What can the Man City hack teach us about phishing?
4 min read.
On 25th September, an independent Premier League commission found Manchester City guilty of 114 of 115 financial charges. City denies wrongdoing and is appealing.
The case can be traced back to a single email. In January 2017, a senior official at Manchester City received an email that appeared to come from someone at UEFA, European football's governing body. It contained a link to what looked like a financial compliance report and the official clicked it.
The email was fake. It was sent by Portuguese hacker Rui Pinto and that click gave him access to the club's servers and thousands of internal emails and documents.
Those files were published by Der Spiegel in 2018 and became the starting point for UEFA's investigation and, later, 115 Premier League charges. Last month an independent commission found City guilty of 114 of them. The club has subsequently denied wrongdoing and is appealing.
Why it worked
Firstly, the attacker didn't break in, he was let in. These three things made the email convincing:
It used a trusted name. UEFA policed City's finances, so an email from UEFA about finances looked routine, not suspicious.
It matched the job. A compliance report is exactly what a senior official expects to receive and act on.
It was aimed at one person. This was spear phishing: a single, researched email sent to someone whose access was worth having.
For most UK businesses, the equivalent is an email that looks like it came from HMRC, your regulation body, your bank or a major client. And because an attacker using real login details looks like a real user, a breach like this can go unnoticed for a long time.
The damage has outlived the breach
The click happened in 2017 but the verdict came in September 2026, almost ten years later. Most businesses think of a cyber attack as a bad day or week but this one is still making headlines a decade on.
The reason is simple: email is a permanent record. Everything sitting in a mailbox, every old thread, attachment and shared folder, is what an attacker walks away with. Once it's out, you no longer decide how it's used or who reads it.
Whatever you think of the outcome for Manchester City, the lesson for every other organisation is the same. The question isn't just "could we be phished?" it is also "what would someone find if we were?"
What to do about it
These are the steps we'd prioritise for any business:
Treat authority as a warning sign. If a regulator, governing body or senior figure sends something unexpected, check it through a contact you already have, not through the email itself.
Stop phishing before it reaches people. An email security platform such as Proofpoint, checks links when they're clicked and flags emails impersonating trusted senders. It catches what a busy person might not.
Use multi-factor authentication everywhere. Use phishing-resistant options such as number matching or passkeys, so a stolen password isn't enough on its own.
Tighten Microsoft 365. Block legacy sign-ins, use conditional access and set alerts for unusual logins and new mailbox forwarding rules.
Protect your own domain. SPF, DKIM and DMARC stop attackers sending email that looks like it came from you.
Train with realistic tests. Run phishing simulations and give senior staff extra attention as they're the most valuable targets.
Keep less. Set retention policies so a compromised mailbox holds months of data, not a decade.
Make reporting easy. A one-click report button and a no-blame culture mean IT hears about a bad click in minutes, not months.
How would your business fare?
The email they received didn't have to be particularly sophisticated because it was believable. That's what makes phishing so effective and why the best defence is a mix of the right settings and people who know what to look for.
If you'd like to know how your business would hold up against an email like this one, get in touch to have a chat with one of our technical team.