Privacy risks lurking behind unknown redirect links

A page offering nothing but a generic "Click here to proceed" button can feel almost nostalgic. In practice, that single link is a small but significant privacy hazard. Unknown redirects sit between you and the site you intended to visit, logging your IP address, browser fingerprint, and arrival path. They are one of the easiest ways to funnel ordinary Australians toward phishing kits, malware payloads, and credential harvesting pages.

The ACCC's Scamwatch service received more than 600,000 reports last year, with a noticeable share starting from a redirect on a social feed or text message. Losses exceeded 2.7 billion dollars, and the Office of the Australian Information Commissioner logged hundreds of notifiable data breaches. The numbers make one thing clear: most incidents do not begin with sophisticated hacking. They begin with a curious click.

This piece walks through how unknown redirects operate, the harm they cause, and what Australian users can do to keep personal data, banking credentials, and tax records out of the wrong hands. The advice applies whether you are browsing from a café in Newtown, a hotel in Cairns, or a property outside Wagga Wagga.

How unknown redirects actually work

A redirect is a piece of code that sends your browser somewhere else, usually after a brief delay. Legitimate services use them for affiliate programs or country-specific gateways. Malicious operators use the same plumbing for less helpful ends. When you click a shortened URL on a forum post or tap a link in a scam SMS, your browser may pass through several intermediary domains before landing on the final page. Each hop records the request.

The chain often begins with a recently registered domain parked on a generic page, offering only a "proceed" button and nothing else. That signals the destination has been kept deliberately vague. Behind the scenes, that landing page may capture referrer headers, screen resolution, language settings, and approximate location derived from your public IP. Combined, this can identify a household, a workplace, or a specific device. Free URL expander tools let you preview the chain before clicking.

Common traps hidden in suspicious links

Phishing campaigns targeting local inboxes often impersonate trusted brands such as Australia Post, the big four banks, AGL, or Telstra. The message looks polished, the logo is correct, yet the link points to a domain registered only days earlier, often with a subtle misspelling or unusual country-code suffix. Clicking it can launch a chain of redirects designed to evade the blocklists used by Australian telcos.

Shortened links inside chat apps and gaming communities present a similar challenge. Without expanding them, you cannot tell whether the destination is a YouTube clip, a Discord invite, or a credential harvester. Even QR codes on lampposts in Surry Hills or at a Melbourne tram stop can hide redirects that lead to fake login pages for MyGov or university portals. Mobile users on Telstra, Optus, or Vodafone networks are especially exposed because carrier-grade filters act on the first domain only, not every redirect in the chain.

Data harvesting behind the curtain

Once a redirect resolves, the destination page can request a surprising amount of information. Cookies from previous sessions, localStorage values, and cached login tokens can all be read by scripts on the new page. If you happened to be signed in to Gmail, Facebook, or Microsoft 365, the script may attempt to read identifying tokens and replay them against the legitimate service.

Geolocation through the browser is another quiet exposure. A page can ask for permission to know your precise location, and many Australians grant it without reading the prompt carefully. Once granted, that information can be combined with your IP-derived city and time zone to triangulate your address. In metropolitan areas such as Brisbane, Perth, or Adelaide this is rarely accurate down to the street, but in regional locations it can narrow your position to a few hundred metres. Device fingerprinting goes further, since screen size, installed fonts, graphics card model, and battery level are all readable through normal browser APIs.

Phishing, malware, and identity theft in practice

The end goal of a redirect chain is rarely the redirect itself. Operators want a target, whether that is your banking credentials, your myGov password linked to ATO records, your Medicare details, or a foothold to install a malicious browser extension. From there the attacker can pivot to your email, reset passwords for services such as Netflix or a cryptocurrency exchange, and start draining value.

Cases reported to Scamwatch often involve a fake toll road notice, a missed delivery from a courier, or a notice from the ATO. The flow is familiar: an SMS arrives, the link opens a convincing copy of a real site, credentials are entered, and within hours the attacker has reset banking passwords using information harvested from the victim's email. Recovery is rarely quick, because Australian banks are increasingly cautious about refunding losses linked to customer-initiated transactions.

Identity theft at scale is even more damaging. A bundle of Australian identifiers, including full name, date of birth, address, driver's licence number, and Medicare details, can be sold on dark-web forums for several hundred dollars. Synthetic identities built from these fragments are then used to apply for credit, lodge fraudulent Centrelink claims, or open telecommunications accounts in the victim's name.

Regulatory protections available in Australia

Australian law offers several layers of protection, though they are reactive rather than preventative. The Privacy Act 1988 requires organisations with an annual turnover above 3 million dollars to take reasonable steps to protect personal information. Smaller operators are not always covered, which is why many small intermediary domains fall outside the regime. The Notifiable Data Breaches scheme obliges eligible entities to inform the OAIC and affected individuals when serious harm is likely.

The eSafety Commissioner plays a growing part in tackling malicious content, while the Australian Cyber Security Centre publishes guidance for households and small businesses through cyber.gov.au. For everyday scams, Scamwatch remains the most useful reporting channel, and reports feed into intelligence shared with banks and telcos. None of these protections prevent a redirect from running. They help with response and recovery, but the safest outcome is still to avoid the click in the first place.

Habits that reduce exposure in daily browsing

A few habits quietly close off most of the risk. Hovering over a link on desktop reveals the destination in the status bar; on mobile, a long press often does the same. If the domain is unfamiliar, do not tap. Enable multi-factor authentication on every account that supports it, particularly email, banking, and government services such as myGov. Use a password manager so the same credential is never reused across sites, and prefer passkeys for Apple, Google, and Microsoft accounts where available.

Keeping your phone and laptop current matters more than people realise, since browsers and operating systems ship with new blocklists and security checks each release. Avoid installing browser extensions from unknown publishers, and clear site data periodically if you share a device. If you receive an unexpected message claiming to be from your telco, your bank, or a delivery service, log in through the official app rather than the link in the message. Read practical ways to verify suspicious links before deciding whether to engage with an unfamiliar page.

Sometimes a single click on a page that looks empty is all it takes. Treat every unfamiliar redirect as a stranger at the door: pause, check, and only proceed when the destination is clearly trustworthy. Before you tap that link next time, take five seconds to preview the URL, check the sender, and confirm the destination through the official app. The cost of getting it right is only a moment of attention.