← Back to Feed

1M+ Emails Use Hidden Text to Dupe AI Security Filters

July 16, 2026 · Dark Reading · Severity: LOW

Over one million emails used hidden text salting techniques to deceive AI-powered security filters, exploiting a surprising weakness in LLMs and AI-based email security systems. Text salting involves embedding invisible or near-invisible characters, zero-width spaces, homoglyphs, or semantically irrelevant text within email content that confuses AI classifiers while remaining visually acceptable to human readers. The massive scale of this campaign demonstrates that attackers have identified and are actively exploiting fundamental limitations in how AI models process text — they can be surprisingly ineffective at distinguishing meaningful content from strategically injected noise.

Key Takeaways

  • Over one million emails used hidden text salting to bypass AI-powered email security filters at scale.
  • Text salting uses zero-width characters, homoglyphs, and invisible text that confuses AI classifiers but not humans.
  • AI models and LLMs can be surprisingly ineffective at distinguishing meaningful content from injected noise.
  • The massive scale proves attackers have identified and operationalized a fundamental AI text processing weakness.
  • Email security vendors must train models to recognize and strip adversarial text perturbations in email content.
☕ Buy a Coffee