A Major Security Compromise
City Relay, a prominent property management firm operating across London and Paris, has disclosed a significant data breach that potentially exposes a wide array of sensitive client information. The company recently alerted landlords and former users that unauthorized intruders gained access to its Metabase Cloud instance on two separate occasions, leading to the exfiltration of personal and financial data. This incident has raised immediate alarms regarding both digital privacy and the physical security of the thousands of properties managed by the firm.
The breach appears to stem from a vulnerability within the third-party cloud platform. While the exact nature of the vulnerability remains undisclosed by City Relay, the company has confirmed that attackers were able to extract extensive datasets. This includes not only contact details like names, phone numbers, and physical addresses, but also critical financial identifiers such as bank account numbers, sort codes, IBANs, and SWIFT references. Of perhaps even greater concern to many clients is the exposure of property-specific information, including the locations of stored keys and the security codes for lockboxes used to gain access to rental units.
The Risks of Connected Databases
Security experts emphasize that the severity of a Metabase-related breach is heavily dependent on how a company configures its database connections. According to Dray Agha, a senior manager of security operations at Huntress, organizations that connect reporting tools like Metabase directly to their core transactional databases—rather than isolated analytics environments—face significantly higher risks. In this instance, the depth of access suggests that highly sensitive information was not sufficiently siloed or protected.
Furthermore, the fact that financial details and passwords were potentially accessible in a readable format has sparked criticism regarding data hygiene. Industry best practices mandate that sensitive credentials and banking information should be encrypted or tokenized at the database level. Failure to implement these layers of defense means that if an auxiliary tool is compromised, the primary repository of sensitive client data remains vulnerable to immediate exploitation.
Mitigation and Immediate Response
City Relay reported that it became aware of the intrusion on September 8 and initiated communication with affected parties by September 14. In an attempt to address the immediate physical threat, the firm has stated that it has already updated the access and key-storage codes for the affected properties, rendering the compromised codes useless. The company currently asserts that there is no evidence of unauthorized physical access resulting from this breach, nor any confirmed instances of the stolen data being misused for financial fraud.
Despite these assurances, the firm is strongly advising all impacted landlords to monitor their bank accounts for suspicious activity and to proactively change passwords, particularly if those credentials were reused across other platforms. The investigation is ongoing, with City Relay coordinating with external cybersecurity specialists and relevant regulatory authorities to fully understand the scope of the incident. While the company manages thousands of properties, it has yet to disclose the exact number of individuals whose data was exposed during this multi-stage cyber attack.











