Cloud marketplace and reseller Pax8 has confirmed that it accidentally sent an email to fewer than 40 partners in the UK containing a spreadsheet of internal business information, including MSP customer data and Microsoft licenses. Pax8 is a fast-growing cloud commerce marketplace with more than 1,700 employees, over 47,000 partners worldwide and operations in 18 countries.
See also: Patch Tuesday 2025 review: Microsoft's biggest vulnerabilities of the year

The company recently surpassed $2 billion in annual revenue, with particularly strong growth in Europe. The email, titled “Possible Business Premium Upgrade Tactics to Save Money,” was sent on January 13 by a strategic account manager based in EMEA and included an attached CSV file.
According to Pax8, the file contained internal Microsoft pricing and program information affecting approximately 1,800 partners, primarily in the UK, with one in Canada — and was accidentally distributed to fewer than 40 recipients in the UK. MSPs who received the message said the CSV file included customer organization names, Microsoft SKUs, license numbers, and New Commerce Experience (NCE) renewal dates.
Evidence shared by multiple recipients reveals that the leaked spreadsheet contained more than 56,000 entries with fields such as:
– Customer Name and ID
– Supplier Name and Product Name
– Gross & Net Reservations
– Total Currency Quantity
– Terms Commitment Expiration Date
Shortly after sending the email, the sender attempted to retract the message and later followed up with another email asking recipients to delete the original message and attachment, acknowledging that it had been sent in error.
See also: Traditional security frameworks leave organizations exposed to AI attacks

In the subsequent notification, Pax8 told partners that the file did not contain personally identifiable information but limited business information that may reveal MSP pricing and Microsoft program management data. Such information, including customer portfolios and license fingerprints, would normally be visible only to the MSP managing those customers and to Pax8 itself.
Importantly, there is no impact to the availability or security controls of the Market as a result of this incident. What Pax8 immediately did:
– Contact each recipient immediately and request that the email and attachment be deleted
– Require confirmation of deletion and non-forwarding
– Conducted individual follow-up calls with recipients to reinforce deletion and confirm completion
– Initiated an internal review to determine how this happened and prevent a recurrence
What to do: No action is required from you.
For competing MSPs, the list could reveal which organizations use Pax8 as their distributor, the size of each customer's Microsoft environment, contract renewal timelines, and potentially the price levels paid — data that could be used for competitive targeting or seduction.
See also: The top 5 AI security threats for 2025

For malicious actors, the dataset could act as a high-quality targeting list, identifying organizations using specific Microsoft products, the scale of their deployments, and which MSP manages their environment.
