Suspected Iranian state-linked hackers infiltrated the personal AOL email account of former U.S. national security adviser John Bolton in 2021, gaining access to sensitive documents and threatening to leak their contents. The hackers reportedly sent extortionate messages referencing the potential for a scandal similar to the 2016 Hillary Clinton email controversy, and Bolton's representative notified the FBI about the intrusion. Prosecutors allege that Bolton used the compromised account to transmit classified information to family members, which may have been obtained by the hackers.
Following the breach, the U.S. Department of Justice charged Bolton with mishandling classified information, specifically for retaining and transmitting sensitive material via his personal email. The indictment, unsealed in October 2025, details the sequence of events and the security lapses involved, raising concerns about the use of personal email accounts for official business by high-ranking government officials. Bolton has denied any wrongdoing and called the charges baseless, while questions remain about the security measures in place on his email account at the time of the breach.

See the actors and campaigns active against you right now.
2 events from the most recent confirmed update back to the earliest known activity.
U.S. authorities charged John Bolton after classified emails were discovered in the compromised AOL account following the Iranian intrusion. Multiple reports described the charge as stemming from the exposure of sensitive messages in the hacked mailbox.
The U.S. Justice Department said Iranian hackers compromised former National Security Adviser John Bolton's AOL account. The breach exposed emails that included classified information, forming the basis for later criminal charges.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.