Going a bit to the extreme, someone can find the current tcp/ip session that you have with the AOL server, actively hijack it, emulate you still sending/receiving messages, and go from there.
...