London property manager breach may have exposed bank details and lockbox codes
City Relay says intruders accessed its Metabase Cloud instance twice and extracted customer data
security
London property manager breach may have exposed bank details and lockbox codes
EXCLUSIVE
City Relay says intruders accessed its Metabase Cloud instance twice and extracted customer data
London property management biz City Relay has warned customers that intruders may have stolen financial data, passwords, and codes used to access keys after compromising its Metabase Cloud instance.
City Relay, marketing itself as "London's most trusted property management company," told landlords via email - seen by The Reg - that attackers accessed the third-party provided cloud twice "as a result of a vulnerability in the platform that we were unaware of."
The message to customers stated: "Personal data was extracted from the platform."
The potentially compromised data on the platform includes names, email and physical addresses, telephone numbers, financial information, property access details, and account passwords.
City Relay said the exposed financial data included bank account numbers, sort codes, IBANs, SWIFT references, and account names and addresses.
Attackers may also have obtained data about property amenities and access, including the locations of stored keys and codes for lockboxes containing them.
Dray Agha, senior manager of security operations at Huntress, explained that Metabase connects to customers' databases, so the information exposed in an attack depends on the access each customer granted it.
"A company linking Metabase to a general analytics database will only expose harmless user metrics," he said. "A company that connects it directly to their core transactional database risks exposing highly sensitive financial records and credentials."
Agha said that if the exposed passwords and financial details were stored in readable form, that would point to inadequate data protection practices.
"Sensitive financial details should also be encrypted or tokenized when held in a database. Keeping this information readable creates a massive risk if a connected reporting tool is ever compromised."
The Register understands that City Relay sent the emails to current landlords and former users of its services. One source claimed City Relay learned of the intrusion on September 8 and notified affected customers on September 14.
"As property access and key-storage information was potentially included, we immediately took precautionary action to update the relevant access and key-storage codes," the emails stated.
"This work has now been completed. The previously exposed codes can no longer be used and we have no evidence of any unauthorised property access arising from the incident."
Beyond the immediate physical security risks, City Relay urged customers to check their bank accounts for suspicious transactions, watch for phishing and other scams, and change any reused passwords on other accounts.
The company told us it had found no evidence that the exposed data had been misused. It is continuing to investigate alongside cybersecurity specialists and "the relevant authorities" to establish the attack's full scope.
City Relay's website says it has hundreds of "partners" – landlords who outsource management of their property portfolios – and that it manages, or has managed, thousands of London properties.
The company has not said how many customers were affected in London or Paris, where it also operates.
The Register asked City Relay for more information.
City Relay did not identify the vulnerability used in the attack. Metabase disclosed a zero-day SQL injection flaw on August 6, saying attackers compromised fewer than 3 percent of its customers before fixes were automatically deployed, but it has not confirmed that the City Relay incident was part of that campaign.
Known victims included laptop maker Framework and workflow automation platform n8n. ®
Originally published on The Register