top of page

Transfer fees, trust, and the other cyber security gaps football still overlooks

  • Writer: Fleko
    Fleko
  • Jun 29
  • 3 min read

Football is very used to managing detail. Contracts are checked carefully, transfers involve legal and financial oversight, and access to players, medical information, and commercial data is usually tightly controlled. At the top end of the game, very little is meant to be left to chance.


Which is why the recent attempted fraud involving a Premier League transfer is so striking. According to a BBC report, cyber criminals were able to compromise email communications during a transfer process and attempt to redirect close to £1 million in payments by impersonating legitimate instructions. The money was recovered before it disappeared, but only just.


What stays with you is how ordinary the entry point was. There was no dramatic system failure in the way people often imagine cyber attacks happening. It began with email access, timing, and a level of trust that someone else had quietly inserted themselves into.

The idea that attackers only target the biggest organisations

There is still a tendency in sport to think cyber security problems belong to the biggest clubs, governing bodies or international brands. In practice, attackers are usually looking for opportunity rather than status.


Smaller clubs, agencies and sports organisations often handle significant payments, sensitive data and fast-moving communication across different people and suppliers. During busy periods, particularly around tournaments and transfer windows, unusual requests are less likely to stand out because everyone is already moving quickly.


Research across the sports sector suggests that around 70% of sporting organisations have experienced some form of cyber incident in recent years. That is not just an elite football issue. It reaches far wider into the industry than many organisations realise.

Why the basics still matter

A lot of serious cyber incidents still begin with fairly ordinary gaps. Weak passwords, outdated software, poorly managed access and unsecured devices continue to create openings because, quite often, they still work.


That is essentially what Cyber Essentials was designed to address. Backed by the UK government and supported by the National Cyber Security Centre, the scheme focuses on the baseline protections that make organisations significantly harder to compromise in the first place. Access control, software updates, device security and secure configuration all sit within that.


You can read more about the scheme itself on the National Cyber Security Centre website. The language around cyber security can make these things sound more technical than they really are. In practice, a lot of it comes down to whether sensible protections are consistently in place.

More than a compliance exercise

Cyber Essentials is sometimes treated as something businesses do for procurement forms or website credibility. The certificate matters, but the real value is usually much more practical.


It is about protecting financial transactions, sensitive conversations and the people trusting your organisation with their information. In sport, where relationships move quickly and reputation carries weight, that kind of care is hard to separate from how professional an organisation feels.


That becomes even more important heading into a summer where tournaments, transfers and commercial activity will all be moving quickly. When organisations are busy, people naturally rely more on trust, routine and assumption. That is often where the risk sits.

Where Fleko fits into it

One of the reasons organisations delay certification is because they assume the process will become disruptive or overly technical. In many cases, some of the foundations are already there. The useful part is understanding what still needs tightening and dealing with it properly.


That is where Fleko’s Cyber Secure services come in. The technical side of certification is handled clearly and practically, so organisations can keep running without trying to interpret every requirement on their own.


At its core, the work is straightforward. People deserve to know that the organisations handling their money, information and communication are taking reasonable care of it. In the current climate, that feels less like an added extra and more like the bare minimum.

Going into 2026

The sports industry is moving into one of the busiest and most commercially significant periods it has seen. The organisations that handle that well are unlikely to be treating cybersecurity as a separate compliance task in the background. It is becoming part of how trust is built and maintained.


Cyber Essentials will not solve every problem on its own, and it is not designed to. What it does provide is a strong baseline in an area where too many organisations still rely on assumptions rather than certainty.


At a time when trust matters as much as performance, having the basics in place should not really be negotiable anymore.


To check your compliance and understand how Fleko’s Cyber Secure services can support your organisation, get in touch with the team today.




 
 
 

Comments


bottom of page