Back Computing Hackers breach London property manager's cloud system, exposing customer data
London property management company City Relay has warned landlords that attackers may have accessed sensitive details after breaching its cloud analytics system.
City Relay said intruders gained access to its Metabase Cloud instance twice, exploiting a vulnerability the company said it was previously unaware of.
The incident may have exposed personal and financial information belonging to current and former customers, as well as details that could be used to access properties.
In a notification sent to customers, City Relay said that "personal data was extracted from the platform," which potentially includes names, addresses, telephone numbers, email IDs and account passwords.
Financial records that may have been accessed include bank account numbers, sort codes, IBANs and SWIFT references, as well as account names and addresses.
The breach could also have implications for the physical security of properties the company manages.
Information stored in the system included details property amenities and access arrangements, including where keys were kept and codes for lockboxes.
One source told The Register that the company became aware of the intrusion on 8 th September and contacted affected customers six days later.
City Relay said it had found no evidence that the stolen information had been misused.
The company says it has taken precautionary measures to change relevant access and key-storage codes.
The company operates in London and Paris and claims to work with hundreds of landlords, managing or having previously managed thousands of properties.
It has not disclosed how many customers were affected or provided a detailed explanation of how the attackers gained access to its Metabase Cloud environment.
It has advised landlords to monitor their bank accounts for unusual activity, remain alert to phishing attempts and change passwords that may have been reused on other services.
Metabase vulnerability under investigation
Metabase provides business intelligence and analytics software that can connect to an organisation's databases. Metabase Cloud is operated as a managed service.
Dray Agha, senior manager of security operations at Huntress, said the potential impact of a Metabase breach depends heavily on what information the customer has made accessible to the platform.
An organisation using Metabase with a limited analytics database could face exposure of relatively low-risk information, he said. But connecting it directly to a transactional database could give attackers access to financial records and other sensitive data.
Metabase disclosed a zero-day SQL injection vulnerability last month, stating that attackers had compromised fewer than 3% of its customers before fixes were deployed.
Several organisations have subsequently reported incidents involving their Metabase environments. For example, laptop manufacturer Framework confirmed that attackers had stolen customer information after compromising its Metabase instance.
Metabase has not confirmed that the City Relay incident was connected to the same campaign, while City Relay has not disclosed which vulnerability was exploited.
The incident comes amid a series of recent security breaches affecting companies holding sensitive customer information.
UK fintech Revolut this week disclosed a separate incident in which an unauthorised third party obtained customer information by sending fraudulent requests from an email domain belonging to a legitimate government agency.
The attackers have threatened to release further information unless Revolut pays a ransom of 10,000 Bitcoin, worth more than $782m at the time of the disclosure.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
