Back Theregister London property manager breach may have exposed bank details and lockbox codes
City Relay says intruders accessed its Metabase Cloud instance twice and extracted customer data
Microsoft configuration change leaves SharePoint pages drawing a blank 30 minutes ago
Microsoft configuration change leaves SharePoint pages drawing a blank
Grassroots coalition asks politicians to choose voters over Big AI's $140M machine 1 hour ago
Grassroots coalition asks politicians to choose voters over Big AI's $140M machine
Microsoft patch gives domain-joined Windows PCs trust issues 2 hours ago
Microsoft patch gives domain-joined Windows PCs trust issues
AI model watermarking changes agent behavior 2 hours ago
AI model watermarking changes agent behavior
Cisco drops another exploited zero-day, this time a perfect 10 3 hours ago
Cisco drops another exploited zero-day, this time a perfect 10
London property management biz City Relay has warned customers that intruders may have stolen financial data, passwords, and codes used to access keys after compromising its Metabase Cloud instance.
City Relay, marketing itself as "London's most trusted property management company," told landlords via email - seen by The Reg - that attackers accessed the third-party provided cloud twice "as a result of a vulnerability in the platform that we were unaware of."
The message to customers stated: "Personal data was extracted from the platform."
The potentially compromised data on the platform includes names, email and physical addresses, telephone numbers, financial information, property access details, and account passwords .
City Relay said the exposed financial data included bank account numbers, sort codes, IBANs, SWIFT references, and account names and addresses.
Attackers may also have obtained data property amenities and access, including the locations of stored keys and codes for lockboxes containing them.
Dray Agha, senior manager of security operations at Huntress, explained that Metabase connects to customers' databases, so the information exposed in an attack depends on the access each customer granted it.
"A company linking Metabase to a general analytics database will only expose harmless user metrics," he said. "A company that connects it directly to their core transactional database risks exposing highly sensitive financial records and credentials."
Agha said that if the exposed passwords and financial details were stored in readable form, that would point to inadequate data protection practices.
"Sensitive financial details should also be encrypted or tokenized when held in a database. Keeping this information readable creates a massive risk if a connected reporting tool is ever compromised."
The Register understands that City Relay sent the emails to current landlords and former users of its services. One source claimed City Relay learned of the intrusion on September 8 and notified affected customers on September 14.
"As property access and key-storage information was potentially included, we immediately took precautionary action to update the relevant access and key-storage codes," the emails stated.
"This work has now been completed. The previously exposed codes can no longer be used and we have no evidence of any unauthorised property access arising from the incident."
Beyond the immediate physical security risks, City Relay urged customers to check their bank accounts for suspicious transactions, watch for phishing and other scams, and change any reused passwords on other accounts.
The company told us it had found no evidence that the exposed data had been misused. It is continuing to investigate alongside cybersecurity specialists and "the relevant authorities" to establish the attack's full scope.
City Relay's website says it has hundreds of "partners" – landlords who outsource management of their property portfolios – and that it manages, or has managed, thousands of London properties.
The company has not said how many customers were affected in London or Paris, where it also operates.
The Register asked City Relay for more information.
City Relay did not identify the vulnerability used in the attack. Metabase disclosed a zero-day SQL injection flaw on August 6, saying attackers compromised fewer than 3 percent of its customers before fixes were automatically deployed, but it has not confirmed that the City Relay incident was part of that campaign.
Known victims included laptop maker Framework and workflow automation platform n8n. ®
London property manager breach may have exposed bank details and lockbox codes
City Relay says intruders accessed its Metabase Cloud instance twice and extracted customer data
Microsoft configuration change leaves SharePoint pages drawing a blank
Validation? Apparently that comes after deployment
HPE makes its “unified storage” claim real as B10000 R6 hits GA
PARTNER CONTENT: Pairs block and adjacent file workloads with independent scaling of performance and capacity
Grassroots coalition asks politicians to choose voters over Big AI's $140M machine
QuitGPT-led pledge targets Leading the Future's push for lighter regulation ahead of the midterms
Open weights are not open source: Why AI's favorite label is under dispute
Downloading a model is increasingly easy. Understanding how it was made, or changing a system at its root, is another matter
AI model watermarking changes agent behavior
Lasso Security sees differences in tool handling and model refusals
SAAS Salesforce staggers back to feet after global outage
Salesforce staggers back to feet after global outage
databases Oracle celebrates banner quarter with another round of layoffs
Oracle celebrates banner quarter with another round of layoffs
CYBER-CRIME Ukrainian lawyer's second career as a Conti coder earns him 4 years behind bars
Ukrainian lawyer's second career as a Conti coder earns him 4 years behind bars
virtualization VMware defends ending downloads of SDK that helps VM backups – or migrations to rivals
VMware defends ending downloads of SDK that helps VM backups – or migrations to rivals
cyber-crime Revolut falls for fake government requests, hands over customer data
Revolut falls for fake government requests, hands over customer data
SOFTWARE German optics giant ditches greenfield SAP migration
German optics giant ditches greenfield SAP migration
ai and ml AI model watermarking changes agent behavior Lasso Security sees differences in tool handling and model refusals
AI model watermarking changes agent behavior
Lasso Security sees differences in tool handling and model refusals
SYSTEMS Nvidia goes green to keep grid capacity from zapping its revenues GPUzilla woos neoclouds into another walled garden, promising smarter, more efficient, and profitable bit barns
Nvidia goes green to keep grid capacity from zapping its revenues
GPUzilla woos neoclouds into another walled garden, promising smarter, more efficient, and profitable bit barns
cyber-crime Spain gets its first taste of AI-aided cyber attack Data protection chiefs call for 'immediate review' of data protection models
Spain gets its first taste of AI-aided cyber attack
Data protection chiefs call for 'immediate review' of data protection models
SYSTEMS AI networking startups race to replace Nvidia's NVLink Intel spin-off Cornelis and newcomer Delos Data pitch open alternatives for scaling AI beyond the rack
AI networking startups race to replace Nvidia's NVLink
Intel spin-off Cornelis and newcomer Delos Data pitch open alternatives for scaling AI beyond the rack
AI AND ML Anthropic and OpenAI look to Uncle Sam to make them too big to fail American model devs are trying to convince Washington to cement their dominance
Anthropic and OpenAI look to Uncle Sam to make them too big to fail
American model devs are trying to convince Washington to cement their dominance
Security Russians are posing as Signal support to launch phishing attacks PLUS: US takes down Iranian propaganda sites; Marketing company asks 'Why Do We Have Your Information?' And more!
Russians are posing as Signal support to launch phishing attacks
PLUS: US takes down Iranian propaganda sites; Marketing company asks 'Why Do We Have Your Information?' And more!
Security Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attack PLUS: China upgrades smartphone surveillance tools; Ring eases anti-snooping stance; and more
Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attack
PLUS: China upgrades smartphone surveillance tools; Ring eases anti-snooping stance; and more
Black Hat and DEF CON DEF CON Franklin project enlists hackers to harden critical infrastructure Voting village reports have been so successful, says Jeff Moss, that the whole of DEF CON will now be included
Black Hat and DEF CON
DEF CON Franklin project enlists hackers to harden critical infrastructure
Voting village reports have been so successful, says Jeff Moss, that the whole of DEF CON will now be included
Security EQT buys majority in Swiss cybersecurity biz Acronis Went at equivalent of $3.5B+ valuation for entire firm, though portion sold not specified
EQT buys majority in Swiss cybersecurity biz Acronis
Went at equivalent of $3.5B+ valuation for entire firm, though portion sold not specified
Malware Month Ten years since the first corp ransomware, Mikko Hyppönen sees no end in sight On the plus side, infosec's a good bet for a long, stable career
Ten years since the first corp ransomware, Mikko Hyppönen sees no end in sight
On the plus side, infosec's a good bet for a long, stable career
Shopify extends lifeline to Tailwind as vibe coding erodes web dev platform's bottom line Acquisition gives open source CSS framework 'a stable long-term '
Shopify extends lifeline to Tailwind as vibe coding erodes web dev platform's bottom line
Acquisition gives open source CSS framework 'a stable long-term '
Switzerland tests a FOSS escape route from Microsoft 365 Swiss Army sticks a knife in American cloud apps with its own FOSS push
Switzerland tests a FOSS escape route from Microsoft 365
Swiss Army sticks a knife in American cloud apps with its own FOSS push
Feel peak Windows was 7? You might like Kumander Linux Debian and Xfce – solid, sensible choices – with a pretty skin
Feel peak Windows was 7? You might like Kumander Linux
Debian and Xfce – solid, sensible choices – with a pretty skin
Canonical shuttering some of its legacy chat channels The Ubuntu Pastebin went in June, IRC gets demoted
Canonical shuttering some of its legacy chat channels
The Ubuntu Pastebin went in June, IRC gets demoted
Audacity audio-editing app no longer looks like it's from the early 2000s The FOSS tool for audio editing has a fresh coat of paint, and new features to boot
Audacity audio-editing app no longer looks like it's from the early 2000s
The FOSS tool for audio editing has a fresh coat of paint, and new features to boot
Haiku OS rises / Beta 6 sails open web / Virtual winds fly fast A real alternative to running some kind of FOSS Unix clone
Haiku OS rises / Beta 6 sails open web / Virtual winds fly fast
A real alternative to running some kind of FOSS Unix clone
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
