The Privacy and Security Risks of Shortened URLs
Shortened URLs trade a tidy message for hidden destinations, third-party tracking and links that can be repointed at malware. Check one before you click.
Short links are still everywhere: in text messages, on social media, in QR codes, and in your inbox. A shortened URL is just a redirect. You click a short address, the service looks up the destination it has on file, and it sends your browser there. The convenience is real. So is the risk, because what makes a short link useful to you also makes it useful to an attacker.
This post was updated for 2026. Google's goo.gl is gone, a couple of services dominate, and how you can inspect a link has changed. The core risks have not.
How shortened URLs work
When you click a short link, your request goes to the shortening service first. The service matches the short code to a destination and returns a redirect, usually a 301 or 302, that your browser follows to the real page. That extra hop is the whole mechanism, and it is where the privacy and security problems live.
The redirect lets the service log the click: your IP address, the rough location it maps to, your device and browser, and the time. Most of that is ordinary marketing analytics. The problem is that you cannot see any of it, and you cannot see where you are going until you are already there. A short link looks the same whether it points to a news article or a credential-harvesting page.
A few things worth knowing about how they behave:
- Shorteners often strip tracking parameters from the long URL to make it tidier, but the service still keeps the data it collected on the way through.
- The redirect happens faster than you can read it, so the destination is effectively hidden.
- The owner of a short link can usually change where it points after the fact, so a link that was safe yesterday is not guaranteed to be safe today.
- Some services can keep tracking you after you arrive, by passing parameters or identifiers through to the destination site.
What has changed since short links first spread
Three shifts matter for anyone deciding how much to trust a short link in 2026.
Google's goo.gl is gone. Google stopped creating new goo.gl links in March 2019, and on 25 August 2025 it ended redirect support for the links that had gone inactive. It later kept actively used links alive, but you cannot create a new one and there is no long-term guarantee for the old ones. Firebase Dynamic Links, once the suggested replacement, was shut down the same day. Treat old goo.gl links in documents and campaigns as dead weight and rebuild them elsewhere. Google's announcement is here.
Bitly still dominates, and smaller services carry most of the abuse. Bitly remains the best-known shortener and now runs a threat-detection service that scans links on creation, plus a Link Checker for recipients. That does not make every bit.ly link safe; it means the biggest service has the most to lose. Research presented at eCrime 2025 found that the ten most-abused shorteners accounted for roughly 70% of the shortened phishing URLs observed, with a median time to takedown of about 48 hours. Two days is a long window for a campaign.
Previewing is easier, if you know the trick. The major services let you inspect a destination without visiting it, one trick per service (see the table below). Browser protection has improved too: Chrome and Firefox check pages against threat lists, and Chrome's Safe Browsing has Standard and Enhanced modes, though none will catch a brand-new phishing page that is not yet catalogued.
Common threats posed by shortened URLs
Beyond ordinary link-sharing analytics, short links create several specific problems.
Disguised malware and phishing attempts
The biggest risk is being redirected to something hostile: an exploit kit, a phishing page, or a malware download. Because the destination is hidden, your email gateway and browser cannot reliably check it before you click, and by the time the page loads you are on the attacker's ground. If you have already been caught out, there are steps you should take after clicking a phishing link.
Attackers also personalise short links. A link that pre-fills your stolen email into a convincing login page is far more effective than a generic one, and a public short link created for a legitimate purpose can later be repointed at a phishing page.
Loss of transparency
A short link tells you nothing about where it leads, and hovering does not help because the short form is all the browser shows. That is the point of the format, and it is why short links hide a hostile destination so well. Even an honest link can be repointed later with no visible sign, and the service has no way to know the owner's intentions have turned.
Privacy and tracking concerns
Shortening services sit between you and the destination, and that position lets them observe every click: your IP address, location, device and browser, logged per link. Some add their own identifiers to the redirect to track reach and engagement. The collection is not always sinister, but it is rarely disclosed in detail, so you usually cannot tell what is logged or who it is shared with.
Potential for malware distribution
Short links are a cheap way to disguise a hostile URL, which is why they turn up constantly in spam, on social media, and in messaging apps. Researchers have documented botnet-driven spam campaigns that route every victim through a shortener so the payload URL never appears in the message. Microsoft reported a February 2025 tax-themed campaign that used a Rebrandly link to reach a fake DocuSign page, and APWG's Q4 2025 report noted a shift toward TinyURL as a redirection layer. If a short link takes you somewhere unexpected, assume malware until you have reason to think otherwise.
Malicious redirects
Because the destination behind a short code can be edited, a short link is only as trustworthy as whoever controls it. Attackers have taken over short links, or bought the same code after it expired, and repointed them at malware. Some services sell this ability outright: paid tiers at Bitly, Rebrandly and Short.io let an owner change where a live link points at any time. Useful for a marketing team, a hazard for everyone else, because the short form gives you no way to tell the target changed.
Large-scale campaigns continue unhindered
Short links let an attacker re-point a whole campaign on the fly. If the landing page is taken down, they swap in a new destination and keep the same short links, so they never have to redistribute anything. That keeps a campaign running as long as the shortener tolerates it and makes takedowns less effective than they look. Some services also pass data through the redirect, which opens the door to interception during the hop.
Best practices for safely using shortened URLs
You can keep the convenience without the whole risk. These habits matter most:
- Treat a short link from an unknown source as hostile. Do not click it just to see where it goes. If you must open it, use an isolated environment; Kasm Workspaces is the quickest option I use.
- Preview before you click, using the service's own trick (below) or a URL expander that resolves the full redirect chain server-side, without your browser touching the destination.
- Look at the final destination, not the first hop. Malicious chains often bounce through a legitimate-looking redirect before the payload. Check the domain at the end letter by letter, and watch for look-alikes and homoglyphs.
- Never follow a short link to a login page, a bank, or a payment screen. If you need to sign in, navigate to the site yourself.
- Check the reputation of the service, not just the link. Free and anonymous shorteners have the loosest controls and attract the most abuse.
- Use your browser's built-in protection and a reputable anti-phishing or antivirus product. Chrome's Safe Browsing and its Firefox equivalent catch known malicious pages, and an ad blocker such as uBlock Origin cuts off many of the malicious-advertising routes short links feed into.
- Do not put a short link on a sensitive asset. Password-reset pages, internal tools and financial sites are an open invitation to a lookalike swap.
- Keep short links inside trusted circles. The narrower the audience, the lower the chance someone repoints the link.
- If you run short links yourself, host your own branded shortener instead of routing readers through a third party. You keep the analytics and control the destination.
- If you share short links publicly, check them periodically and retire any whose destination you no longer control.
- Skip shorteners when you can. If the original URL fits, use it; a visible domain is worth more than a tidier message.
- Tell other people why this matters. Most people who click a malicious short link do not know the destination can be changed after the link is created.
Built-in preview tricks for the common shorteners:
| Service | Preview trick | Example |
|---|---|---|
| Bitly | Add + to the end | bit.ly/abc123+ |
| TinyURL | Add preview. before the domain | preview.tinyurl.com/abc123 |
| is.gd / v.gd | Add - to the end | is.gd/abc123- |
| tiny.cc | Add = to the end | tiny.cc/abc123= |
None of these tricks makes a link safe on its own. They show you the destination; you still have to judge it. A clean-looking domain is not proof the page is legitimate, and a brand-new phishing page will not be on any threat list yet.
Short links are not going away, and they are not automatically dangerous. The risk is in what they hide. Expand before you click, judge the destination, and keep your guard up when a link arrives from someone you do not know. For the background on why messaging is a favourite delivery channel, see the comparison of encrypted messaging apps.