
A cybersecurity incident at a London-based property management company has raised fresh alarm about how much sensitive data landlords hand over to third-party cloud tools — and what happens when those tools get hacked. City Relay, which describes itself as one of the capital’s most trusted property managers, has told customers that intruders may have stolen bank details, passwords, and even the codes used to unlock properties, after its Metabase Cloud instance was breached twice. The London property data breach is now under investigation by cybersecurity specialists and unnamed authorities, according to details reviewed by The Register.
Key takeaways
- City Relay’s Metabase Cloud instance was compromised twice through a platform vulnerability the company says it was unaware of.
- Exposed data may include names, addresses, phone numbers, passwords, and financial details such as bank account numbers, IBANs, and SWIFT codes.
- Lockbox codes and key-storage locations were also potentially exposed, creating a physical break-in risk at managed properties.
- City Relay learned of the intrusion around September 8 and notified affected customers on September 14, immediately resetting access codes.
- The company says it has found no evidence yet of unauthorized property entry or misuse of the stolen data.
City Relay Metabase Cloud Breach Overview
City Relay’s cloud analytics platform, Metabase, was breached not once but twice, through what the company calls an unknown flaw in the third-party service. In an email sent to landlords and reviewed by The Register, the firm said attackers accessed the platform “as a result of a vulnerability in the platform that we were unaware of,” and that “personal data was extracted from the platform” as a result.
Details of the double compromise
City Relay has not disclosed exactly how the second intrusion occurred or whether it exploited the same weakness as the first. What is clear is that the breach did not happen once and get patched — it happened twice, which suggests the underlying vulnerability was either missed or reopened before the company caught it. The company has also not said how many customers or properties were affected, despite managing thousands of properties across London and, to a lesser extent, Paris.
Types of exposed data
The scope of what may have leaked is broad. City Relay reported that data potentially exposed in the breach spans names, email and physical addresses, telephone numbers, financial information, property access details, and account passwords. On the financial side, the exposure reportedly covers bank account numbers, sort codes, IBANs, SWIFT references, and the names and addresses tied to those accounts.
Perhaps most unsettling for tenants and landlords alike, the attackers may also have obtained data tied to physical property access — including where keys are stored and the codes needed to open lockboxes containing them. That combination of financial and physical-security data is what sets this incident apart from a typical customer-data leak.
Company Response and Investigation
City Relay moved to contain the fallout by resetting every access and key-storage code tied to the exposed data, and it says that work is already finished. The company’s notification to customers, sent roughly a week after it discovered the intrusion, framed the response as immediate and precautionary rather than reactive to any confirmed misuse.
Notification and mitigation measures
One source told The Register that City Relay first learned of the intrusion on September 8 and reached out to affected customers on September 14. The company’s email stated: “As property access and key-storage information was potentially included, we immediately took precautionary action to update the relevant access and key-storage codes.” It added that “this work has now been completed” and that the previously exposed codes “can no longer be used.”
Beyond resetting physical access codes, City Relay urged customers to monitor their bank accounts for suspicious activity, stay alert for phishing attempts, and change any passwords reused across other accounts — standard advice, but a reminder of how far the blast radius of a single cloud breach can extend.
Ongoing forensic and regulatory actions
City Relay says it has found no evidence that the exposed data has actually been misused, and specifically stated it has “no evidence of any unauthorised property access arising from the incident.” The company said it is continuing to investigate alongside cybersecurity specialists and “the relevant authorities” to determine the full scope of the attack — language that leaves open just how large the breach ultimately turns out to be.
Security Context and Expert Insights
The breach lands just weeks after Metabase itself disclosed a serious flaw in its own platform. On August 6, Metabase revealed a zero-day SQL injection vulnerability, saying attackers had compromised fewer than 3 percent of its customers before the company automatically deployed a fix. Metabase has not confirmed whether the City Relay incident was connected to that same campaign, so the exact cause of City Relay’s breach remains officially unattributed.
Dray Agha, senior manager of security operations at Huntress, explained that Metabase connects directly into whatever database a customer links it to — meaning the real-world damage from any breach depends entirely on what access each client granted. “A company linking Metabase to a general analytics database will only expose harmless user metrics,” Agha said. “A company that connects it directly to their core transactional database risks exposing highly sensitive financial records and credentials.”
Agha also flagged a deeper concern: if the exposed passwords and financial details were stored in plain, readable form rather than encrypted, that points to a more basic failure in how the data was handled in the first place. “Sensitive financial details should also be encrypted or tokenized when held in a database,” he said. “Keeping this information readable creates a massive risk if a connected reporting tool is ever compromised.”
That warning cuts to the heart of why this incident matters beyond City Relay itself. Property managers, letting agents, and similar businesses routinely feed landlord and tenant data into analytics and reporting tools without necessarily auditing how that data is stored on the other end. When a connected platform like Metabase gets hit — as it was with laptop maker Framework and workflow automation platform n8n, both also named among known victims of the earlier zero-day — the consequences ripple out to every downstream customer who trusted it with sensitive records.
For now, City Relay says its investigation is ongoing and it has seen no confirmed fraud or unauthorized entry linked to the breach. Whether that holds as forensic work continues — and whether regulators eventually weigh in on how the incident was disclosed — remains to be seen.
FAQ
What data was exposed in the City Relay breach?
Attackers may have accessed personal information including names, addresses, phone numbers, financial details, passwords, and property access codes.
Has there been any evidence of misuse of the stolen data?
City Relay reported no evidence so far of unauthorized property access or misuse of the exposed data.
When did City Relay inform customers and what actions were taken?
City Relay notified customers on September 14 and immediately updated access and key-storage codes to prevent misuse.
What security vulnerability is linked to this breach?
Metabase disclosed a zero-day SQL injection flaw fixed on August 6, but it is unclear if it was the cause of this breach.
Article produced with the assistance of artificial intelligence and reviewed by the editorial team.

6 hours ago
28







English (US) ·