Text-Salting Phish Bypasses AI Email Filters

eSecurity Planet · Medium sophistication
Last updated July 30, 2026

Barracuda reports seeing more than one million retail-themed phishing emails since April that use “text salting,” where attackers hide large amounts of harmless text inside the message to trick automated email security tools. The victim sees a normal-looking urgent lure (like expiring rewards points), while hidden HTML/CSS content changes how some detection engines score the email. The campaign also uses authenticated-looking sending infrastructure (e.g., DKIM) and multiple hiding techniques to improve delivery.

How the attack worked

Barracuda identified more than one million retail-themed phishing emails since April built around a technique called text salting. Recipients see a normal-looking urgent message, often claiming that rewards points, loyalty benefits, or a gift card are about to expire and encouraging immediate action. Behind that visible lure, the email's HTML/CSS contains large blocks of unrelated, benign-looking text that is hidden from the reader but present in the underlying code.

A related variant uses a technique called Zero Font, which inserts random hidden words directly inside a recognizable phishing phrase and sets the inserted text to a font size of zero. For example, the underlying HTML may read "Your pass [hidden text] word expired," while the recipient only sees "Your password expired." The campaign also relies on trusted infrastructure, authenticated domains, hidden HTML content, and CSS concealment techniques to improve delivery and reduce suspicion.

Why it succeeded

These emails work because the two layers of content serve different purposes. The visible layer is a simple, believable, urgent lure tied to something many people actually have, like rewards points or a gift card. The hidden layer is designed purely to manipulate how automated detection engines classify the message. Because some security tools scan the raw HTML or source code rather than what the user actually sees, the extra hidden text or invisible inserted words can throw off pattern-matching and signature-based detection, letting messages that would otherwise be flagged slip through to the inbox. Authenticated-looking sending infrastructure, including DKIM configured on lookalike or compromised domains, adds another layer of apparent legitimacy.

What to watch for

  • Urgent emails about expiring rewards points, loyalty benefits, or gift cards, especially when unrelated to a recent purchase or account activity
  • Generic password-expired notices that are not tied to specific account context
  • Links that may not lead to the retailer's or service's real domain, even when the email itself looks legitimate
  • Any unusual formatting or hidden HTML artifacts if you inspect a suspicious message's source

Building resistance

Employees, especially in customer support and sales roles that regularly handle retail-related email, should verify urgent expiration claims through a separate, trusted channel, such as typing the retailer's URL directly rather than clicking an embedded link. For password-reset or login requests, use a known bookmark or official portal instead of following a link in the email. Security and IT/identity teams should ensure email defenses analyze the message as it actually renders for the recipient, not just the raw HTML or source code, since that is where hidden content like text salting and Zero Font is designed to operate undetected.

Key findings

  • Barracuda identified “more than one million retail-themed phishing emails since April” using text salting.
  • The lure is visible to the user, while “large blocks of unrelated text” are hidden in the email to influence how AI/ML tools classify it.
  • Attackers used “trusted infrastructure, authenticated domains, hidden HTML content, CSS concealment techniques, and Zero Font.”
  • The visible message pushes urgency around “rewards points, loyalty benefits, or gift cards” expiring.
  • Some emails may pass authentication checks because they are configured to pass DKIM on lookalike or compromised infrastructure.

Who’s being targeted

  • Commonly targeted roles: All employees, Customer support, Sales, IT/Identity teams, Security awareness trainees.
  • Affected industries: Retail, All industries using email (cross-industry).
  • Attack channels: email.
  • Impersonated: Retail loyalty/rewards program, Account/identity support (generic).

Red flags to watch for

  • Creates urgency around expiring benefits/gift cards
  • Unexpected rewards/loyalty email not tied to a recent purchase/account
  • Link destination may not match the real retailer, even if the email looks legitimate
  • “Password expired” message is generic and not tied to your actual account context
  • Login/reset links that do not go to the company’s real sign-in domain
  • Email may contain unusual formatting/HTML artifacts if inspected (hidden content tricks)
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What is text salting in phishing emails?

Text salting is a technique where attackers hide large blocks of harmless-looking text inside a phishing email's HTML/CSS to change how automated detection tools score the message, while the visible message the user sees stays the same.

What is Zero Font in phishing emails?

Zero Font is a technique that embeds random hidden words inside recognizable phishing phrases and sets that inserted text to a font size of zero, so it is invisible to the recipient but can confuse signature-based detection scanning the raw HTML.

How many phishing emails used this technique?

Barracuda identified more than one million retail-themed phishing emails since April that used text salting.

How can I spot this kind of phishing attack?

Treat urgent messages about expiring rewards points, loyalty benefits, or gift cards as suspicious, and verify password-reset or login requests through a known bookmark or official portal rather than an embedded link.

Read the video transcript

You get an email: “Your rewards points are about to expire, act now.” It looks totally normal… and it passed all our filters. Behind that one line, the HTML is stuffed with hidden junk text, “text salting,” plus tricks like Zero Font, so AI email filters think it’s harmless while you just see an urgent rewards offer. Barracuda’s already seen over a million of these retail-themed emails since April, some even using authenticated-looking domains so DKIM passes. The only real tell? That “expiring rewards” or “password expired” panic, out of nowhere. If an email says rewards or a password are about to expire, don’t click the email. Type the retailer or account URL yourself and check from there.

Categories

Similar attacks

N0va Device-Code Phish Steals Microsoft Sessions

N0va Device-Code Phish Steals Microsoft Sessions

Researchers reported a real phishing operation (“N0va” phishkit) that tricks people into signing into Microsoft through a legitimate Microsoft page, but for an attacker-started session. Victims can complete MFA and still grant the attacker access and refresh tokens, letting the attacker operate as…

September 11, 2026
DocuSign Phish Uses “Blob” Pages in Your Browser

DocuSign Phish Uses “Blob” Pages in Your Browser

Researchers described a real phishing campaign where victims click through legitimate Microsoft services and end up on a fake login page that is generated inside their own browser. The phishing page uses a temporary “blob URL” (not a normal website) and can disappear after the session, making it…

September 10, 2026
Phish Page Built Inside Your Browser

Phish Page Built Inside Your Browser

Researchers reported a real phishing campaign that uses legitimate Microsoft OAuth and Teams pages to make the journey look trustworthy. Instead of hosting a fake login site on a suspicious domain, the attackers render the phishing page inside the victim’s own browser using a temporary “blob URL,”…

September 10, 2026
Blob URL Phish Hides Page Inside Your Browser

Blob URL Phish Hides Page Inside Your Browser

Barracuda observed a real phishing campaign that avoids hosting a traditional fake website. Instead, victims are led through Microsoft Teams to load a resource that their browser converts into a “blob URL,” rendering the phishing page only inside the victim’s browser, making it harder for scanners…

September 9, 2026
Fake GitHub Lure Tricks macOS Users Into Stealer

Fake GitHub Lure Tricks macOS Users Into Stealer

Researchers described AmnesiaStealer, a macOS info-stealer spread through a counterfeit “Download for macOS” page that tricks users into pasting a command into Terminal. The malware steals passwords and browser session data, and can even give an attacker live, hidden control of the victim’s browser…

August 17, 2026
Vishing “Help Desk” Scams and Lookalike Phish Surge

Vishing “Help Desk” Scams and Lookalike Phish Surge

This weekly roundup highlights multiple real-world social engineering threats, including fake IT help-desk phone calls that push employees to phishing sites to steal passwords and one-time authentication codes. It also describes credential-phishing sites impersonating WhatsApp and Instagram that…

August 14, 2026