters analyze what users actually see rather than the raw source.

Barracuda researchers report more than one million retail-themed phishing emails since April that use 'text salting' — hidden, harmless-looking text invisible to recipients but readable by scanners — to dilute malicious signals and fool both traditional and AI-powered email security filters. Generative AI lets attackers generate these salted campaigns cheaply, at scale, and with high variation, while AI-based content analysis engines fail to see through the hidden content.