
You're caught in an impossible position. Your employees need shortened URLs to do their jobs effectively - they're embedded in marketing campaigns, social media posts, and legitimate business communications. But these same URLs are costing organizations an average of $4.88 million per phishing incident (IBM Cost of a Data Breach Report, 2025).
The problem isn't that your security team made poor decisions. It's that traditional URL filtering tools were never designed for the redirect-heavy web that defines modern work. They can tell you whether bit.ly is trustworthy, but they can't see where that link actually takes your users.
Threat actors understand this limitation better than most security vendors do.
URL shortening attacks represent a type of Legacy URL Reputation Evasion (LURE) - techniques that exploit the binary trusted/untrusted categorization your URL filters rely on. When someone clicks a shortened link, your security tools evaluate the reputation of the shortening service itself, not the final destination after all the redirects.
The math is brutal. APWG recorded 3.8 million phishing attacks globally in 2025 (APWG, 2025), with Q1 alone exceeding one million attempts. Menlo Labs has observed a 198% increase in browser-based phishing attacks over the past six months - 30% of these attacks use evasive techniques specifically designed to bypass traditional security controls.
The rise correlates directly with the maturation of Phishing-as-a-Service (PhaaS) kits. These pre-packaged attack toolkits include URL shortening templates alongside email designs and credential-harvesting pages. With 82.6% of phishing emails now containing AI-generated content (Keepnet, 2025), these campaigns look legitimate enough to fool both your employees and your security stack.
Your URL filtering solution works exactly as designed - it just wasn't designed for a world where legitimate business relies on link redirection. Here's what happens when an employee clicks a shortened URL: your security tool evaluates the reputation of bit.ly or t.co, not the content and intent of wherever that link redirects. This architectural limitation creates three specific vulnerabilities:
The business impact extends beyond the immediate financial cost of breaches. Your security team ends up managing an impossible trade-off: block all shortened URLs and field hundreds of productivity complaints, or accept the risk and hope your employees make perfect decisions about which links to trust.
The solution requires a fundamentally different approach - one that analyzes web content at the point of interaction rather than relying on historical reputation data. The Menlo Browser Security Platform addresses this by executing all web content in the Menlo Cloud before it reaches your users' devices.
When someone clicks a shortened URL, HEAT Shield AI follows the complete redirect chain and performs real-time analysis of the final destination - including full page content, JavaScript behavior, and visual elements. This means your security posture no longer depends on whether a threat has been seen before or whether your URL database includes the latest malicious redirects. Even zero-day phishing sites reached through multiple URL shortening services get neutralized before your employees can interact with them.
Your security team gains granular policy control based on actual risk assessment rather than binary allow/block decisions:
The current state is unsustainable: your URL filters provide a false sense of security while leaving a gap that costs the average organization nearly $4.88 million per successful phishing incident (IBM Cost of a Data Breach Report, 2025). Your employees need shortened URLs to do their jobs effectively, but every click represents potential exposure.
Browser-level security changes this equation. Instead of hoping your reputation databases stay current with rapidly evolving threats, you get real-time protection that adapts to whatever attackers send your way. Your security team manages consistent policies rather than impossible trade-offs.
Most importantly, your organization can embrace the productivity benefits of modern web tools without accepting disproportionate security risks. That's not a technical achievement - it's a business advantage.
What is a LURE attack? Legacy URL Reputation Evasion (LURE) attacks exploit the way traditional security tools categorize websites. Instead of attacking sites your filters already know are dangerous, attackers either hijack trusted sites or create new ones that initially appear harmless. URL shortening is particularly effective because it hides the final destination entirely.
Why can't URL filtering tools detect these attacks? URL filters evaluate the reputation of the link presented to users, not where that link ultimately redirects. Since services like bit.ly and t.co are legitimate businesses, they pass reputation checks even when the final destination is malicious. Tools that try to follow redirects can be blocked by CAPTCHA challenges or content that only activates after initial scans.
How does browser-level security solve the URL shortening problem? Rather than relying on URL reputation, the Menlo Browser Security Platform executes web content in an isolated cloud environment and analyzes the actual page content, JavaScript behavior, and visual elements in real time. This provides protection against zero-day threats and evasive techniques that traditional tools miss entirely.
What happens to legitimate shortened URLs? Browser security platforms can distinguish between legitimate and malicious content at the final destination, so legitimate shortened URLs from marketing campaigns or social media continue working normally. The protection happens transparently without disrupting business workflows.
Neko Papez is a Cybersecurity Strategist at Menlo Security, specializing in browser-based threat prevention. With a career spanning industry leaders like Proofpoint, Domo, and now Menlo, Neko bridges the gap between complex security architecture and business-driving product marketing. Neko has a proven track record of helping enterprises combine deep technical expertise with a sharp marketing lens to deliver impactful thought leadership and robust defense frameworks for the world’s most targeted enterprises.
Learn more about how Menlo Security protects against LURE attacks and other browser-based threats. Schedule a demo here.
Menlo Security
