A data breach at City Relay, a London property management company, has exposed sensitive landlord bank details and tenant access codes, prompting renewed calls for stronger cybersecurity practices across the property sector. The incident is a reminder that companies sitting on financial records and physical access information are attractive, and often under-protected, targets for cybercriminals.
What Was Exposed in the City Relay Breach
According to reporting on the incident, the breach at City Relay resulted in the theft of bank account details belonging to landlords, along with access codes used to enter rental properties. This combination of financial data and physical security information makes the breach particularly concerning. Bank details can be used for direct financial fraud, while stolen access codes raise the possibility of unauthorized entry into properties that landlords and tenants assumed were secure. The company is now being urged to review its cybersecurity measures in response.
While the full scope of the breach, including how many landlords or tenants were affected, has not been detailed publicly, the nature of the stolen data alone is enough to warrant serious concern. Financial information and door codes are not the kind of records that should ever end up in the wrong hands, and their exposure highlights a gap between how much sensitive data property managers collect and how well that data is actually protected.
Why Property Management Firms Are Prime Targets for Fraud
Property management companies occupy a unique position in the data ecosystem. They routinely handle bank account numbers for rent collection and landlord payouts, personal identification for tenant screening, and increasingly, digital access credentials for smart locks and building entry systems. That combination of financial and physical security data makes these firms especially valuable to attackers, since a single breach can enable both fraud and unauthorized property access.
Unlike large financial institutions, many property management firms operate with smaller IT budgets and less mature security infrastructure, even though they manage data that is just as sensitive. This mismatch between the value of the data and the resources dedicated to protecting it is a pattern seen across the real estate industry, and the City Relay incident fits squarely within it.
Protecting Financial and Access Data as a Landlord or Tenant
Landlords and tenants who rely on third-party property management services are largely dependent on those companies to safeguard sensitive information. Still, there are steps individuals can take to reduce their own exposure. Landlords should monitor bank accounts closely for unusual activity following any notification of a breach and consider changing account details if a provider confirms financial data was compromised. Tenants who use digital access codes should ask their property manager whether those codes have been reset following the incident, since reused or unchanged codes remain a security risk even after a breach is disclosed.
It is also worth asking any property management company directly how they store and encrypt sensitive data, whether remote access systems are protected with strong authentication, and how quickly they notify customers when something goes wrong. Companies that cannot answer these questions clearly may not be equipped to handle the data they are entrusted with.
The City Relay incident is not the only example of a service provider struggling to communicate clearly after a breach. In a separate case, the London Hydro data breach left customer names, addresses, and account information exposed, with the utility offering limited clarity to affected customers about what happened and what steps were being taken. Comparing how different organizations respond, or fail to respond, to similar incidents can help consumers judge whether a company is taking data protection seriously.
Cybersecurity Steps Property Managers Should Take Now
For property management firms, the City Relay breach should serve as a prompt to reassess how sensitive data is stored and transmitted. Encrypting remote access systems, limiting who within the organization can view or export bank details, and enforcing multi-factor authentication on internal systems are baseline measures that reduce the risk of a similar incident. Regularly auditing third-party vendors and software used to manage tenant and landlord data is equally important, since breaches often originate from overlooked integrations rather than the core platform itself.
Just as importantly, firms need clear incident response plans that prioritize timely, transparent communication with affected customers. The lesson from cases like the London Hydro breach is that vague or delayed disclosures erode trust even further than the breach itself.
What This Means For You
If you rent a property managed by a third-party firm or own property that relies on one, this incident is a useful trigger to ask questions rather than assume your data is safe by default. Property data breach security is not just an IT department's responsibility; it directly affects the financial safety and physical security of everyone whose information passes through these systems.
Actionable Takeaways
- Contact your property manager directly to ask whether your bank details or access codes were part of any breach.
- Change bank account numbers or request new access codes if you have any reason to believe your data was exposed.
- Monitor bank statements regularly for unauthorized transactions in the weeks following a disclosed breach.
- Ask property management firms about their encryption practices and data handling policies before signing new agreements.
The City Relay breach is a clear signal that property data breach security deserves far more attention across the rental industry, and taking these steps now can help limit the damage if your information was among the data exposed.




