You might wonder why a cyber and data security company is weighing in on a football story about finance, success and alleged cheating. Stay with me — because at the very start of it all was a hacker, and a single phishing email.

Last week an independent commission found Manchester City guilty of 114 of the 115 charges the Premier League brought against them — serious breaches of its financial rules across nine seasons. City strongly deny any wrongdoing, say the decision contains material errors, and are appealing; any sanctions will be decided separately. However it ends, it is already one of the biggest scandals in English football history.

But here’s the part that stops me, as someone who works in cyber security every day: none of it would be public without a phishing email.

It began with one click

Back in 2017, the Portuguese hacker Rui Pinto — the man behind “Football Leaks” — reportedly sent phishing messages to individuals and organisations across football. One, it is widely reported, was dressed up as a financial report from UEFA. A senior figure at Manchester City opened the malicious link — and with that single click, Pinto gained access to the club’s servers, emails and documents.

He then searched, found and downloaded a huge volume of internal emails and files. That material later fed the Der Spiegel revelations, triggered investigations by UEFA and the Premier League, and ultimately led to the 115 charges. Pinto has since been convicted of hacking offences in Portugal, while casting himself as a whistleblower exposing football’s hidden side.

A near-billion-pound storm from a spam email

Think about the scale of what grew from that one click. A case the Premier League has called the most significant in its history. Allegations centred on roughly £900 million. Some of the biggest clubs and players on the planet, in one of the best leagues in the world, and millions of fans around the world affected — all of it traceable back to a phishing email that someone, somewhere, clicked.

I’m a huge football fan — I’ve loved the game since I could kick a ball — so I’ll be following every twist of this closely. But I can’t ignore the sobering truth underneath it: this entire saga exists because of email, data, and a lapse in cyber security.

The lesson for every business

If a phishing email can breach one of the richest, most sophisticated football clubs on earth, it can breach your business too. The organisations that stay safe aren’t the ones that think they’re too small, or too careful, to be caught — they’re the ones that assume the click will happen and build their defences around it.

That means the basics, done properly: Cyber Essentials certification, multi-factor authentication and hardened Microsoft 365, ongoing phishing-awareness training for your team through our cyber security service, and tested backups for when something does slip through. One click should never be able to hand over everything.

Football’s biggest financial story of the decade started with a spam email. It’s a remarkable reminder that, whoever you are, your security is only ever as strong as the last link someone clicks.

Sources: Premier League statement and reporting by Reuters, The Athletic, Al Jazeera and NBC News on the 28–29 September 2026 verdict; and reporting by Der Spiegel, Wikipedia and others on how the Football Leaks data was obtained. Manchester City deny wrongdoing and are appealing. This article is the author’s personal opinion and general cyber-security guidance.