City Relay Data Breach Exposes Customer Financial and Property Access Information
London-based property management firm City Relay has disclosed a data breach in which attackers accessed its Metabase Cloud instance twice, potentially extracting sensitive customer information. The incident, discovered on September 8, was reported to affected landlords and former users on September 14.
The compromised data includes names, email and physical addresses, phone numbers, financial details (bank account numbers, sort codes, IBANs, SWIFT references), property access codes, and account passwords. Attackers may have also obtained information on key storage locations and lockbox codes, raising concerns about physical security risks.
Dray Agha, Senior Manager of Security Operations at Huntress, noted that the exposure of readable passwords and financial data suggests inadequate encryption practices. He emphasized that sensitive information should be encrypted or tokenized to mitigate risks when third-party tools like Metabase are compromised.
City Relay stated that it has updated all exposed access codes and found no evidence of unauthorized property access or data misuse. However, the company advised customers to monitor bank accounts for fraudulent activity and remain vigilant against phishing attempts.
The breach’s full scope remains under investigation, with cybersecurity specialists and authorities involved. While City Relay manages thousands of properties across London and Paris, it has not disclosed the number of affected customers.
The attack may be linked to a zero-day SQL injection vulnerability in Metabase, disclosed on August 6, which impacted fewer than 3% of its customers before fixes were deployed. Other known victims include Framework and n8n, though Metabase has not confirmed whether the City Relay incident was part of the same campaign.
Metabase TPRM report: https://www.rankiteo.com/company/metabase
Framework TPRM report: https://www.rankiteo.com/company/theframeworks-london
City Relay TPRM report: https://www.rankiteo.com/company/city-relay
"id": "themetcit1789662413",
"linkid": "theframeworks-london, metabase, city-relay",
"type": "Vulnerability",
"date": "9/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'industry': 'Real Estate',
'location': 'London, UK; Paris, France',
'name': 'City Relay',
'size': 'Manages thousands of properties',
'type': 'Property Management Firm'}],
'attack_vector': 'Exploitation of third-party software (Metabase Cloud)',
'customer_advisories': 'Advised to monitor bank accounts for fraudulent '
'activity and remain vigilant against phishing '
'attempts.',
'data_breach': {'data_encryption': 'Inadequate (readable passwords and '
'financial data exposed)',
'data_exfiltration': 'Potential (under investigation)',
'personally_identifiable_information': 'Names, email and '
'physical addresses, '
'phone numbers, '
'account passwords',
'sensitivity_of_data': 'High (financial details, passwords, '
'property access codes)',
'type_of_data_compromised': ['Personal Identifiable '
'Information',
'Financial Data',
'Property Access Information']},
'date_detected': '2023-09-08',
'date_publicly_disclosed': '2023-09-14',
'description': 'London-based property management firm City Relay disclosed a '
'data breach in which attackers accessed its Metabase Cloud '
'instance twice, potentially extracting sensitive customer '
'information. The compromised data includes names, email and '
'physical addresses, phone numbers, financial details, '
'property access codes, and account passwords. The breach may '
'be linked to a zero-day SQL injection vulnerability in '
'Metabase.',
'impact': {'brand_reputation_impact': 'Potential reputational damage due to '
'exposure of sensitive customer data',
'data_compromised': 'Names, email and physical addresses, phone '
'numbers, financial details (bank account '
'numbers, sort codes, IBANs, SWIFT '
'references), property access codes, account '
'passwords, key storage locations, lockbox '
'codes',
'identity_theft_risk': 'High (financial and personal data exposed)',
'payment_information_risk': 'High (bank account numbers, sort '
'codes, IBANs, SWIFT references '
'exposed)',
'systems_affected': 'Metabase Cloud instance'},
'investigation_status': 'Ongoing',
'lessons_learned': 'Sensitive information should be encrypted or tokenized to '
'mitigate risks when third-party tools are compromised.',
'post_incident_analysis': {'corrective_actions': 'Updated all exposed access '
'codes; ongoing '
'investigation with '
'cybersecurity specialists '
'and authorities',
'root_causes': 'Exploitation of zero-day SQL '
'injection vulnerability in '
'Metabase Cloud; inadequate '
'encryption of sensitive data'},
'recommendations': 'Monitor bank accounts for fraudulent activity, remain '
'vigilant against phishing attempts, and ensure proper '
'encryption of sensitive data.',
'references': [{'source': 'Huntress (Dray Agha, Senior Manager of Security '
'Operations)'},
{'date_accessed': '2023-08-06',
'source': 'Metabase vulnerability disclosure'}],
'response': {'communication_strategy': 'Advisories to landlords and former '
'users on September 14',
'containment_measures': 'Updated all exposed access codes',
'law_enforcement_notified': 'Authorities involved',
'third_party_assistance': 'Cybersecurity specialists'},
'stakeholder_advisories': 'Advisories sent to landlords and former users on '
'September 14.',
'title': 'City Relay Data Breach Exposes Customer Financial and Property '
'Access Information',
'type': 'Data Breach',
'vulnerability_exploited': 'Zero-day SQL injection vulnerability'}