SECURITY Signal 52
London property manager City Relay reports breach exposing bank details and lockbox codes
City Relay says intruders accessed its Metabase Cloud instance twice and extracted customer data
The breach has potential implications for the financial security of customers as sensitive data may have been compromised. Property access codes being exposed raises significant security risks for tenants and landlords alike. Customers are urged to take immediate actions to protect their financial information and accounts.
Written by elseif from the cluster below · every claim links back to a sourceThe three things worth knowing
City Relay's Metabase Cloud instance was accessed twice by intruders, compromising customer data.
Exposed data includes bank details, passwords, and property access codes, creating significant security risks.
Customers are advised to monitor bank accounts for suspicious activity and update passwords.
THE READ
What the cluster adds up to.
City Relay experienced a significant data breach where attackers accessed its Metabase Cloud instance, extracting sensitive customer information, including bank details and property access codes. This breach could have serious financial implications for affected customers, as their personal and financial data may be used for fraudulent activities.
The company reported that the attacks were due to a vulnerability in the Metabase platform that they were unaware of. It is essential for companies leveraging third-party cloud services to ensure that sensitive information is properly protected, ideally through encryption or tokenization, to mitigate risks in case of a breach.
City Relay took immediate actions to protect its customers by updating access codes and notifying them of the potential risks associated with the breach. However, the company has not disclosed the exact number of affected customers, leaving a gap in understanding the full impact of the incident.
As a precaution, City Relay has advised customers to monitor their bank accounts for unusual transactions and change passwords. This highlights the ongoing risk of phishing and scams that can arise from such data breaches, emphasizing the need for robust cybersecurity practices among businesses.
The ongoing investigation, alongside cybersecurity specialists, aims to determine the full scope of the attack. This incident serves as a reminder of the importance of securing sensitive data, especially when it is stored in cloud environments that may be vulnerable to exploitation.
Written by elseif from the cluster below · checked for specifics the sources never containedTHE CLUSTER