A ransomware group calling itself Clop claims to have targeted AOL.com, with the claim dated August 12, 2026. This claim was identified on the group’s own leak-site listing, which is tracked by ransomware.live, a security research platform that monitors ransomware groups’ public extortion sites. At this time, the claim is unverified — AOL has not issued any public confirmation, and no regulator or independent investigator has corroborated it.
What we know — and don’t
- Clop’s leak-site listing references a claimed attack dated August 12, 2026.
- AOL.com operates in the ‘other’ sector category, as it is not a bank, law firm, school, retailer, or healthcare provider.
- The specific types of data Clop claims to have obtained have not been disclosed by the group or confirmed by any outside party.
- There is no independent verification that any AOL systems were actually compromised.
- AOL has not made any public statement acknowledging or denying this claim as of publication.
What should you do if you have an account with this company?
- Change your AOL account password, and avoid reusing that password anywhere else.
- Enable two-factor authentication (2FA) on your AOL account and any linked email or recovery accounts.
- Be alert for phishing emails or messages that reference AOL, your account, or this claimed incident — do not click unfamiliar links or attachments.
- Review your account’s recovery email and phone number to ensure they have not been altered without your knowledge.
- Consider signing up for identity monitoring, such as a service like Aura or LifeLock, to get alerted if your personal information turns up in places it shouldn’t be.
- Keep an eye on financial and other online accounts for unusual activity, particularly if you reuse credentials across services.
This claim remains unverified. BreachLetter will update this page if AOL confirms an incident, or if the matter is officially reported to regulators.