Skip to content

Over One Million Emails Use Hidden Text to Bypass AI Security Filters

Bottom line: Text-salting techniques enable attackers to circumvent AI-driven email filters by embedding hidden text passages in messages that remain undetected by LLMs.

Over one million emails employ hidden text to deceive AI-based security filters and inject phishing messages into inboxes. AI models and LLMs demonstrate surprising vulnerability to this so-called text-salting technique.

Security researchers have documented that over one million emails use text-salting procedures to outwit AI-based phishing detection systems. This attack method operates with human-invisible or heavily obscured text portions embedded in email content.

The core problem lies in a fundamental weakness of large language models and AI filters: they process text differently than human readers and can therefore be misled by strategically placed, visually hidden text elements. While a human could identify a phishing email based on layout and visual appearance, automated AI filters fail against this tactic.

For security professionals, this means that AI-driven email security alone is insufficient. Text-salting attacks demonstrate that modern security filters must be augmented by multi-layered approaches that do not rely solely on AI text recognition. Complementary techniques such as rendering-based analysis, sender authentication, and user training are gaining importance.


Source: www.darkreading.com · Published 16 July 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification via Lumi News Pipeline v1.7.3.

Share on: