Mailchimp Transactional (the service formerly called Mandrill) does not stand apart from the Mailchimp marketing product. It stands on top of it. The Transactional dashboard, where API keys are issued, listed, rotated, and revoked, is a sibling UI served from mandrillapp.com and gated by the same Mailchimp parent-account login. Whoever reaches the parent account reaches the sending credentials. For a WordPress operator that means Mandrill security is Mailchimp account security, and the audit should treat them as the same system rather than two.
What parent-account access reaches
Signing into Mailchimp and switching to Transactional exposes the full API key list, the option to generate a new key, the activity feed, the subaccount list, and the webhook configuration. Nothing in the Transactional UI is additionally gated once the Mailchimp login is through. A stolen Mailchimp password, a hijacked session, or an unauthorised administrator added to the account is enough to send mail as your domain through Mandrill’s infrastructure, read the recent send history, and quietly add a new API key that your WordPress site never sees.
Mandrill’s subaccount feature isolates reputation and rejection lists per sender, which matters for operational hygiene. It does not isolate credentials. A parent-level API key can send on behalf of any subaccount by passing the subaccount parameter or the X-MC-Subaccount SMTP header, so subaccounts are not a security partition.
The incidents on the public record
Mailchimp has disclosed three social-engineering compromises of its own internal tools since 2022: March 2022, 319 accounts accessed and 102 with data exported, in the Trezor phishing wave; August 2022, 214 accounts accessed through the Okta 0ktapus campaign, mostly cryptocurrency customers; and January 2023, 133 accounts accessed after staff were socially engineered, with Mailchimp stating no credit card or password information was compromised. None of the published write-ups say Mandrill sending credentials were extracted. None say they were not. The architecture in the previous section is why that distinction matters: an attacker inside Mailchimp’s internal tools was in the same product that holds the Transactional keys.
The risk model for a WordPress site integrating with Mandrill has to treat the parent Mailchimp account as the piece most likely to fall first. That is where the three disclosed incidents reached, and the Transactional dashboard is one authenticated step away.
What the operator controls
Four moves, concrete and small.
- Enable two-factor authentication on every Mailchimp login on the account. Authenticator app over SMS. The three disclosed incidents all defeated staff controls on Mailchimp’s side; strong authentication on the customer side is the control the customer actually owns.
- Give each application its own API key. The Transactional account supports multiple keys per account (the
/messages/searchendpoint filters results by key, which exposes this to clients). A WordPress site should hold one key dedicated to that site, not one shared with a billing script or a staging environment. Replacing a leaked key then touches one application rather than all of them, and the activity feed shows exactly what each key was doing instead of blurring every sender together. - Watch the activity feed. The Outbound view shows send volume, bounces, and rejection reasons per subaccount. Mandrill keeps aggregate statistics (deliveries, bounces, rejections, opens, clicks) indefinitely, bounced-message details for 90 days, and the full HTML and text of sent messages for 30 days. For an unfamiliar sending pattern the shape of the traffic is visible for the long term; it is only the message bodies, the forensic detail on a specific suspect send, that cut off at the 30-day mark.
- Rotate on any Mailchimp security notice. The last three incidents were disclosed days to weeks after discovery. A new key, issued and swapped into the WordPress SMTP settings, costs one deploy and resets the clock on anything the previous key might have been exposed to.
This is the same discipline the Brevo supply-chain incident demanded in September: the mail provider’s security is not fully under your control, so audit the parts that are. Different platform, same job.
