Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

LONDON PROPERTY MANAGEMENT COMPANY CITY RELAY BREACH MAY HAVE EXPOSED BANK DETAILS AND LOCKBOX CODES




London property management company City Relay has issued a warning to its customers after a breach may have exposed sensitive information, including bank details and lockbox codes. The breach is believed to have occurred due to a vulnerability in the Metabase Cloud instance. City Relay has urged its customers to be cautious and has taken steps to update the relevant access and key-storage codes. The breach has raised concerns about the security of property management companies and the potential risks of third-party provided cloud services.

  • The breach at City Relay may have exposed sensitive information, including bank details and lockbox codes.
  • The breach is believed to have occurred due to a vulnerability in the Metabase Cloud instance.
  • The exposed data may have included names, email addresses, physical addresses, telephone numbers, financial information, and account passwords.
  • City Relay has taken steps to update the relevant access and key-storage codes and notified affected customers of the breach.
  • The breach highlights the importance of adequate data protection practices and cybersecurity awareness.



  • London property management company City Relay has issued a warning to its customers after a breach may have exposed sensitive information, including bank details and lockbox codes. The breach is believed to have occurred due to a vulnerability in the Metabase Cloud instance, which was accessed twice by intruders.

    According to City Relay, the breach may have exposed personal data, including names, email addresses, physical addresses, telephone numbers, financial information, property access details, and account passwords. The company has also stated that the exposed financial data may have included bank account numbers, sort codes, IBANs, SWIFT references, and account names and addresses.

    The breach has raised concerns about the security of property management companies and the potential risks of third-party provided cloud services. Dray Agha, senior manager of security operations at Huntress, has highlighted the importance of adequate data protection practices, stating that sensitive financial details should be encrypted or tokenized when held in a database.

    City Relay has taken steps to update the relevant access and key-storage codes and has notified affected customers of the breach. The company has also urged its customers to check their bank accounts for suspicious transactions, watch for phishing and other scams, and change any reused passwords on other accounts.

    The breach has also raised questions about the responsibility of property management companies to protect their customers' data. City Relay has not identified the vulnerability used in the attack, and Metabase has disclosed a zero-day SQL injection flaw on August 6, but it has not confirmed that the City Relay incident was part of that campaign.

    The breach has also highlighted the importance of cybersecurity awareness and the need for companies to prioritize data protection. City Relay has emphasized the importance of caution and has urged its customers to be vigilant in protecting their data.

    In conclusion, the breach at City Relay has raised important questions about the security of property management companies and the potential risks of third-party provided cloud services. The company's response to the breach has highlighted the importance of adequate data protection practices and the need for companies to prioritize data protection.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/LONDON-PROPERTY-MANAGEMENT-COMPANY-CITY-RELAY-BREACH-MAY-HAVE-EXPOSED-BANK-DETAILS-AND-LOCKBOX-CODES-ehn.shtml

  • https://www.theregister.com/security/2026/09/17/london-property-manager-breach-may-have-exposed-bank-details-and-lockbox-codes/5297232


  • Published: Thu Sep 17 15:52:31 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us