Manchester City, one phishing email, and 114 reasons to train your employees
One email. One click. And, nearly a decade later, 114 guilty verdicts.
The Manchester City financial scandal started with something far less sophisticated than disguised sponsorship agreements, hidden payments, or Premier League financial regulations.
It started with phishing.
In January 2017, a senior Manchester City official received an email that appeared to come from someone at UEFA. It contained a link to what looked like a financial compliance report.
The employee clicked "download."
That was all it took.
Think about that for a moment. One employee clicked one bad link. And the rest, as they say, is 114 guilty verdicts.
That happened in 2017. Phishing has gotten a lot more sophisticated since then.
Today's phishing email might perfectly mimic Microsoft, DocuSign, your bank, a customer, your CEO, or one of your vendors. Attackers can scrape LinkedIn and company websites to learn reporting relationships and job responsibilities. Generative AI makes it trivial to write polished, personalized emails without the bad grammar and awkward phrasing that used to give scams away.
And phishing isn't limited to email. It can arrive by text, Teams, Slack, social media, or even a phone call.
So what can an employer do?
Here are eight places to start.
1. Train employees to verify, not just recognize.
"Look for typos" is not a cybersecurity strategy anymore.
Employees need a simple rule: if an email unexpectedly asks you to click a link, download a file, enter credentials, move money, change banking information, or disclose sensitive information, verify the request through another channel.
Call the person. Open the website yourself instead of using the link. Start a new email using an address you already know.
The National Institute of Standards and Technology specifically recommends independently verifying suspicious or urgent requests rather than relying on contact information contained in the message itself.
2. Turn on multifactor authentication everywhere you can.
A stolen password shouldn't equal a stolen account.
Require MFA for email, cloud storage, payroll, HRIS platforms, remote access, financial systems, and especially administrator accounts.
Better still, move toward phishing-resistant MFA such as passkeys or FIDO security keys. Traditional text-message codes and one-time passwords are better than passwords alone, but sophisticated attackers can sometimes steal those, too. CISA and NIST both recommend phishing-resistant authentication for higher-risk accounts.
3. Stop giving everyone access to everything.
If one employee's account gets compromised, the attacker should not inherit the keys to the entire company.
Apply the principle of least privilege. Employees should have access only to the systems and information they actually need to do their jobs. Administrative access should be especially limited.
The smaller the compromised account's footprint, the smaller the potential blast radius.
4. Harden your email system.
Your employees should not be your only line of defense.
Use modern spam and malware filtering, safe-link scanning, attachment screening, and email authentication technologies such as SPF, DKIM, and DMARC.
DMARC, in particular, can make it harder for attackers to impersonate your company's domain in phishing campaigns.
5. Make reporting suspicious messages ridiculously easy.
Give employees a one-click "Report Phishing" button or an obvious place to forward questionable messages.
And don't punish people for raising false alarms.
I'd rather have IT review 50 legitimate emails than have an employee hesitate for 30 seconds over the one malicious email that matters.
Speed also matters after someone clicks. The sooner IT knows, the sooner it can disable accounts, revoke sessions, reset credentials, isolate devices, and determine what the attacker accessed.
6. Phish your own employees.
Run periodic simulated phishing exercises.
Not as a "gotcha." Not so HR can create a list of employees to discipline.
Use them to identify where your training and systems are failing.
Which kinds of messages fool people? Are executives more vulnerable to fake document-sharing notices? Is accounting susceptible to vendor-payment scams? Are employees entering credentials into fake Microsoft login pages?
Train against the attacks your workforce is actually falling for.
7. Protect the people attackers are most likely to target.
Cybercriminals don't choose victims randomly.
Executives, finance employees, HR, IT administrators, and anyone with access to payroll, employee data, banking information, confidential business information, or wire-transfer authority deserve additional safeguards.
Those safeguards might include stronger authentication, transaction verification procedures, tighter access controls, additional training, and alerts for unusual login behavior.
Your CFO should not be able to change a vendor's bank account based solely on an email. Neither should anyone else.
8. Have a plan for the click that gets through anyway.
Because eventually somebody will click something.
Your cybersecurity plan should assume that prevention will sometimes fail.
Know who gets called. Know how accounts get locked. Know who contacts your cyber insurer. Know how you preserve logs and evidence. Know when outside forensic counsel or cybersecurity professionals get involved. Know whether legal or regulatory notification obligations might be triggered.
And practice the plan before you need it.
Cybersecurity isn't just an IT problem. It's an HR problem, a training problem, a risk-management problem, a legal problem, and ultimately a business problem.
Manchester City reportedly spent years and enormous resources fighting over what Rui Pinto found after one employee clicked one link.
Your company probably doesn't have Manchester City's resources.
Train your employees accordingly.