Back to main menu

Product

Mailgun security incident and important customer information

On January 3, 2018, Mailgun became aware of an incident in which a customer’s API key was compromised and immediately began diagnostics to help determine the cause and the scope of impact. Read more...

PUBLISHED ON

PUBLISHED ON

This was originally posted on January 5, 2018.

On January 3, 2018, Mailgun became aware of an incident in which a customer’s API key was compromised and immediately began diagnostics to help determine the cause and the scope of impact.

At that point in time, we were able to determine that the root cause was due to a Mailgun employee’s account being compromised by an unauthorized user. We immediately closed the point of access to the unauthorized user and deployed additional technical safeguards to further protect this sensitive portion of our application.

Mailgun has now completed its diagnostic of accounts that were affected and has notified each of the affected users. At this time, we believe less than 1% of our customer base was potentially affected. If you were not directly notified by Mailgun regarding this incident, then your account was not affected. We are engaging with a third-party security team to complete an additional audit of this incident to validate our findings.

Finally, we’d like to assure our customers and partners that we take security at Mailgun very seriously. We are using this as an opportunity to further evaluate the security of our platform to better serve and protect our customers. We will provide an update upon the completion of our investigation.

If you have any questions, please do not hesitate to contact security@mailgun.net. For media inquiries, please contact media@mailgun.net.

Questions you may have

Who was affected?

Only a small subset of Mailgun accounts were impacted. We have directly notified all affected users. If you did not receive a notification email, your account was not among those affected.

What do I need to do to protect my account?

If you were notified that your account was affected, we advise that you do the following to protect your account from unauthorized access: 1) Rotate your Mailgun API keys (click here for more info on how this process works) 2) Change your SMTP username and passwords (this article shows you where to manage your SMTP credentials)

Was my account billing or credit card information compromised?

No. Customer payment information was not compromised.

Related readings

Email validation – Why is it vital for your inbox?

We all have those moments when we get nervous and need to double-check ourselves. Did we fill in the right answer bubbles on a test? Did we type in the right password when...

Read More

Announcing new analytics features to maximize your email performance

Navigating email analytics has never been easier than with our latest updates. Advanced data analysis, faster performance, and better data management tools have been released...

Read More

Streamlining bulk email sending with custom queue management using Mailgun’s API

Sending bulk emails requires quite a bit of finesse and care. Several factors add to the complexity, including throttling and rate limits set by mailbox providers to control the flow of emails, data protection laws that must be adhered to, and deliverability issues...

Read More

Popular posts

Email inbox.

Email

5 min

Build Laravel 11 email authentication with Mailgun and Digital Ocean

Read More

Mailgun statistics.

Product

4 min

Sending email using the Mailgun PHP API

Read More

Statistics on deliverability.

Deliverability

5 min

Here’s everything you need to know about DNS blocklists

Read More

See what you can accomplish with the world's best email delivery platform. It's easy to get started.Let's get sending
CTA icon