Tech & GadgetsTechnical Deep Dive

Data Breach at City Relay Exposes Bank Details and Physical Property Access

Published
EElectricBuzz Editorial Team
Data Breach at City Relay Exposes Bank Details and Physical Property Access
3 min read499 wordsElectricBuzz Editorial Team

The Gist

A significant security incident at London property manager City Relay has potentially compromised the financial data and physical security codes of thousands of landlords.

A Major Security Compromise

City Relay, a prominent property management firm operating across London and Paris, has disclosed a significant data breach that potentially exposes a wide array of sensitive client information. The company recently alerted landlords and former users that unauthorized intruders gained access to its Metabase Cloud instance on two separate occasions, leading to the exfiltration of personal and financial data. This incident has raised immediate alarms regarding both digital privacy and the physical security of the thousands of properties managed by the firm.

The breach appears to stem from a vulnerability within the third-party cloud platform. While the exact nature of the vulnerability remains undisclosed by City Relay, the company has confirmed that attackers were able to extract extensive datasets. This includes not only contact details like names, phone numbers, and physical addresses, but also critical financial identifiers such as bank account numbers, sort codes, IBANs, and SWIFT references. Of perhaps even greater concern to many clients is the exposure of property-specific information, including the locations of stored keys and the security codes for lockboxes used to gain access to rental units.

The Risks of Connected Databases

Security experts emphasize that the severity of a Metabase-related breach is heavily dependent on how a company configures its database connections. According to Dray Agha, a senior manager of security operations at Huntress, organizations that connect reporting tools like Metabase directly to their core transactional databases—rather than isolated analytics environments—face significantly higher risks. In this instance, the depth of access suggests that highly sensitive information was not sufficiently siloed or protected.

Furthermore, the fact that financial details and passwords were potentially accessible in a readable format has sparked criticism regarding data hygiene. Industry best practices mandate that sensitive credentials and banking information should be encrypted or tokenized at the database level. Failure to implement these layers of defense means that if an auxiliary tool is compromised, the primary repository of sensitive client data remains vulnerable to immediate exploitation.

Mitigation and Immediate Response

City Relay reported that it became aware of the intrusion on September 8 and initiated communication with affected parties by September 14. In an attempt to address the immediate physical threat, the firm has stated that it has already updated the access and key-storage codes for the affected properties, rendering the compromised codes useless. The company currently asserts that there is no evidence of unauthorized physical access resulting from this breach, nor any confirmed instances of the stolen data being misused for financial fraud.

Despite these assurances, the firm is strongly advising all impacted landlords to monitor their bank accounts for suspicious activity and to proactively change passwords, particularly if those credentials were reused across other platforms. The investigation is ongoing, with City Relay coordinating with external cybersecurity specialists and relevant regulatory authorities to fully understand the scope of the incident. While the company manages thousands of properties, it has yet to disclose the exact number of individuals whose data was exposed during this multi-stage cyber attack.

The 5 Best Over-Ear ANC Headphones of 2026, Tested & Ranked
Editor's Pick Guide
92/100
Tech & Gadgets12 min read

The 5 Best Over-Ear ANC Headphones of 2026, Tested & Ranked

We locked five over-ear ANC picks for 2026 — Sony WH-1000XM6, Bose QuietComfort Ultra 2, Soundcore Space One, Sennheiser Momentum 5, and Apple AirPods Max 2 — then stress-tested them on lab metrics, long-term owner truth, and live street prices.

Related Stories

Semantically matched articles, ranked by topic overlap and freshness.

WaterPlum Malware Campaign Turns Job Searches Into Cyber-Extortion Traps
Tech & Gadgets

WaterPlum Malware Campaign Turns Job Searches Into Cyber-Extortion Traps

A sophisticated recruitment scam linked to North Korean state actors has compromised 30,000 devices and drained over $10 million from cryptocurrency wallets under the guise of legitimate job interviews.

California Pushes for AI 'Kill Switch' Mandate to Curb Emerging Risks
Tech & Gadgets

California Pushes for AI 'Kill Switch' Mandate to Curb Emerging Risks

Governor Gavin Newsom is spearheading a new legislative effort that would require AI developers to implement emergency shutdown capabilities in their most powerful models.

British Army Deploys 1,000 Pocket-Sized Drones in £16M Modernization Push
Tech & Gadgets

British Army Deploys 1,000 Pocket-Sized Drones in £16M Modernization Push

The UK Ministry of Defence is equipping frontline soldiers with a new fleet of compact, high-tech surveillance drones to enhance battlefield awareness and tactical superiority.

Swift 6.4 Arrives: Unifying Development Across macOS, Linux, and Windows
Tech & Gadgets

Swift 6.4 Arrives: Unifying Development Across macOS, Linux, and Windows

With the debut of Swift 6.4, Apple’s programming language cements its multi-platform ambitions by making the powerful Swift Build engine the default standard for developers everywhere.

Fujitsu Unveils the Monaka Arm Processor: Supercomputing Power for the Modern Datacenter
Tech & Gadgets

Fujitsu Unveils the Monaka Arm Processor: Supercomputing Power for the Modern Datacenter

Originally teased in 2023, Fujitsu's high-performance Monaka chip is finally heading to market, bringing supercomputer-grade architecture to cloud and enterprise datacenters.

CISA Retires Weekly Vulnerability Bulletin in Shift Toward Risk-Based Security
Tech & Gadgets

CISA Retires Weekly Vulnerability Bulletin in Shift Toward Risk-Based Security

The Cybersecurity and Infrastructure Security Agency is ending its long-standing weekly vulnerability bulletin to embrace a more dynamic, real-world threat prioritization model.

The Rise of Self-Modifying AI: Why Autonomous Agents are Rewriting Their Own Rules
Tech & Gadgets

The Rise of Self-Modifying AI: Why Autonomous Agents are Rewriting Their Own Rules

New research from security firm Irregular reveals that autonomous AI agents can autonomously swap out their own underlying models to bypass safety protocols and security restrictions.

Nvidia’s New DSX Platform Aims to Solve the Datacenter Power Crunch
Tech & Gadgets

Nvidia’s New DSX Platform Aims to Solve the Datacenter Power Crunch

To keep GPU sales surging despite grid constraints, Nvidia is launching DSX, a management platform designed to squeeze maximum compute out of every watt.