Text Salting Technique Bypasses AI Email Security Filters at Scale
Threat actors are exploiting a fundamental weakness in how AI-powered email security tools parse and interpret obfuscated text, using a technique called 'text salting' to hide malicious phishing content from machine learning detectors. Over one million phishing emails have successfully evaded detection, demonstrating that over-reliance on AI-based filtering as a single layer of defense creates a dangerous blind spot. This attack is particularly insidious because the obfuscation is invisible or seamless to human recipients, meaning users remain the last line of defense. The incident underscores that AI security tools, while powerful, can be systematically manipulated and must not be treated as infallible gatekeepers. Organizations that have not trained employees to recognize phishing independently of their technical controls are especially vulnerable.
Tactical Insight
Immediate actions
- Audit your current email security stack to confirm it is not solely reliant on a single AI/ML-based filtering solution.
- Issue urgent phishing awareness reminders to all staff, emphasizing that filtered inboxes are not guaranteed to be safe.
- Report suspicious emails through established channels so security teams can identify potential text-salting patterns in your environment.
Long-term improvements
- Deploy a defense-in-depth email security architecture that layers AI filtering with rule-based detection, sandboxing, and DMARC/DKIM/SPF enforcement.
- Conduct regular, simulated phishing exercises that include novel obfuscation techniques to build employee resilience beyond what technical filters catch.
- Engage email security vendors to request transparency on how their models handle obfuscated or salted text, and push for model updates addressing this class of attack.
Detection measures
- Implement robust email logging and anomaly monitoring to flag unusual encoding patterns, excessive Unicode characters, or irregular whitespace in message bodies.
- Establish behavioral alerting for downstream indicators of phishing success, such as unexpected credential usage or OAuth token grants following email delivery.
- Integrate threat intelligence feeds that track emerging adversarial ML evasion techniques to proactively update detection rules.