One phishing email and almost ten years of fallout: What the Manchester City story teaches every business about cyber risk
One phishing email and almost ten years of fallout
What the Manchester City story teaches every business about phishing, identity security and the long afterlife of a cyber incident.
The Manchester City story is a reminder that the impact of phishing can last far beyond the initial compromise. Once sensitive information leaves your control, the legal, commercial and reputational consequences can continue for years, which is why email security, identity controls, limited permissions, monitoring and rapid reporting all matter.
Every so often, a story comes along that sort of… transcends its space, if you know what I mean? The sort of thing that gets everyone and their dog talking about it, like orbiting the moon earlier this year, a royal wedding, or, in the most recent case, an all-time sports scandal.
Unless you’ve been under a rock for the last week or so, you’ll know by now that an independent Prmier League Commission found Manchester City guilty of all charges relateed to serious breaches of the league’s financial rules over nine seasons, as well as the majority of charges concerning its failure to co-operate with the investigation. For what it’s worth, at the time of writing, the club has lodged an appeal on the 1st of October, while maintaining innocence and says the decision contains material errors, with any potential sanctions still to be decided.
You may now ask yourself, ‘Well, why are Fifosys talking about it?’, and that’s down to what set it all off.
From our understanding, what looked like a routine email from UEFA about a financial compliance report landed in someone’s inbox - which is the sort of message a senior football executive might reasonably expect to receive, read and move on from.
This very email, we’re led to believe, reached a Manchester City official in January 2017, but wasn’t from UEFA at all - it was a phishing message linked to Rui Pinto, a Portuguese hacker behind Football Leaks. The recipient clicked the download link, Pinto gained access to the club’s systems, and thousands of internal emails and documents were reportedly taken, and, well… you know the rest from there.
But there wasn’t any form of dramatic outage, flashing ransom note, or even immediate indication that one ordinary-looking email would still be producing consequences almost a decade later. And that’s what we’re here to dive into.
This isn’t a blog to stick the boot into City (however much I’d personally like to, in part thanks to some horrible - and now meaningless - memories associated with them over the years), but it’s a great opportunity to explore the extraordinary afterlife of a cyber incident.
A phishing email can become a ten-year business problem
Most businesses think about phishing in the immediate tense. Will somebody send money to the wrong account? Will an inbox be hijacked? Will systems go offline?
Those are real risks associated with the attack vector, and you can Google a whole host of examples to back up any of those points. But the thing with this Manchester City story is how it shows another side of cyber security: a breach can uncover information, decisions and internal conversations that continue to matter long after the technical access has been closed.
The initial incident and the later findings aren’t even the same thing. A cyber attack doesn’t create whatever is already in the files it exposes, and neither does unlawful access make every interpretation of stolen material automatically correct. In this case, despite 114 guilty counts, Manchester City has consistently challenged the conclusions drawn and is now appealing the Commission’s decision.
The business lesson to take away from this, really, is a simpler one than unpicking the back-and-forth that’s raged on for years - and very well looks set to continue. Once sensitive information leaves your control, you may lose control of the timetable, too. Journalists, regulators, customers, litigants and competitors can all examine it years later, even if it was illegally obtained.
The technical clean-up might take days, but the commercial, legal and reputational consequences can take much longer.
Was Manchester City hacked through a phishing email
According to recent reporting, yes. A phishing email reportedly impersonated a UEFA contact and presented a link as a financial compliance report. When a Manchester City official clicked it, Pinto gained access to the club’s systems and obtained internal material.
The attack didn’t need to loudly announce itself as dangerous or hold systems to ransom. It borrowed the identity and context of an organisation that the recipient already knew. The trusted name was part of the payload.
Why this matters to an SME
It admittedly is tempting to file this under ‘problems for billion-pound-potentially-state-owned football clubs’. The scale may be near impossible to replicate for almost any other business, but the route in was a very familiar one.
UK SMEs and mid-market organisations live in the same world of supplier emails coming in and out of inboxes, shared documents, cloud accounts and requests that arrive with just enough urgency to discourage a second look. A fake message from your accountant, insurer, bank, technology provider or largest customer can be every bit as plausible as a fake UEFA report. In fact, it’s no less relatable if your spoofed sender isn’t the organisation that runs the Champions League.
Smaller organisations can also have a surprisingly larger blast radius. One Microsoft 365 identity, for example, may include email, Teams, SharePoint, customer files, and password reset messages, while a senior account may contain years of commercially sensitive conversations. The size of the company isn’t the point. The access attached to the account is.
Five practical lessons for business leaders
Trust is what makes phishing work
Attackers imitate people and organisations the recipient expects to hear from, then give them a believable reason to click, sign in or approve something.
Protect the identity, not just the inbox
Use MFA, passkeys, conditional access and sensible password-reset controls so a stolen password doesn’t automatically become wider access.
Limit what one compromised account can reach
Apply least privilege, review access regularly and separate everyday identities from administrative accounts.
Detection changes the size of the incident
Monitor unusual sign-ins, forwarding rules, downloads, privilege changes and access from unfamiliar devices or locations.
The first report shouldn’t be a confession
Give staff a visible, low-friction reporting route so suspicious clicks are raised quickly rather than hidden through fear of blame.
1) Trust is what makes phishing work
These days, phishing attempts look less and less obvious, which is a worry. Instead, it tends to look timely and familiar. Slightly boring, even. Attackers tend to imitate people and organisations the recipient expects to hear from, then give them a believable reason to click, sign in or approve something.
Email filtering, link scanning and domain protections such as SPF, DKIM and DMARC can remove a great deal of malicious traffic, sure, but they cannot make judgment disappear. Staff still need simple ways to verify unusual requests through a separate channel, especially where money, credentials or sensitive documents are involved (You can read the NCSC's phishing guidance for more, and we wrote a blog on Phishing, too).
2) Protect the identity, not just the inbox
Email is pretty much the front door to the rest of just about any business these days, save for some very unique examples. Multi-factor authentication, passkeys, conditional access and sensible controls around password resets make a stolen password less useful. Privileged and senior accounts deserve particular attention because their authority and access make them more likely to be in attackers' crosshairs.
Don’t be under any illusions that MFA is a force field that ensures 100% safety, by the way. Attackers can still use consent phishing, session theft and convincing prompts to circumvent it, although it does remain one of the most valuable layers within a broader email and identity security approach.
3) Limit what one compromised account can reach
The impact of a breach is shaped by one thing: permissions. If every user can see every folder, and old accounts retain access indefinitely, one compromised identity can become an organisation-wide event… Or cause havoc a decade later.
Apply least privilege, review access regularly and separate everyday accounts from administrative ones. Make sure you pay particular attention to shared mailboxes, finance systems, board papers, contracts and document repositories. If you’re in doubt, remember that access should follow the role, not the employee’s seniority or length of service.
4) Detection changes the size of the incident
Prevention gets the headlines, but monitoring determines how long an attacker can operate. Useful alerts might include unusual sign-ins, new forwarding rules, unexpected downloads, privilege changes and access from unfamiliar devices or locations.
Logs need to exist, be protected, and be retained long enough to answer basic questions such as: what happened, which accounts were involved, what was accessed, and whether the attacker returned.
5) The first report shouldn’t be a confession
You can invest in the most state-of-the-art defences, but at the end of the day, there’s still a risk that people will click emails they shouldn’t. And it’s not done out of spite; sometimes, they just really are that convincing.
But treating every mistake as a disciplinary event encourages silence if someone has potentially made a bad click, and all that does is give an attacker more time to cause chaos. You need to have a space where the behaviour and attitude revolves around rapid reporting, so someone can say: ‘I clicked this and something felt wrong.’
Give staff a visible reporting route, so if they use it (or IT flags the breach), you’re sure that somebody is ready to act to step in with a fix. Training works best when it reflects the emails people actually receive and is backed by technical controls (and no, carrying out a quarterly multiple-choice quiz tacked onto a 15-minute, AI-generated video on phishing isn’t enough to carry your whole defence).
What should a business do after a suspected phishing click?
A suspected click alone isn’t proof of a breach, but it is a reason to move quickly, and your response process should tell people who to contact and give the technical team or security provider a clear starting point.
Report and preserve
Report the message immediately and preserve it for analysis.
Check activity
Review sign-ins, mailbox rules, delegated access, application consents and recent downloads.
Contain the identity
Contain affected accounts and sessions, then reset credentials through a known-clean route where appropriate.
Understand the blast radius
Establish what data and connected systems the identity could access, not only what sat inside the inbox.
Keep a decision log
Bring in leadership, legal, insurance, communications or regulatory specialists when the facts require it.
Learn without blame
Review why the message succeeded and improve the relevant control, process or training.
The National Cyber Security Centre recommends planning for incidents in advance and aligning incident response with business continuity, disaster recovery and communications. Why? Well, that’s because ‘the middle of an incident’ is a pretty poor time to discover that the only copy of the plan is in the compromised mailbox, for example.
Could better cyber security have prevented it?
Possibly, but no responsible provider can promise that a phishing email will never get through or that nobody will ever click on one.
That means the better question is whether a single click has the ability to cause a major breach. Layered email security, strong identity controls, limited permissions, active monitoring and a rehearsed response can reduce both the likelihood of compromise and the damage that follows.
Governance belongs in that conversation, too. Assume that internal emails and documents may one day be read without the context in which they were written. Keep records accurately. Challenge opaque decisions. Retain information for a reason, not simply because storage is cheap. Cyber resilience and good governance reinforce each other.
The question to take into your next leadership meeting
The Manchester City case, according to the reporting, began with an email that looked normal enough to click. Years later, the consequences are still unfolding in a very public manner.
You don’t need to have a football club’s profile to face the same underlying risk; all you need is an inbox, a trusted relationship and information worth taking. So that limits it to… just about any business, ever.
If a senior colleague clicked a convincing phishing email this afternoon, would you know by tomorrow what the attacker had reached?
If the honest answer is ‘not with confidence’, that right there is the gap to work on. Fifosys helps organisations strengthen email security, identity controls, monitoring and incident response in a way that fits the business around them, so reach out to us and we’ll help you explore more. Start with visibility. Then make one click a contained event, not the opening chapter of a very long story.
Manchester City phishing story FAQs
Was Manchester City hacked through a phishing email?
According to reporting cited in this article, a phishing email impersonating a UEFA contact was sent to a Manchester City official in 2017. The recipient reportedly clicked a download link, after which Rui Pinto gained access to internal material.
Why can phishing have consequences years after the original attack?
Once sensitive information is stolen, an organisation may lose control over when and how it is later used. Internal documents can be reviewed by journalists, regulators, litigants, competitors or criminals long after the technical compromise has been contained.
Why do convincing phishing emails work?
Effective phishing often relies on familiarity and context. Attackers imitate organisations or people the recipient expects to hear from and provide a plausible reason to click, sign in, approve a request or open a document.
Does MFA stop phishing?
MFA significantly strengthens account security, but it cannot prevent every form of phishing. Session theft, consent phishing and convincing approval prompts can still create risk, so MFA should sit alongside email security, conditional access, monitoring and staff awareness.
What should a business do after someone clicks a phishing email?
Report and preserve the message, review sign-in and mailbox activity, contain affected accounts and sessions, establish what systems and data were accessible, keep a decision log and involve relevant specialists where necessary.
How can businesses reduce the impact of a compromised account?
Apply least-privilege access, separate administrative and everyday accounts, monitor unusual account activity, protect identities with strong authentication and keep an incident response process that can quickly contain affected accounts and sessions.
Can phishing ever be completely prevented?
No security control can guarantee that every malicious email will be blocked or that nobody will ever click one. The aim is to combine prevention, identity protection, limited permissions, detection and response so a single mistake is less likely to become a major incident.
Make one bad click a contained event
We can help you strengthen email security, identity controls, monitoring and incident response so a convincing phishing message has fewer places to go.
Talk to our team
Bring us your phishing, identity or email-security concerns and we’ll help you understand where the biggest gaps sit.
Security Framework
See how Fifosys brings identity, email protection, monitoring and response into a structured cyber security approach.