
What hath Hatman wrought? Huge new data breach or old data recycled?
It’s a breach, but how did it really happen, and what should be done about it?


English Premier League soccer team Manchester City FC (Man City, as they’re known colloquially) have won the world’s richest football league eight times.
Since 2019, however, the club has been under investigation for financial irregularities relating to the league’s Financial Fair Play (FFP) rules.
Many big-money sporting leagues around the world have financial controls of this sort, aimed in part at preventing clubs from buying their way to victory.
After all, if an expensive buying spree of top talent doesn’t work out, the solvency of the club is at risk, which isn’t fair to the other teams, and could threaten the league as a whole.
But if it does work out, the league itself risks becoming uncompetitive and lop-sided, which isn’t fair to the other teams, either.
Last Friday [2026-09-25], news broke claiming that Man City had finally been found guilty on all but one of 115 charges against the club.
This includes a claimed 54 financial reporting failures from the 2009/10 season up to and including the 2017/18 season, during which the club won three league titles, and 35 charges of failing to co-operate with investigations from the end of 2018 on.
Quite how this investigative saga will end is hard to guess, given how long it’s been going on already, and given that City are likely to appeal.
Points deducted in the current season, perhaps enough to ensure they are relegated next year? Huge fines? Expulsion from the league altogether? Stripping the club of its titles? Legal claims for damages from other clubs?
Whatever happens, it’s worth remembering that this long-running drama kicked off in the first place because of a data breach.
Back in 2015, Portuguese football fan Rui Pinto, who’s now 37 years old, set up a website called Football Leaks, allegedly with the purpose of revealing the financial shenanigans he claimed were commonplace in top-flight European football.
Automated translation via Google:
This project aims to expose the hidden side of football. Unfortunately, the sport we love so much is rotten, and it is time to put a stop to it. Investment funds, commissions, shady deals – it all serves to enrich certain parasites who exploit the sport, completely draining clubs and players alike.
Over the coming months, I will be sharing various materials that have come into my possession in recent years. There will be plenty of controversy and fascinating details – stay tuned.
I welcome donations, as acquiring all this material took a great deal of time, and it is always wonderful to contribute․․․
Apparently, Pinto fed his site with data extracted from thousands of emails he’d acquired from a football investment company, claiming, as shown above, that he wanted “to expose the hidden side of football.”
Readers and journalists liked what they saw, because Pinto acquired a popular public reputation as a whistleblower who took the lid off shady dealings in the big-money world of football.
But he also attracted the ire of Portuguese law enforcement authorities, who saw him first and foremost as a cybercriminal, not as the hero he became after releasing the data he described as having “come into my possession in recent years.”
The authorities claimed that Pinto not only stole the data he relied upon for his subsequent notoriety as a whistleblower, but also first used it in an attempt to blackmail the breached company into paying him to keep the breach secret.
Pinto, who was working in Hungary at the time, was arrested in 2019 at the request of Portuguese investigators, extradited to Portugal, charged, and put on trial.
He was ultimately convicted of multiple cybercrime offenses, including unlawful access to data, and cyber-extortion.
Finally, in 2023, he was given a four-year suspended prison sentence.
He was also charged with cybercriminality in France, where he received a six-month suspended sentence.
Pinto was prosecuted again in Portugal in 2025 on a further sea of charges in a similar vein, but that case was thrown out in early 2026.
The court told the prosecutors that they couldn’t have a second go at him, because his previous conviction and sentence had already set the matter to rest, so there was no new case to answer.
Pinto’s tortuous journey through the legal system has run the gamut of arrest, solitary confinement, extradition, home detention, witness protection, trials, convictions, and an acquittal, spread over many years.
But the side-effects of his Football Leaks website, though apparently fed by the fruits of cybercriminality, are now being felt by the world’s richest football league, and one of its most successful clubs.
As the BBC wrote, with perhaps just a touch of metaphorical overload::
For some, Rui Pinto is a criminal hacker who stole information with sinister intentions. To others he is a heroic whistleblower who shone a light on the darker side of the beautiful game.
What is undeniable is that one Portuguese man on his computer in Budapest has had a seismic impact on global football.
Or, as Pinto’s own lawyer put it in a more down-to-earth way:
In his statement in court, Francisco Texeira da Mota, representing Pinto, accepted that his client was “not a hero and not a saint” but said he had brought “advantages for society.”
It’s therefore important to remember that:
Even if you elicit (and, indeed, deserve) sympathy as a breach victim, you may also end up in trouble of your own, either for wrongdoings revealed in the data once it’s leaked, or simply because you should have protected it better.
Best defense: Don’t get breached in the first place!
Reach out to the experts today to learn how SolCyber can help you become cyber-resilient.
Ask how SolCyber can help you do cybersecurity in the most human-friendly way. Don’t get stuck behind an ever-expanding convoy of security tools that leave you at the whim of policies and procedures that are dictated by the tools, even though they don’t suit you or your business!
Paul Ducklin is a respected expert with more than 30 years of experience as a programmer, reverser, researcher and educator in the cybersecurity industry. Duck, as he is known, is also a globally respected writer, presenter and podcaster with an unmatched knack for explaining even the most complex technical issues in plain English. Read, learn, enjoy!
Featured image of football by Janosch Jost via Unsplash.

It’s a breach, but how did it really happen, and what should be done about it?

Business Email Compromise (BEC) is a type of email cybercrime in which attackers impersonate the owner of an email account in an effort to defraud a company. The attack, which is increasing in prevalence, often looks to obtain funds or credentials. Global losses from BEC attacks have increased by 17% from December 2021 to December 2022, reports the FBI’s Internet Crime Complaint Center (IC3). From October 2013 to December 2022, the IC3 recorded over $50 billion in global losses due […]

What if we all adopted a cybersecurity culture anchored in value and quality, instead of a race-to-the-bottom predicated on cheapness and quantity?

By subscribing you agree to our Privacy Policy and provide consent to receive updates from our company.






