About

The consultancy born at the intersection of behavioral economics and human experience.

NOW HIRING

Join a team reshaping how the world experiences brands.

View open roles →

COMPANY

GROW WITH US

CONNECT

Services

Comprehensive CX and management consulting for enterprise brands.

ALL SERVICES

Explore the full range of CX & management consulting services.

Browse all services →

CORE

SPECIALIST

Solutions

Structured solutions that turn CX ambition into measurable outcomes.

ALL SOLUTIONS

Explore every CX solution we offer.

Browse solutions →

STRATEGY & GOVERNANCE

DESIGN & DELIVERY

CULTURE & EXPERIENCE

Industries

A decade of CX transformation across the region's defining sectors.

ALL INDUSTRIES

See how we work across every sector.

Browse industries →

BUILT ENVIRONMENT

FINANCE & TECH

PEOPLE & MOBILITY

Products

Proprietary tools, platforms, and AI that power CX transformation.

ALL PRODUCTS

Explore the full Renascence product ecosystem.

Browse products →

AI & TECHNOLOGY

LEARNING & GAMES

PLATFORMS & TOOLS

AI PRODUCTS

Opinion

Insights, research, and conversations at the frontier of CX.

ReadExperience JournalArticles & research on CX, behavior, and transformation.Watch & listenExperience LoomOur video podcast on CX & behavior.CuratedCX NewsIndustry news that matters in CX, minus the noise.

Latest articles

Latest episodes

Latest news

Hub

Free tools, templates, and resources to advance your CX practice.

NEW · MANIFESTO

Burn the Deck. Ten Virtues. Zero Excuses. — read our manifesto for the brave consultant.

Start reading →

AI TOOLS

FREE TOOLS

LEARNING

CULTURE

Banking · 18 September 2026

City Relay breach exposes bank details, lockbox codes

London property manager City Relay disclosed two unauthorised intrusions into its Metabase Cloud analytics tool, exposing customer bank details and lockbox access codes.

Newsdesk
Curated briefing · 2 min read

What happened

City Relay, a London-based property management firm, has disclosed that intruders gained unauthorised access to its Metabase Cloud instance on two separate occasions and extracted customer data. According to reporting by The Register, the exposed information is understood to include sensitive details such as bank information and lockbox access codes used to manage entry to rental properties.

Metabase Cloud is a hosted business-intelligence and analytics tool that companies typically use to query and visualise operational data, meaning the breach points to gaps in how access to backend reporting systems was secured and monitored. The fact that attackers were able to return for a second intrusion suggests the initial compromise was not fully remediated after it was first detected.

Why it matters

For a property manager, the data at stake is unusually sensitive: bank details enable financial fraud, while lockbox codes control physical access to homes. A breach touching both categories moves beyond a typical data-privacy incident into questions of tenant and landlord safety, making this a service-design and trust failure as much as a technology one.

The incident is a reminder that customer trust in property, hospitality and any business handling physical access credentials rests on the assumption that back-office analytics tools — often treated as internal, low-risk systems — are held to the same security standard as customer-facing platforms. When a reporting dashboard becomes the weak link, the operational and reputational consequences land squarely on customer experience and duty of care.

The Renascence take

Breaches involving physical-access credentials sit at the intersection of security and service design, and they expose a blind spot many organisations share: the systems people worry least about are often the ones holding the most consequential data.

Most leaders treat business-intelligence tools as internal furniture — useful for dashboards, invisible to risk registers. This case is a sharp reminder that any system aggregating customer data, however "back office" it seems, is a frontline trust asset and needs frontline-grade controls, monitoring and incident response. The fact that access reportedly recurred after an initial breach is the real service-design failure: detection without containment simply invites a second visit. Operators handling physical-access data — lockbox codes, entry credentials, keys — should treat that information with the same segregation and monitoring rigor as payment data, because the harm from a leak is not abstract; it is a stranger with the code to someone's front door.

Sources

This briefing was written by our Newsdesk, synthesising reporting from the outlets below. Follow the links for the original coverage.

FAQ

Questions we get on this topic

City Relay, a London-based property management firm, disclosed that intruders accessed its Metabase Cloud instance and extracted customer data.

According to reporting by The Register, the exposed data is understood to include sensitive bank information and lockbox access codes used to enter rental properties.

Intruders gained unauthorised access on two separate occasions, suggesting the initial compromise was not fully contained after it was first detected.

Because it combines financial data with physical-access credentials, the breach raises both fraud risk and tenant/landlord safety concerns, going beyond a typical privacy incident.

Stay ahead of CX

Get the signal, not the noise.

The stories shaping customer experience — plus the Journal and Experience Loom — in your inbox.