Skip to content
London property manager breach may have exposed bank details and lockbox codes

London property manager breach may have exposed bank details and lockbox codes

Theregister September 17, 2026

City Relay says intruders accessed its Metabase Cloud instance twice and extracted customer data

Microsoft configuration change leaves SharePoint pages drawing a blank 30 minutes ago

Microsoft configuration change leaves SharePoint pages drawing a blank

Grassroots coalition asks politicians to choose voters over Big AI's $140M machine 1 hour ago

Grassroots coalition asks politicians to choose voters over Big AI's $140M machine

Microsoft patch gives domain-joined Windows PCs trust issues 2 hours ago

Microsoft patch gives domain-joined Windows PCs trust issues

AI model watermarking changes agent behavior 2 hours ago

AI model watermarking changes agent behavior

Cisco drops another exploited zero-day, this time a perfect 10 3 hours ago

Cisco drops another exploited zero-day, this time a perfect 10

London property management biz City Relay has warned customers that intruders may have stolen financial data, passwords, and codes used to access keys after compromising its Metabase Cloud instance.

City Relay, marketing itself as "London's most trusted property management company," told landlords via email - seen by The Reg - that attackers accessed the third-party provided cloud twice "as a result of a vulnerability in the platform that we were unaware of."

The message to customers stated: "Personal data was extracted from the platform."

The potentially compromised data on the platform includes names, email and physical addresses, telephone numbers, financial information, property access details, and account passwords .

City Relay said the exposed financial data included bank account numbers, sort codes, IBANs, SWIFT references, and account names and addresses.

Attackers may also have obtained data property amenities and access, including the locations of stored keys and codes for lockboxes containing them.

Dray Agha, senior manager of security operations at Huntress, explained that Metabase connects to customers' databases, so the information exposed in an attack depends on the access each customer granted it.

"A company linking Metabase to a general analytics database will only expose harmless user metrics," he said. "A company that connects it directly to their core transactional database risks exposing highly sensitive financial records and credentials."

Agha said that if the exposed passwords and financial details were stored in readable form, that would point to inadequate data protection practices.

"Sensitive financial details should also be encrypted or tokenized when held in a database. Keeping this information readable creates a massive risk if a connected reporting tool is ever compromised."

The Register understands that City Relay sent the emails to current landlords and former users of its services. One source claimed City Relay learned of the intrusion on September 8 and notified affected customers on September 14.

"As property access and key-storage information was potentially included, we immediately took precautionary action to update the relevant access and key-storage codes," the emails stated.

"This work has now been completed. The previously exposed codes can no longer be used and we have no evidence of any unauthorised property access arising from the incident."

Beyond the immediate physical security risks, City Relay urged customers to check their bank accounts for suspicious transactions, watch for phishing and other scams, and change any reused passwords on other accounts.

The company told us it had found no evidence that the exposed data had been misused. It is continuing to investigate alongside cybersecurity specialists and "the relevant authorities" to establish the attack's full scope.

City Relay's website says it has hundreds of "partners" – landlords who outsource management of their property portfolios – and that it manages, or has managed, thousands of London properties.

The company has not said how many customers were affected in London or Paris, where it also operates.

The Register asked City Relay for more information.

City Relay did not identify the vulnerability used in the attack. Metabase disclosed a zero-day SQL injection flaw on August 6, saying attackers compromised fewer than 3 percent of its customers before fixes were automatically deployed, but it has not confirmed that the City Relay incident was part of that campaign.

Known victims included laptop maker Framework and workflow automation platform n8n. ®

London property manager breach may have exposed bank details and lockbox codes

City Relay says intruders accessed its Metabase Cloud instance twice and extracted customer data

Microsoft configuration change leaves SharePoint pages drawing a blank

Validation? Apparently that comes after deployment

HPE makes its “unified storage” claim real as B10000 R6 hits GA

PARTNER CONTENT: Pairs block and adjacent file workloads with independent scaling of performance and capacity

Grassroots coalition asks politicians to choose voters over Big AI's $140M machine

QuitGPT-led pledge targets Leading the Future's push for lighter regulation ahead of the midterms

Open weights are not open source: Why AI's favorite label is under dispute

Downloading a model is increasingly easy. Understanding how it was made, or changing a system at its root, is another matter

AI model watermarking changes agent behavior

Lasso Security sees differences in tool handling and model refusals

SAAS Salesforce staggers back to feet after global outage

Salesforce staggers back to feet after global outage

databases Oracle celebrates banner quarter with another round of layoffs

Oracle celebrates banner quarter with another round of layoffs

CYBER-CRIME Ukrainian lawyer's second career as a Conti coder earns him 4 years behind bars

Ukrainian lawyer's second career as a Conti coder earns him 4 years behind bars

virtualization VMware defends ending downloads of SDK that helps VM backups – or migrations to rivals

VMware defends ending downloads of SDK that helps VM backups – or migrations to rivals

cyber-crime Revolut falls for fake government requests, hands over customer data

Revolut falls for fake government requests, hands over customer data

SOFTWARE German optics giant ditches greenfield SAP migration

German optics giant ditches greenfield SAP migration

ai and ml AI model watermarking changes agent behavior Lasso Security sees differences in tool handling and model refusals

AI model watermarking changes agent behavior

Lasso Security sees differences in tool handling and model refusals

SYSTEMS Nvidia goes green to keep grid capacity from zapping its revenues GPUzilla woos neoclouds into another walled garden, promising smarter, more efficient, and profitable bit barns

Nvidia goes green to keep grid capacity from zapping its revenues

GPUzilla woos neoclouds into another walled garden, promising smarter, more efficient, and profitable bit barns

cyber-crime Spain gets its first taste of AI-aided cyber attack Data protection chiefs call for 'immediate review' of data protection models

Spain gets its first taste of AI-aided cyber attack

Data protection chiefs call for 'immediate review' of data protection models

SYSTEMS AI networking startups race to replace Nvidia's NVLink Intel spin-off Cornelis and newcomer Delos Data pitch open alternatives for scaling AI beyond the rack

AI networking startups race to replace Nvidia's NVLink

Intel spin-off Cornelis and newcomer Delos Data pitch open alternatives for scaling AI beyond the rack

AI AND ML Anthropic and OpenAI look to Uncle Sam to make them too big to fail American model devs are trying to convince Washington to cement their dominance

Anthropic and OpenAI look to Uncle Sam to make them too big to fail

American model devs are trying to convince Washington to cement their dominance

Security Russians are posing as Signal support to launch phishing attacks PLUS: US takes down Iranian propaganda sites; Marketing company asks 'Why Do We Have Your Information?' And more!

Russians are posing as Signal support to launch phishing attacks

PLUS: US takes down Iranian propaganda sites; Marketing company asks 'Why Do We Have Your Information?' And more!

Security Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attack PLUS: China upgrades smartphone surveillance tools; Ring eases anti-snooping stance; and more

Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attack

PLUS: China upgrades smartphone surveillance tools; Ring eases anti-snooping stance; and more

Black Hat and DEF CON DEF CON Franklin project enlists hackers to harden critical infrastructure Voting village reports have been so successful, says Jeff Moss, that the whole of DEF CON will now be included

Black Hat and DEF CON

DEF CON Franklin project enlists hackers to harden critical infrastructure

Voting village reports have been so successful, says Jeff Moss, that the whole of DEF CON will now be included

Security EQT buys majority in Swiss cybersecurity biz Acronis Went at equivalent of $3.5B+ valuation for entire firm, though portion sold not specified

EQT buys majority in Swiss cybersecurity biz Acronis

Went at equivalent of $3.5B+ valuation for entire firm, though portion sold not specified

Malware Month Ten years since the first corp ransomware, Mikko Hyppönen sees no end in sight On the plus side, infosec's a good bet for a long, stable career

Ten years since the first corp ransomware, Mikko Hyppönen sees no end in sight

On the plus side, infosec's a good bet for a long, stable career

Shopify extends lifeline to Tailwind as vibe coding erodes web dev platform's bottom line Acquisition gives open source CSS framework 'a stable long-term '

Shopify extends lifeline to Tailwind as vibe coding erodes web dev platform's bottom line

Acquisition gives open source CSS framework 'a stable long-term '

Switzerland tests a FOSS escape route from Microsoft 365 Swiss Army sticks a knife in American cloud apps with its own FOSS push

Switzerland tests a FOSS escape route from Microsoft 365

Swiss Army sticks a knife in American cloud apps with its own FOSS push

Feel peak Windows was 7? You might like Kumander Linux Debian and Xfce – solid, sensible choices – with a pretty skin

Feel peak Windows was 7? You might like Kumander Linux

Debian and Xfce – solid, sensible choices – with a pretty skin

Canonical shuttering some of its legacy chat channels The Ubuntu Pastebin went in June, IRC gets demoted

Canonical shuttering some of its legacy chat channels

The Ubuntu Pastebin went in June, IRC gets demoted

Audacity audio-editing app no longer looks like it's from the early 2000s The FOSS tool for audio editing has a fresh coat of paint, and new features to boot

Audacity audio-editing app no longer looks like it's from the early 2000s

The FOSS tool for audio editing has a fresh coat of paint, and new features to boot

Haiku OS rises / Beta 6 sails open web / Virtual winds fly fast A real alternative to running some kind of FOSS Unix clone

Haiku OS rises / Beta 6 sails open web / Virtual winds fly fast

A real alternative to running some kind of FOSS Unix clone