Pax8’s email error shows how much MSP data distributors hold
An email attachment sent by mistake to fewer than 40 UK partners held business information on about 1,800 Pax8 partners. The wider question for MSPs is who else holds their customer data

- Pax8 says the file held pricing and program information for 17 Microsoft SKUs and no personal data; recipients told BleepingComputer it listed customer names, license counts and renewal dates.
- Renewal dates and seat counts are commercially sensitive because they tell rivals and criminals when a customer is open to a change.
- MSPs buying through indirect providers should find out what customer data those providers hold, who can export it and how fast they would be told of an incident.
On 13 January a Pax8 employee mistakenly sent an email to fewer than 40 UK partners, the company has said. The attachment included limited internal business information on about 1,800 of the cloud marketplace’s partners, all of them UK-based except one in Canada, according to the incident report Pax8 published on its status page.
Pax8 says the file reflected its pricing and program information for 17 stock-keeping units (SKUs) across four Microsoft Modern Work product categories, and that it contained no personally identifiable information, credentials, payment data or anything enabling system access. Recipients told BleepingComputer, which first reported the incident on 14 January, that it listed customer organization names, Microsoft SKUs, license counts and renewal dates under Microsoft’s new commerce experience (NCE).
For UK managed service providers, the incident raises a question that goes beyond one distributor. How much of an MSP’s commercial picture – who its customers are, how many seats they hold and when they renew – sits with suppliers it does not control, and what has it agreed about how that data is handled?
What Pax8 has said
The facts on the record are narrow. Pax8 says it contacted every recipient and asked them to delete the email and attachment and confirm they had done so. It also launched an internal review. On 15 January it began giving affected partners secure access to the partner-specific information that had been in the attachment, sent to each organization’s primary partner admin.
“We recognize that we have a responsibility to safeguard the partner-confidential information entrusted to us, and we apologize that this incident occurred,” the company said in its 14 January update.
BleepingComputer reported that artifacts shared by several recipients showed more than 56,000 entries. Fields included partner and customer names, product names, bookings, quantities, postal codes and commitment term end dates.
Pax8 says no personal data was involved. For an MSP, though, a list of its customers with their seat counts and renewal dates is close to the whole of its book of business.
Why renewal dates are the sensitive part
Under NCE, Microsoft licenses are sold on monthly or annual commitment terms. Pax8’s own guide to the program describes a seven-day cancellation window for subscriptions. Once that has passed, the end of a term is likely to be the point at which a customer is most open to a new price, a new bundle or a new provider.
A rival who knows when a customer renews, how many users it licenses and which products it runs knows when to call and what to offer. A criminal with the same information has a credible pretext for a phishing email or a fake renewal invoice timed to land when the customer expects one.
Distributors hold this information because of how Microsoft’s cloud solution provider (CSP) program works. When an MSP buys through an indirect provider, that provider transacts the licenses, so it can see the customers and subscriptions involved. BleepingComputer reported that data of this kind would normally be visible only to the MSP managing those customers and to Pax8. Pax8, which says it serves more than 47,000 partners worldwide, is far from the only distributor in that position. Every indirect provider is likely to hold a version of the same map.
A supply chain small customers cannot see
The customers at the end of this chain are likely to be mostly small firms, and official data suggests few of them look at supplier risk at all. The government’s Cyber Security Breaches Survey 2025, based on 2,180 UK businesses surveyed between August and December 2024, found that only 14% reviewed the cybersecurity risks posed by their immediate suppliers and 7% looked at their wider supply chain. Among micro businesses the figure for immediate suppliers was 11%, and among small businesses 21%, against 32% for medium-sized firms.
The survey’s interviews also found that some smaller businesses relied on their third-party IT providers to decide whether to pursue accreditations such as Cyber Essentials. For those customers, the MSP is the supplier they trust, and the distributor behind it is a step they are unlikely ever to see.
That puts the burden on the MSP. If a customer asks who holds its licensing data and how it is protected, the honest answer for most partners in the indirect model is that at least one other company does, under terms the customer may never have read.
What MSPs should ask their distributor
Partners affected by the Pax8 incident can use the secure access Pax8 has set up to see exactly what was in the file about their own business. That is a first step, not the last one.
Every MSP buying through an indirect provider should know what customer-level data that provider holds and who inside it can export it. Partners should ask what controls stop customer data leaving by email, how quickly they will be told when something goes wrong and whether that commitment is written into their agreement. They should also check what their own contracts with customers say about sharing data with suppliers.
None of this is a reason to leave a distributor. Indirect providers give small MSPs access to products, programs and billing they would struggle to run alone, and any of them can be affected by a single human error. But if small businesses rely on their IT providers to judge risk for them, as the government survey suggests, those providers need to hold their own suppliers to the same standard.
The lesson from 13 January is simple: treat the distributor as part of the MSP’s own supply chain and audit it with the rigor partners sell to their customers.
Get The VETTDD BriefingThe week in the technology channel, every week.
Subscribe freeSources
- Pax8, “January 13th Incident Report”, Pax8 Platform status page, updates of 13, 14 and 15 January 2026. https://status.pax8.com/incidents/ndmn6zrpnxjp
- BleepingComputer, “Cloud marketplace Pax8 accidentally exposes data on 1,800 MSP partners”, 14 January 2026. https://www.bleepingcomputer.com/news/security/cloud-marketplace-pax8-accidentally-exposes-data-on-1-800-msp-partners/
- IT Channel Oxygen, “Pax8 launches internal review after email blunder”, 15 January 2026. https://itchanneloxygen.com/pax8-launches-internal-review-after-email-blunder/
- Pax8, “Microsoft CSP new commerce experience”, blog, updated 7 July 2025. https://www.pax8.com/blog/microsoft-csp-new-commerce-experience/
- Department for Science, Innovation and Technology, “Cyber Security Breaches Survey 2025”, official statistics, 10 April 2025. https://www.gov.uk/government/statistics/cyber-security-breaches-survey-2025/cyber-security-breaches-survey-2025




