Skip to main content
Emerging ThreatsData Breaches

City Relay Breach Exposes London Property Managers' Financial Data

London cityscape with office building and subtle digital interface hint.

"Personal data was extracted from the platform," City Relay warned landlords in an email, a disclosure seen by The Register that confirmed intruders had accessed a third‑party Metabase Cloud instance connected to the firm's systems.

City Relay's notification to landlords and immediate actions

City Relay — which markets itself as "London's most trusted property management company" and says it manages, or has managed, thousands of London properties — told current landlords and former users by email that attackers accessed the third‑party cloud twice "as a result of a vulnerability in the platform that we were unaware of." The company said it had found no evidence the exposed data had been misused and that it is continuing to investigate alongside cybersecurity specialists and "the relevant authorities."

One source told The Register that City Relay learned of the intrusion on September 8 and notified affected customers on September 14. Because "property access and key‑storage information was potentially included," the firm said it immediately updated relevant access and key‑storage codes. "This work has now been completed. The previously exposed codes can no longer be used and we have no evidence of any unauthorised property access arising from the incident," the email stated.

Data reportedly exposed: bank details, passwords, and lockbox codes

The email listed a wide range of potentially compromised material. City Relay said the platform contained names, email and physical addresses, telephone numbers, financial information, property access details, and account passwords. The firm specified exposed financial data as including "bank account numbers, sort codes, IBANs, SWIFT references, and account names and addresses."

Critically for physical security, City Relay warned attackers may also have obtained data about property amenities and access, including the locations of stored keys and codes for lockboxes containing them. As a precaution the company urged customers to check bank accounts for suspicious transactions, watch for phishing and other scams, and change any reused passwords on other accounts.

Metabase Cloud: a disclosed zero‑day and an uncertain link

City Relay said attackers accessed a Metabase Cloud instance supplied by a third party, but the company did not identify the specific vulnerability used in the attack. Separately, Metabase disclosed a zero‑day SQL injection flaw on August 6 and said attackers compromised fewer than 3 percent of its customers before fixes were automatically deployed. Metabase has not confirmed that the City Relay incident was part of that campaign. Known victims of the earlier Metabase campaign included laptop maker Framework and workflow automation platform n8n, according to reporting.

Huntress senior manager Dray Agha on how exposure depends on integrations

Dray Agha, senior manager of security operations at Huntress, explained why the same Metabase compromise can produce widely different outcomes for customers: "Metabase connects to customers' databases, so the information exposed in an attack depends on the access each customer granted it." Agha said a company linking Metabase to a general analytics database risks only "harmless user metrics," while "a company that connects it directly to their core transactional database risks exposing highly sensitive financial records and credentials."

Agha also pointed to data‑protection shortcomings implied by the City Relay disclosure: if the exposed passwords and financial details were stored in readable form, "that would point to inadequate data protection practices." He added, "Sensitive financial details should also be encrypted or tokenized when held in a database. Keeping this information readable creates a massive risk if a connected reporting tool is ever compromised."

What this means for landlords, tenants, and property managers

  • Landlords and former City Relay partners: the company explicitly advised checking bank accounts for suspicious transactions, watching for phishing and other scams, and changing any passwords reused elsewhere. The email was sent to current landlords and former users, underscoring that both groups may need to act.
  • Tenants and people with physical access to affected properties: because lockbox locations and codes may have been exposed, tenants and property owners should confirm that City Relay's reported updates to access and key‑storage codes have been completed and that no unauthorised access has occurred.
  • Property managers and procurement leads: the incident highlights that connected reporting tools can serve as routes to sensitive transactional data depending on how they are integrated. As Huntress noted, where a reporting tool is given direct access to core transactional databases, the potential for exposing financial records and credentials increases.

City Relay has not said how many customers were affected in London or Paris, where it also operates, and it did not identify the vulnerability used in the attack. With Metabase's August 6 zero‑day campaign remaining an unresolved reference point — and Metabase not confirming a direct link to City Relay — the full scope and provenance of this breach remain open questions that the company's ongoing investigation and any regulatory inquiries will need to answer.

Original story at The Register