LatestLabour’s ‘chaotic’ zero-hour crackdown could cost firms £3bn per year

Canadian business, markets & economy · Thursday, 13 August 2026

Business

US investors watch as IT consultant ordered to repay £50,000 over Soho House data breach

An IT consultant was ordered to repay £50,000 after threatening to expose data on thousands of Soho House members, a case that draws interest from US investors and raises Canadian privacy concerns.

US investors watch as IT consultant ordered to repay £50,000 over Soho House data breach

The case, which has drawn attention from US investors in the global members' club, saw Amit Sharma ordered to repay £50,000 after being accused of stealing personal details of Soho House members.

Soho House data breach allegations

Sharma allegedly threatened to leak personal information of more than 50,000 members of Soho House unless he was sent a "seven figure" sum following a dispute over pay with his employer.

The consultant, who worked for IT firm Espire Infolabs, had been seconded to the private members' club to work on an IT project which involved access to personal data of members including addresses, bank and payment card details.

He later fell out with Espire, citing harassment from colleagues, and sought a settlement to exit the company.

After being dissatisfied with the termination payment from Espire, in July last year Sharma began writing emails to Soho House and its members, threatening to release their personal information unless he received "no less than seven figures", according to a civil court judgment published earlier this month.

"Your address and other sensitive details are leaked and [the club] is trying to cover this [up]," Sharma wrote to some Soho House members.

"You're going to be listed as a rich person in your neighbourhood for all kind [sic] of people. Your personal safety, security and family has been breached."

Sharma also wrote to journalists and said the club "gave me unsolicited access to very high profile and elite clients, across the globe" and gave a list of examples.

A week later, Soho House reported the messages to the Information Commissioner's Office and notified the police, who arrested Sharma the following day and seized his electronic devices.

Sharma later wrote to Espire's lawyers vowing to delete the data, adding: "I have learned my lesson."

Legal outcome and broader implications

Appearing before a civil court last month, the consultant said he suffered bullying and harassment throughout his employment, citing Espire's large exit settlement as evidence. He was ordered to repay the £50,000 settlement.

Soho House declined to comment. It is understood that the consultant only obtained the details of a small number of members but claimed to have tens of thousands of their details to use as a bargaining chip.

Founded in Greek Street in Soho in 1995, Soho House has since grown into a global members' club with more than a quarter of a million members across dozens of venues.

The firm floated on the New York Stock Exchange in 2021 before being taken private last year by US hotel operator MCR in a $2.7bn (£2bn) deal.

The involvement of US investors underscores how data‑security incidents at internationally listed firms can affect shareholders in both countries. Canadian privacy regulators have warned that similar breaches could trigger investigations under the Personal Information Protection and Electronic Documents Act, highlighting the relevance of this case for Canadian businesses.

About the author

Raj Patel

Reporting for CityAM Canada on business and the wider Canadian economy.

All work by Raj Patel ›