London, 28 September 2026 — EBM Newsdesk Analysis — By Katie Winearls
This is not really a football story. It is about how corporate wrongdoing now comes to light. Across Europe, leaks rather than regulators have become the main way hidden practices surface, from football clubs to banks to offshore wealth centres. City’s case shows what happens when a company’s own words are read back to it by a tribunal.
Who Rui Pinto Is
Pinto’s archive is extraordinary. The cache contained more than 70 million documents and reached well beyond Manchester City, touching on allegations about Cristiano Ronaldo and plans for the European Super League. The City material was shared with Der Spiegel and partners in the European Investigative Collaborations network, and it helped trigger investigations by both UEFA and the Premier League.
Join The European Business Briefing
New subscribers this quarter are entered into a draw to win a Rolex Submariner. Join 40,000+ founders, investors and executives who read EBM every day.
SubscribeHis methods were illegal. He was arrested in Budapest in 2019 and later received a four-year suspended sentence. After a year in pre-trial detention, he agreed to cooperate with the Portuguese authorities and became a protected witness, living in safe houses at undisclosed locations. In Portugal, he remains deeply divisive: a whistleblower to some, a criminal to others.
Stolen Evidence, Real Consequences
This is the uncomfortable part for business. A man convicted of hacking supplied the material that helped bring down one of the world’s most powerful football clubs. The courts punished the method, and a tribunal acted on what it revealed.
Pinto has gone further than the panel. He describes City’s conduct as “meticulously orchestrated fraud”. That is his characterisation, not the tribunal’s wording, and City maintain their innocence and are expected to appeal. But the club’s case was ultimately damaged by its own emails. The lesson for any company is that internal messages are not private conversations. They are potential evidence.
What Boards Should Take From This
Three lessons stand out. First, assume that anything written internally could one day be read by a regulator, a journalist or a court. Governance that only works while nobody is looking is not governance, and investors increasingly expect institutional-quality standards as a baseline.
Second, cyber security is now a legal and reputational risk, not just an IT issue. Pinto reached City’s secrets through other people’s systems, which shows how exposed companies are through their lawyers, agents and advisers.
Third, the whistleblower question is unresolved. Europe now protects people who report wrongdoing they discover through their work. It does not protect people who break into systems to find it. Pinto sits in the grey zone between the two, and the next Football Leaks will too.
The Takeaway
My view is that Pinto’s vindication is real but awkward. He broke the law, and he was punished for it. Without him, the Premier League case would probably never have existed. For clubs owned by Gulf sovereign money, and for leagues whose value to broadcasters in the sports streaming war depends on trust, that is an unsettling thought. For every other company, the message is simpler: write every email as if it will be read aloud in court. One day, it might be.
Related Analysis




































