Artificial intelligence and LLMs can be surprisingly ineffective against text salting, allowing phishing emails to slide right into your inbox.
July 16, 2026
Hackers are using simple text salting to evade both static and artificial intelligence-powered email security checks.
Since April, researchers at Barracuda Networks observed more than 1 million retail-themed phishing emails that used hidden text to make malicious social engineering look legit to automated security filters. It's a simple age-old trick that's working better today than ever, thanks to an asymmetric advantage afforded by large language models (LLMs). LLMs are helping attackers salt their phishing emails faster and more effectively than ever, whereas the AI-based content analysis engines they're up against don't seem to be putting up much of a defense.
"Text salting appears simple, but its continued and growing use shows it remains effective," says Peterson Gutierrez, vice president of information security at Barracuda. "A technique many people associate with older spam-filter evasion can also influence modern AI-based detection."









