Threat · curated 16 Jul 2026
Text salting: How hidden text evades AI email security
First reported · updated · 2 reports barracuda.com
Coverage timeline
Why it matters
Text salting shows that AI-powered email defenses can be systematically evaded by manipulating the raw content LLMs analyze, letting phishing slide into inboxes unless filters analyze what users actually see rather than the raw source.
Barracuda researchers report more than one million retail-themed phishing emails since April that use 'text salting' — hidden, harmless-looking text invisible to recipients but readable by scanners — to dilute malicious signals and fool both traditional and AI-powered email security filters. Generative AI lets attackers generate these salted campaigns cheaply, at scale, and with high variation, while AI-based content analysis engines fail to see through the hidden content.