City Relay says intruders accessed its Metabase Cloud instance twice and extracted customer data.
City Relay, marketing itself as "London's most trusted property management company," told landlords via email - seen by The Reg - that attackers accessed the third-party provided cloud twice "as a result of a vulnerability in the platform that we were unaware of."
The potentially compromised data on the platform includes names, email and physical addresses, telephone numbers, financial information, property access details, and account passwords.
City Relay said the exposed financial data included bank account numbers, sort codes, IBANs, SWIFT references, and account names and addresses.
Attackers may also have got data about property amenities and access, including the places of stored keys and codes for lockboxes containing them.
Dray Agha, senior manager of security operations at Huntress, explained that Metabase connects to customers' databases, so the information reported in an attack depends on the access each customer granted it.
Agha said that if the exposed passwords and financial details were stored in readable form, that would point to inadequate data protection practices.
One source claimed City Relay learned of the intrusion on September 8 and told affected customers on September 14.
Metabase disclosed a zero-day SQL injection flaw on August 6, saying attackers compromised fewer than 3 percent of its customers before fixes were automatically deployed, but it has not confirmed that the City Relay incident was part of that campaign.