London property manager breach may have exposed bank details and lockbox codes
City Relay says intruders accessed its Metabase Cloud instance twice and extracted customer data
London property management firm City Relay has informed its customers that their financial data, passwords, and lockbox access codes may have been stolen by intruders who breached the company's Metabase Cloud instance. The breach occurred due to a vulnerability in the third-party cloud platform that City Relay was unaware of. City Relay notified landlords via email, stating that personal data, including names, email addresses, telephone numbers, financial information, property access details, and account passwords, were extracted from the platform.
The exposed financial data encompassed bank account numbers, sort codes, IBANs, SWIFT references, account names, and addresses. Attackers might have also obtained information about property amenities and access, including stored key locations and codes. According to Dray Agha, a senior manager of security operations at Huntress, the exposed information depends on the level of access City Relay granted Metabase.
If passwords and financial details were stored in a readable format, it would indicate insufficient data protection practices. City Relay has taken precautionary measures by updating access and key-storage codes, which are now invalid. The company advises customers to monitor their bank accounts for unusual transactions, watch for phishing and scams, and change reused passwords on other accounts.
City Relay has not identified the vulnerability exploited in the attack and stated that no evidence suggests the exposed data has been misused. The company continues to investigate alongside cybersecurity specialists and relevant authorities to determine the full scope of the incident.
Written by urgent.news from The Register's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.