AOL Hacked, User Account Info Compromised

Last week the level of spam with AOL email addresses jumped up significantly, filling inboxes with garbage emails. At the time, the company insisted that its mail servers weren't hacked, but instead spammers with their own email servers were "spoofing" legit AOL email addresses. Changing passwords doesn't remedy the issue since nothing was hacked to begin with.

"Spoofing is a tactic used by spammers to make it appear that the message is from an email user known to the recipient in order to trick the recipient into opening it. These emails do not originate from the sender's email or email service provider -- the addresses are just edited to make them appear that way," writes AOL's Mail Team.

The company announced that it was on the case, and now AOL reports that there was unauthorized access to information regarding a "significant" number of user accounts. Hackers managed to grab email addresses, postal addresses, address book contact information, encrypted passwords, encrypted answers to security questions, and certain employee information. They might as well have grabbed our wallet or purse.

"We believe that spammers have used this contact information to send spoofed emails that appeared to come from roughly 2-percent of our email accounts," the team writes.

The team says that at this point in the investigation, there's no indication that the encryption on the passwords or the answers to security questions was broken. There's also no indication that this incident resulted in disclosure of users' financial information, including debit and credit cards, which is also fully encrypted.

Still, AOL wants users to change passwords and security questions.

"The ongoing investigation of this serious criminal activity is our top priority," the team writes. "We are working closely with federal authorities to pursue this investigation to its resolution. Our security team has put enhanced protective measures in place and we urge our users to take proactive steps to help ensure the security of their accounts."

The team warns that users should not open suspicious emails, and do not click on attachments. If you receive an email with a known AOL address, contact the other party and see if it's legit. Never provide your sensitive personal information in an email to anyone, such as bank details and passwords. If you're a victim of spoofing, tell all your friends so they won't click on disguised attached malware.

"AOL is notifying potentially affected users and is committed to ensuring the protection of its users, employees and partners and addressing the situation as quickly and forcefully as we can," the team writes.

TOPICS
Latest in Cyber Security
GeForce RTX 3090
Akira ransomware can be cracked with 16 RTX 4090 GPUs in around ten hours — new counterattack breaks encryption
Crypto Hacker
FBI identifies North Korea as source of $1.5 billion ByBit hack
A broken lock on a PCB.
Apartment buildings broken into with phone in minutes — IoT-connected intercoms using default creds vulnerable to anyone with Google
Streamjackers want your digital treasures
CS2 fans targeted by Streamjackers — viewers swindled out of crypto and Steam valuables
Eight Sleep's Pod 4 Ultra Smart Bed
Security researcher finds vulnerability in internet-connected bed, could allow access to all devices on network
13th Generation Intel CPU
Intel roasts AMD and Nvidia in its latest product security report, claiming AMD has vulnerabilities with no fix planned, Nvidia has only high-severity security bugs [Updated]
Latest in News
Despite external similarities, the RTX 3090 is not at all the same hardware as the RTX 4090 — even if you lap the GPU and apply AD102 branding.
GPU scam resells RTX 3090 as a 4090 — complete with a fake 'AD102' label on a lapped GPU
Inspur
US expands China trade blacklist, closes susidiary loopholes
WireView Pro 90 degrees
Thermal Grizzly's WireView Pro GPU power measuring utility gets a 90-degree adapter revision
Qualcomm
Qualcomm launches global antitrust campaign against Arm — accuses Arm of restricting access to technology
Nvidia Ada Lovelace and GeForce RTX 40-Series
Analyst claims Nvidia's gaming GPUs could use Intel Foundry's 18A node in the future
Core Ultra 200S CPU
An Arrow Lake refresh may still be in the cards with only K and KF models, claims leaker
  • segio526
    Seems redundant. Given the typical AOL user, I'm pretty sure all their data was already stolen long ago! Hackers gained nothing new!
    Reply
  • n3cw4rr10r
    People still use AOL? Holy shit, I remember using it back in the 90s .. You Got Mail !!!
    Reply
  • derekullo
    User: I believe your system was hacked. My account is sending spam to all my friends.

    AOL: We weren't hacked. Getting hacked costs us a lot of money.
    Reply
  • Quarkzquarkz
    Listen, who the heck still uses AOL? If you ask me, if you still use this ancient service provider, you deserved to be hacked.. I'm sorry~ =(
    Reply
  • kawininjazx
    I run a computer store, everyone over 40 has AOL, it's horrible.
    Reply
  • rantoc
    Gotta love the mentality of collecting all eggs on one convinient place for any skilled hacker - the cloud gotta be their best friend :)
    Reply
  • rpgplayer
    "AOL Hacked, User Account Info Compromised"
    Both of them?
    Reply
  • boytitan2
    Screw it just gonna transfer everything important to gmail. Manageing 3 email accounts was getting to be a pain in the but anyways.
    Reply