Threat Spotlight: How 'Text Salting' Confuses AI-Powered Email Defenses
Barracuda Networks, Thursday, July 16th, 2026
Barracuda researchers detected over one million phishing attacks using hidden 'text salting' to evade AI email security.
Barracuda researchers identified more than one million phishing attacks using text-salting techniques designed to deceive both conventional and AI-based email security systems.
The evasion method hides benign filler text within emails to dilute suspicious keywords while still displaying phishing content to recipients, exploiting the fact that AI models process raw source code rather than user-visible content.
Attackers use CSS styling to push text off-screen and zero-font techniques to conceal characters, making detection difficult even when tools try to expose hidden content.
Barracuda recommends layered defenses that analyze message structure, sender reputation, authentication results, and the gap between visible and underlying email code, supplemented by security awareness training.