We received an email saying an API key was generated in our Hexnode portal, but none of our admins intentionally created or enabled an API key. The notification went to the administrators, so it raised some security concerns.
Is this email always caused by someone manually generating a key? Also, if the portal/subscription is no longer active, does that API key still pose any risk?