Hi,
According to the documentation, you need both the MeshID and Api key to use the Mesh API, if you confirm both were compromised then you can have your data exposed. I imagine that you created the API key following the instructions detailed here: https://developer.adobe.com/graphql-mesh-gateway/gateway/create-mesh/#manually-create-an-api-key-opt... if so, you can delete the existing API key which got compromised and create a new one.
Hope this helps.
Esteban Bustamante