Newsroom Update

Apple and Google deliver support for unwanted tracking alerts in iOS and Android. Learn more >

Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

AOL Passwords hacked from iPhone

I have had my AOL account for close to 15 years (since it's inception really). I've had a few problems wiht my password being hacked over the years, but nothing like what I'm going through now. I rarely check my email through their website - I use my iPhone 4S.


It all started when I was going through my AOL spam folder on my iPhone looking for a legitimate email from my lawyer. When I moved that message, it opened the next message (truly spam) that contained a link (and possibly an attachment...I don't remember). I NEVER open junk email on my phone, I usually just delete it. Next thing I know, my AOL account is sending rogue emails to every address I've got stored in my phone. It all happened in a 6 hour span. I changed my password, and updated it on my phone and thought all was good. Then I received an email from a friend that looked legit so I opened it. As soon as I did it, I knew it was a mistake, so the cycle started again. I've change my password at least three times since the second time and have used a random combination of letters (mix of upper and lower case), numbers and symbols 12 characters long, so I know it's not easy to hack, I keep having this problem daily unless I remove the account from my phone - in which case, everything is fine...the problem only seems to be present when I set up my account on my phone.


It seems like there's a keylogger or virus on my iPhone 4s. I've updated my OS, I've updated my computer, I've backed up my iPhone...what else can I do? Should I replace my iPhone, or delete my AOL account permanently and change to gmail? HELP!! I'm at my wits end and my friends are tired of getting strange emails from me!

iPhone 4S, iOS 7.1

Posted on Apr 14, 2014 8:15 PM

Reply
122 replies

Apr 19, 2014 7:22 PM in response to Lawrence Finch

Lawrence Finch wrote:


AOL claims they were not vulnerable to heartbleed. I don't believe them.

I can't find a single test site that reports them as vulnerable to include a couple that claim to have the ability to test sites before Heartbleed was announced.


AOL does use Akamai as a Content Distribution Network (CDN), as seemingly most every large networking company does, and they were vulnerable for a long time. I just don't know that a CDN would ever have user login credentials.

Apr 19, 2014 9:14 PM in response to Robn Hood Six

Yes...exactly....

Hi!

News: then a link here


Then it uses my emall address as a signature........that is not my normal signature


None of these sent emails show up in my sent folder either


It is sending emails out 3 or 4 times a day


I did get thru to aol 5 or 6 days ago and they made me change my password and security question....I have since changed both 4 or 5 times and then gave up......it does nothing......deleting our accts won't stop it.....my password is currently 16 characters long....capitals, reg letters, symbols, complete gibberish so no one can guess it. Aol phone lines have been jammed up ever since and I get no response to emails or anything from them. My acct is 18 years old.....I sure wish they would fix this for us.....I don't think any of us did anything....they have to know these emails are being sent out....I am so friggin tired of apologizing to people.

Apr 19, 2014 9:34 PM in response to Carvinginnyc

Carvinginnyc wrote:


None of these sent emails show up in my sent folder either

That's a good sign, but the best hackers will take the time to delete them before they leave your account to cover the fact that it's being used.


Still, chances are good that it's not coming from your account. You should be able to figure out where it's coming from by submitting the original message with headers, not a bounce report, to Spamcop for analysis.

Apr 20, 2014 4:03 AM in response to asuguy184

It is strangely reassuring to see lots of other people with the same issue. Two of my families aol accounts were hacked, and contacts copied, with 'News' spam starting on the 19th April.


Nothing in the sent box.


Changed passwords and security questions, spoke to aol etc...but that is like shutting the stable door after the horse has bolted. They said normally 3 to 4 days before they bring it under control.

Apr 20, 2014 5:55 AM in response to MadMacs0

It's even possible that your account was never hacked.


Suppose the account of someone you know was hacked, and their contact list was acquired. The hackers could then use every address in that list as both a FROM address and a target address for their spam. As I assume this is someone you know it's likely that there's a lot of overlap between your contacts and theirs.


So it might appear that you were hacked when you were not.

Apr 20, 2014 6:17 AM in response to nozparker

I've the same issue with an IMac and a macbook.....100 miles apart. There is nothing in either sent box, but lots of undeliverable messages.


Looks to me that AOL has been breached strategically, and lots of people have lost their contact lists simultaneously. The AOL customer service and aoilmail twitter pages are a little 'busy' with this issue.

AOL Passwords hacked from iPhone

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.