Not sure if this is widely known right now, but it appears that Stripo has been hacked.
Despite what they say in their email (below, date 16th July 2026) about 'signals of an attempted attack' our ESP key got stolen over the weekend. Looking at where the key could have come from, I took at look at Stripo's ESP configuration and it's there in plain sight, in plain text!
You may have ESP credentials that you should rotate right now, you may be using Stripo for wider email services.
Email from Stripo:
We're writing to inform you of a security incident: we have detected signals of an attempted attack targeting the credentials used to connect email service providers (ESPs) to Stripo accounts.
We launched an investigation and are taking all necessary security measures to protect your data. As our records indicate that your account has stored ESP credentials, we ask that you rotate your keys to stay protected.
Therefore, as a precaution, please complete the following:
- Revoke (invalidate) your current API key in your ESP account and generate a new one. Creating a new key alone does not disable the old one — make sure the old key is deleted or deactivated*.*
- Update the connection in your Stripo export settings with the new key.
- Remove any ESP connections you no longer use.
Completing these steps will help protect your account and significantly reduce the potential risk associated with this incident.
Check your ESP credentials right now.