Cloud marketplace and distributor Pax8 confirmed an accidental data leak after an internal spreadsheet/CSV containing sensitive business information was mistakenly emailed to fewer than 40 UK-based partners. The file—titled "Potential Business Premium Upgrade Tactic to Save Money"—was sent on January 13 by a strategic account manager and included details that recipients said exposed MSP customer organization names and Microsoft licensing information (e.g., SKUs, license counts, and New Commerce Experience (NCE) renewal dates). Pax8 attempted to recall the email and followed up asking recipients to delete the message and attachment.
Artifacts reviewed by reporting indicated the dataset contained 56,000+ entries and fields such as partner/customer names and IDs, product/vendor details, bookings, quantities, territory/account owner, provision/cancellation dates, transaction type, commitment term end date, and postal code. Pax8 stated the file did not include personally identifiable information (PII), but it did expose commercially sensitive intelligence (pricing/program and partner management data) affecting roughly 1,800 partners (primarily UK-based, with one noted in Canada). Industry sources cited in coverage warned that threat actors are attempting to acquire the dataset, raising risks of competitive targeting, phishing, and extortion using exposed customer and licensing context.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Pax8 confirmed that the mistakenly emailed spreadsheet exposed sensitive business information to fewer than 40 UK-based partners and stated that no personally identifiable information was included. Public reporting on January 14-15, 2026, detailed the scope of the exposed customer and Microsoft licensing data.
By the time the incident was reported publicly, industry sources said threat actors were approaching some affected MSPs to buy copies of the leaked spreadsheet. The data was seen as potentially useful for competitive intelligence, phishing, business email compromise, or extortion tied to renewal dates.
After discovering the mistaken disclosure, Pax8 attempted to recall the email, contacted recipients directly, and asked them to delete the message and attachment while confirming they had not forwarded it. The company also said it launched an internal review to prevent a recurrence.
On 2026-01-13, a Pax8 EMEA strategic account manager sent an email titled “Potential Business Premium Upgrade Tactic to Save Money” to fewer than 40 UK-based MSP partners with an attached CSV containing internal business data. The spreadsheet reportedly included more than 56,000 entries covering MSP customer organization names, Microsoft licensing details, pricing information, and program management data.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.