London Property Manager Breach Exposes Bank Details and Key Lockbox Codes
London-based City Relay has told landlords and former customers that intruders compromised its Metabase Cloud instance on two occasions, extracting personal and financial data. The exposed information reportedly includes names, addresses, phone numbers, bank account numbers, sort codes, IBANs, SWIFT references, and account passwords. Attackers may also have obtained details about property access, including the location of stored keys and codes for lockboxes.
City Relay said the breach resulted from a vulnerability in the platform it was unaware of. According to reports, the company learned of the intrusion on 8 September and notified affected customers on 14 September, taking precautionary steps to update access and key storage codes.
Security experts note that the scale of exposure in such incidents depends on what data a company connects to tools like Metabase. Analytics platforms linked only to general usage data pose limited risk, but those connected directly to core databases containing financial records or credentials can expose highly sensitive information, particularly if that data is stored without encryption or tokenisation.