TL;DR: City Relay told customers, in a London property data breach, that property access and key-storage information may have been exposed in an intrusion it discovered on September 8. It contacted customers on September 14 and says it has updated the relevant codes so the exposed ones no longer work. If you use lockboxes or door codes, change them.

👉 Run a free digital footprint check on yourself →

According to reporting based on The Register, City Relay first learned of the intrusion on September 8, 2026 and reached out to affected customers on September 14. Its email said that because property access and key-storage information was potentially included, it immediately updated the relevant access and key-storage codes, and that the previously exposed codes can no longer be used.

Why this breach is different

Most breaches expose data that can be misused online. This one touches physical security: a code for a key safe or an entry system connects a digital leak to a real doorstep. Names and addresses linked to access codes are more sensitive than either alone.

What landlords, tenants and guests should do

  1. Confirm with your property manager that your codes were changed, and ask for the new ones only through a channel you trust.
  2. Change any lockbox, smart-lock or door-entry code you set yourself, especially if you reused it elsewhere.
  3. Do not trust a message asking you to confirm your code or address through a link. Breach follow-ups are a common phishing hook, as our data breach notification email guide explains.
  4. If your address and phone number were included, expect callers who know where you live. Read how scammers build a profile of you.

What is still unclear

The reports we reviewed do not give the number of customers affected or confirm which properties were involved. City Relay says its response was precautionary rather than a reaction to confirmed misuse.

Another UK impersonation story from the same week is our TV Licence direct debit email scam warning.

FAQs

What did the City Relay breach expose?

City Relay says property access and key-storage information was potentially included. It has since updated those codes so the exposed ones no longer work.

Do I need to change my own lockbox code?

Yes, if you set it yourself or reused it elsewhere. Changing it is quick and removes any doubt.

How do I know the City Relay email is genuine?

Contact your property manager using contact details you already trust, not the ones in the email, and avoid links that ask you to confirm codes.

A quick self-check shows what strangers can see: use the free digital footprint checker.

Curious what's already out there? Scan My Shadow checks a phone number and email across 1,500+ sources and sends a clear report — no guesswork, just facts. Start your scan.

Sources

Related Reading