Subscribe Sign in

United Kingdom

London property manager breach may have reported bank details and lockbox codes

1 min read Rewritten in plain language

Security

Show what we removed Rules applied: A1 C2×2 D2×2 D3×6 D4 E3 F2 all 30 rules
  • City Relay says intruders accessed its Metabase Cloud instance twice and extracted customer data.
  • City Relay said the exposed financial data included bank account numbers, sort codes, IBANs, SWIFT references, and account names and addresses.
  • Dray Agha, senior manager of security operations at Huntress, explained that Metabase connects to customers' databases, so the information reported in an attack depends on the access each customer granted it.
  • One source claimed City Relay learned of the intrusion on September 8 and told affected customers on September 14.

4 sentences from our version of the report, chosen to cover it. Nothing here is written; every line is in the article below. How

Headline check

Headline as published: London property manager breach may have exposed bank details and lockbox codes

The headline claims nothing the report does not, but it puts it more firmly than the report does.

  • The headline states “exposed” outright. In the report the claim is attributed to somebody, or hedged.

Figures, names and quoted words in the headline, looked for in the report itself — not in the summary above. How this is checked

City Relay says intruders accessed its Metabase Cloud instance twice and extracted customer data.

City Relay, marketing itself as "London's most trusted property management company," told landlords via email - seen by The Reg - that attackers accessed the third-party provided cloud twice "as a result of a vulnerability in the platform that we were unaware of."

The potentially compromised data on the platform includes names, email and physical addresses, telephone numbers, financial information, property access details, and account passwords.

City Relay said the exposed financial data included bank account numbers, sort codes, IBANs, SWIFT references, and account names and addresses.

Attackers may also have got data about property amenities and access, including the places of stored keys and codes for lockboxes containing them.

Dray Agha, senior manager of security operations at Huntress, explained that Metabase connects to customers' databases, so the information reported in an attack depends on the access each customer granted it.

Agha said that if the exposed passwords and financial details were stored in readable form, that would point to inadequate data protection practices.

One source claimed City Relay learned of the intrusion on September 8 and told affected customers on September 14.

Metabase disclosed a zero-day SQL injection flaw on August 6, saying attackers compromised fewer than 3 percent of its customers before fixes were automatically deployed, but it has not confirmed that the City Relay incident was part of that campaign.

Shortened to 1 minute of reading, this version reads 5 on the Niral Score.

You are reading our version, not theirs. This is The Register's report shortened to its most important sentences, in plainer words, with verdicts and loaded words taken out. Plain description stays, and so do adjectives that carry a fact, such as "former" or "federal". The reporting, the facts and the quotations are theirs — quotations are never edited — and the indicators beside it measure this version. Hover or tap Adjectives to see every one left in the text.

How this outlet filed it, and how we rewrote it

No other newsroom we read has filed on this event, so there is nothing to compare it with yet.

Outlet Niral ScoreAdjectivesSourcingSentimentHappiness
The Registeras they published this story 8.7 6 79 -0.3 46.8
Mundane Readneutralized from The Register 6.1 5 79 -0.1 46.8

Sign in to react.

Comments

Nothing here yet.

Sign in to comment.

Questions

Readers can ask a question about this story here. Questions and answers are for subscribers. Sign in to read them.

Comments are read before they appear where anything in them needs a person to look. Nothing posted here is ever deleted; a comment taken down keeps its text and the reason, so the decision can be looked at again. How this works