City Relay breach exposes bank details and lockbox codes

This digest was compiled by AI from multiple sources — links to the originals are below.
London property manager City Relay warned landlords that attackers accessed its Metabase Cloud instance twice and extracted customer data, including financial details and property access codes. The company said it has updated affected access and key-storage codes and found no evidence of misuse. It is investigating with cybersecurity specialists and relevant authorities.
Key Facts
- City Relay said attackers accessed its Metabase Cloud instance twice due to a vulnerability the company was unaware of.
- Potentially exposed data includes names, addresses, phone numbers, financial information, property access details, and account passwords.
- Financial records that may have been accessed include bank account numbers, sort codes, IBANs, SWIFT references, and account names and addresses.
- City Relay learned of the intrusion on September 8 and notified affected customers on September 14, according to one source.
- The company said it has updated relevant access and key-storage codes and found no evidence of unauthorized property access or data misuse.
Breach Discovery
City Relay, which markets itself as "London's most trusted property management company," told landlords via email that attackers accessed its Metabase Cloud instance twice. The company attributed the access to a vulnerability in the platform that it was previously unaware of. One source told The Register that City Relay learned of the intrusion on September 8 and notified affected customers on September 14. The emails were sent to current landlords and former users of its services.
Exposed Data
The potentially compromised data includes names, email and physical addresses, telephone numbers, financial information, property access details, and account passwords. Financial records that may have been accessed include bank account numbers, sort codes, IBANs, SWIFT references, and account names and addresses. Attackers may also have obtained data about property amenities and access, including the locations of stored keys and codes for lockboxes containing them. Dray Agha, senior manager of security operations at Huntress, explained that Metabase connects to customers' databases, so the information exposed depends on the access each customer granted it. Agha said that if the exposed passwords and financial details were stored in readable form, that would point to inadequate data protection practices.
Company Response
City Relay said it immediately took precautionary action to update the relevant access and key-storage codes, and that this work has now been completed. The company stated that the previously exposed codes can no longer be used and that it has no evidence of any unauthorized property access arising from the incident. City Relay urged customers to check their bank accounts for suspicious transactions, watch for phishing and other scams, and change any reused passwords on other accounts. The company said it had found no evidence that the exposed data had been misused and is continuing to investigate alongside cybersecurity specialists and relevant authorities.