Barracuda Threat Spotlight

July 19, 2026

Attackers set the font size to zero in phishing emails to hide random text and thus deceive AI-powered email protection systems

Barracuda Research uncovers ‘text salting’ techniques in one million retail-related attacks

Researchers at Barracuda have uncovered more than one million phishing attacks utilising an evasion tactic developed years ago. This bypasses conventional spam filters by diluting the impact of suspicious words. A new report describes in detail how this tactic, known as ‘text salting’, works: large amounts of unrelated, innocuous text are inserted into an email and then concealed in such a way that, whilst security tools can scan it, it remains invisible to the email recipient. The recipient sees only the intended phishing content.

The aim is to deceive security tools and trick them into classifying the email as harmless. To achieve this, suspicious phrasing is altered or the concentration of words typically associated with scams – such as ‘urgent’, ‘bonuses’ and ‘expiring’ – is diluted.

Whilst analysing this scam in the retail sector, Barracuda researchers discovered ‘text salting’ techniques, which involved, amongst other things, reducing the visible display window by 100 per cent or shifting the text so far to the right-hand edge that it was no longer visible to the recipient. Attackers also inserted text directly into words or sentences and set its font size to zero, or they fragmented HTML streams with non-standard terms to bypass signature-based filters that search for exact phrases. For example, the HTML text might read: “Your pass [random text with font size zero] word has expired”. Scanners searching for the phrase “Your password has expired” would then fail to detect it.

The hidden content consisted of random stories, generic conversations or project-related notes containing a high number of positive words such as ‘puppy’, ‘training’, ‘notes’, ‘task’, ‘rhythm’ or ‘book’, in order to reduce the impact of suspicious words. The visible message, on the other hand, contains an urgent, retail-related lure, such as expiring rewards, points or gift card offers.

Over the past year, Barracuda researchers have observed an increase in the use of ‘text salting’ – no longer just to deceive speech recognition and keyword analysis, but also to trick machine learning models and, increasingly, LLM-based security tools into to mistakenly classify phishing or spam messages as legitimate, thereby enabling their delivery to recipients.

What makes AI-powered email security systems vulnerable to these techniques

Hidden text can influence how a Large Language Model (LLM) interprets an email. LLMs process all aspects of the email content equally – including the hidden text – and use this information to assess the email’s intent, tone, purpose and level of risk. When faced with large amounts of disjointed, harmless text, the model is more likely to mistakenly classify the email as harmless.

AI also makes it easier and faster for attackers to automatically generate an endless number of normal-sounding paragraphs on any topic, free of charge. As a result, every single phishing email can look completely different, making it impossible to trace.

“Techniques involving hidden text are making a comeback in the age of AI,” says Pranati Sethi, Senior Threat Analyst at Barracuda. “These techniques manipulate the way in which both traditional and AI-based security tools interpret an email, whilst generative AI makes text-salting campaigns cost-effective, scalable and extremely diverse.”

Researchers therefore recommend a robust, multi-layered approach to email security that does not rely solely on keyword detection, but also assesses the structure of the message, the sender’s reputation, behavioural anomalies, authentication results, embedded links, HTML rendering techniques and the content visible to the user. This should be underpinned by educating users about warning signs of phishing emails, such as unexpected offers or messages urging immediate action.

Related Articles

Share This