Link shortener abuse refers to the exploitation of URL shortening services' characteristic of hiding the destination link to redirect users to phishing sites, malware distribution sites, scam sites, and other malicious destinations.
There are three main abuse tactics. First, phishing (redirecting to fake login pages for banks or services). Second, malware distribution (redirecting to pages that download viruses or ransomware). Third, spam (mass-generating shortened URLs and distributing them via social media or email).
Shortening services do take countermeasures, but which methods they use and how much they catch is generally not disclosed. Rather than judging safety from assumptions about detection, it is more reliable to go by what can be observed from the outside. The measures visible to users include warning screens that display the destination before redirecting (splash pages), a channel for reporting abuse, and limits that keep large numbers of links from being created in a short time. The presence of these features does not, however, mean that links issued through the service are safe.
User-side precautions are equally important. When you receive a suspicious shortened URL, useful habits include: using whatever destination check the service itself provides (the method differs between services), verifying the link beforehand with a URL expansion service such as CheckShortURL, and confirming whether the sender of the email or message is trustworthy.
When selecting a URL shortening service for enterprise use, security features should be a key evaluation criterion. Check for custom domain support, HTTPS enforcement, access log retention, and how quickly an issued link can be disabled. Detection mechanisms themselves are not published, so what you can actually verify is how fast a problem link can be stopped.