URL scanning services are now a common component of modern security workflows. They help detect phishing websites or malware early and warn users before they visit a URL. However, the practice of some of these services—publishing scanned URLs—can inadvertently expose sensitive user data. CISPA researcher Ali Mustafa, together with colleagues from the Max Planck Institute for Security and Privacy and Ca’ Foscari University of Venice, conducted the first systematic investigation of the risks arising from this practice.
The researchers presented their paper, “LEAKYLINKS: Measuring the Security and Privacy Risks of URL Scanning Services,” at the IEEE Symposium on Security and Privacy 2026.
URL scanning services such as URLScan, VirusTotal or Cloudflare Radar automatically analyze websites for suspicious content. “For example, they check network requests, site reputations or embedded scripts, thereby helping companies and individuals detect malicious websites early on,” Mustafa explains.
