Executive Summary
Since April 2026, Barracuda Networks has identified over one million phishing emails employing 'text salting' techniques to evade both traditional and AI-powered email security filters. These emails, often retail-themed, use hidden text within their HTML code to manipulate security gateways, allowing malicious content to bypass detection and reach users' inboxes. (darkreading.com)
The resurgence of text salting, facilitated by large language models (LLMs), highlights the evolving sophistication of phishing attacks. This trend underscores the need for advanced security measures capable of analyzing the full context of email content, including hidden elements, to effectively combat such evasive tactics. (blog.barracuda.com)
Why This Matters Now
The increasing use of AI by cybercriminals to enhance phishing techniques like text salting poses a significant threat to current email security systems. Organizations must adapt by implementing more sophisticated detection methods to protect against these evolving attacks. (cyberdaily.au)
Attack Path Analysis
Attackers utilized text salting techniques to bypass AI-based email security filters, leading to successful phishing attacks. This initial compromise allowed them to gain unauthorized access to user accounts. Subsequently, they escalated privileges by exploiting misconfigurations or weak credentials. The attackers then moved laterally within the network to access sensitive data. They established command and control channels to maintain persistent access. Finally, they exfiltrated data and caused significant impact by disrupting business operations.
Kill Chain Progression
Initial Compromise
Description
Attackers used text salting techniques to evade AI-based email security filters, leading to successful phishing attacks.
MITRE ATT&CK® Techniques
Email Hiding Rules
Obfuscated Files or Information: Invisible Unicode
Phishing: Spearphishing Link
Masquerading
User Execution: Malicious Link
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Malicious Software Prevention Mechanisms
Control ID: 5.1.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 6
CISA ZTMM 2.0 – Email Security
Control ID: 3.1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
Email security evasion via text salting threatens customer communications, enabling phishing attacks that bypass AI filters to compromise financial accounts and sensitive data.
Health Care / Life Sciences
Hidden text techniques in phishing emails can evade healthcare security gateways, exposing patient data and violating HIPAA compliance requirements through compromised communications.
Retail Industry
Retail-themed phishing campaigns using text salting specifically target this sector, exploiting brand impersonation to steal customer credentials and payment information through AI filter evasion.
Computer Software/Engineering
Software organizations face elevated risk as attackers leverage AI/LLMs to enhance text salting techniques while their own AI-powered security solutions prove inadequate against these attacks.
Sources
- 1M+ Emails Use Hidden Text to Dupe AI Security Filtershttps://www.darkreading.com/threat-intelligence/1m-emails-hidden-text-dupe-ai-security-filtersVerified
- Threat Spotlight: How ‘text salting’ confuses AI-powered email defenseshttps://blog.barracuda.com/2026/07/16/text-salting-ai-email-securityVerified
- Barracuda warns of AI-era resurgence in ‘text salting’ phishing attackshttps://www.cyberdaily.au/security/13919-barracuda-warns-of-ai-era-resurgence-in-text-salting-phishing-attacksVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it likely limits the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and identity-aware policies.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: While Aviatrix Zero Trust CNSF may not prevent initial phishing attacks, it could likely limit the attacker's subsequent network access.
Control: Zero Trust Segmentation
Mitigation: Zero Trust Segmentation would likely limit the attacker's ability to escalate privileges by enforcing strict access controls.
Control: East-West Traffic Security
Mitigation: East-West Traffic Security would likely limit lateral movement by restricting unauthorized inter-workload communications.
Control: Multicloud Visibility & Control
Mitigation: Multicloud Visibility & Control would likely limit the establishment of command and control channels by monitoring and controlling outbound communications.
Control: Egress Security & Policy Enforcement
Mitigation: Egress Security & Policy Enforcement would likely limit data exfiltration by controlling and monitoring outbound data flows.
While Aviatrix Zero Trust CNSF may not prevent all disruptions, it could likely limit the scope and severity of the impact by containing the attacker's reach.
Impact at a Glance
Affected Business Functions
- Email Communication
- Customer Support
- Internal Collaboration
Estimated downtime: N/A
Estimated loss: N/A
Potential exposure of sensitive information through successful phishing attacks, including credentials and personal data.
Recommended Actions
Key Takeaways & Next Steps
- • Implement advanced email filtering techniques to detect and block text salting methods used in phishing attacks.
- • Enforce strict access controls and regularly audit user privileges to prevent unauthorized privilege escalation.
- • Deploy network segmentation to limit lateral movement within the network.
- • Monitor network traffic for unusual patterns to detect and disrupt command and control channels.
- • Establish data loss prevention measures to prevent unauthorized data exfiltration.



