Stripo has sent an email to users disclosing a security incident involving an attempted attack targeting credentials used to connect email service providers (ESPs) to Stripo accounts.
Stripo says it detected signs of an attempted attack and immediately launched an investigation. There is no public confirmation that any accounts or credentials were compromised. However, if you have connected services such as SendGrid, Mailchimp, Brevo, Amazon SES, or other supported email providers through Stripo, you should review those connections and update your credentials.
Stripo recommends taking these steps to protect API keys from abuse:
- Revoke or delete your current API key in your email service provider.
- Generate a new API key.
- Update your Stripo export settings with the new key.
- Remove any email service provider connections that you no longer use.
Note that generating a new API key does not automatically disable the old one. You must revoke or delete the previous key to prevent it from remaining active.