Threat · curated 16 Jul 2026
1M+ Emails Use Hidden Text to Dupe AI Security Filters
First reported · updated · 3 reports darkreading.com
Coverage timeline
Why it matters
Text salting demonstrates that AI-powered email defenses can be reliably fooled by hidden-text manipulation, meaning defenders must analyze what users actually see rather than raw source code to catch these evasive phishing campaigns.
Barracuda researchers observed more than one million retail-themed phishing emails since April 2026 that use 'text salting' — hidden text inserted into messages — to evade both traditional and AI-powered email security filters. The hidden content dilutes malicious signals and manipulates how AI/LLM-based content analysis engines interpret the email, while generative AI lets attackers produce cheap, varied salting campaigns at scale.