Computing London Property Manager Breach Exposes Sensitive Customer Data
Article Content
- •City Relay's Metabase Cloud instance was breached, exposing sensitive customer data.
- •The breach may have compromised financial information, including bank account details.
- •City Relay notified customers six days after discovering the intrusion.
City Relay, a London property management company, reported a breach of its Metabase Cloud instance, where attackers accessed sensitive customer data twice due to an unknown vulnerability. The compromised data includes personal information such as names, email addresses, and financial details like bank account numbers and access codes for properties. City Relay became aware of the intrusion on September 8 and notified affected customers on September 14, advising them to monitor their accounts for unusual activity. The breach raises concerns about the physical security of the properties managed by City Relay, as access codes and key storage information may have been exposed. The company has not disclosed the number of affected customers or how attackers exploited the system. Security experts emphasize that the impact of such a breach depends on the data linked to the Metabase platform. City Relay has taken precautionary measures to secure access and key storage codes.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Conti and City Relay in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Iranian State Actors Deploy CHOSEN BRICK Spyware Against Dissidents On September 15, 2026, the UK, US, and Netherlands issued a joint advisory regarding a spyware campaign attributed to Iranian state actors targeting dissidents, activists, and journalists. The malware, known as CHOSEN BRICK, is delivered through spear-phishing attacks on messaging platforms like WhatsApp and Telegram.…