Pax8 Accidentally Exposes Sensitive Business Data of 1,800 MSP Partners

  • Pax8, a cloud commerce marketplace and distributor used by managed service providers (MSPs), accidentally exposed business data of about 1,800 MSP partners when an email was sent with a spreadsheet attachment to fewer than 40 UK-based partners.
  • The email, titled “Potential Business Premium Upgrade Tactic to Save Money,” contained a CSV file that included internal partner information.

What was in the exposed file

The spreadsheet reportedly had over 56,000 entries containing fields such as:

  • Partner and customer organization names and IDs
  • Microsoft license SKUs and license counts
  • Renewal dates and program status
  • Territory, gross/net bookings, and other business metadata

Pax8 says the file did not contain personally identifiable information (PII), but it did include limited internal business and licensing details that partners normally expect to stay confidential.

Pax8’s response

  • The employee who sent the email attempted to recall the message and then sent a follow-up email asking recipients to delete the original email and attachment.
  • Pax8 is conducting an internal review of the incident and is contacting partners one-on-one to confirm deletion and prevent future occurrences.
  • According to Pax8’s follow-up, the incident did not impact the security of the marketplace platform itself.

Potential risks and reactions

  • Industry sources say threat actors have approached some affected MSPs trying to buy the leaked dataset, which could be used for competitive targeting or cybercriminal campaigns such as phishing or business email compromise.
  • Exposure of licensing and customer portfolio details might help competitors identify client contracts or pricing strategies.

What it means for partners

Even though Pax8 characterizes the leak as business information rather than personal data, such details can still be sensitive:

  • Competitors could glean insights about MSP customer bases.
  • Cybercriminals could use product and renewal info for highly targeted attacks.