If accurate this means any mailgun user can pretend to be another one when sending email out- that's pretty damn bad. Since companies add mailgun to their SPF/DKIM records it means those spoofed emails will be hard to distinguish as fake.
I didn’t know I needed proof because people often resorted to victim blaming even though I never fell for any of the emails
Mailgun should have a way to monitor and block this. We used SMTP to interface with Mailgun and frankly, I didn't even think of this as being a vulnerability until I left the service. The DMARC reports just prove it was happening.