Skip to content

Invisible Text in Phishing Emails Bypasses AI Protection Systems

In a nutshell: Attackers use invisible text embedding to evade AI-based email filters and deceive phishing detection models.

Attackers hide random character strings in phishing emails using invisible text (text salting) to deceive AI-powered email filters and bypass detection.

The technique is based on a simple method: attackers set the font size of text to zero and embed random text in the email. This text is invisible to human readers, but is processed by mail systems and their AI models.

AI-powered protection systems analyze email content to identify phishing, malware, and spam. By embedding noise text or randomly generated words, the model becomes confused: the classification of suspicious content becomes difficult or fails because the statistical signature of the message changes.

For CISOs, this means that pure AI filters are insufficient. The security of email systems depends on implementing multi-layered controls — such as sender authentication (SPF, DKIM, DMARC), sandbox analysis of suspicious attachments, and training users to recognize phishing indicators that go beyond content scanning.


Source: itwelt.at · Published 17 July 2026
Lumi AI News — AI-assisted curation pursuant to Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: