My understanding is that ex-City employees were able to access City's "Scout7" system on a number of occasions after they had joined Liverpool. If that is correct it might not be what is considered a classic hacking attack but does show poor practices in the IT systems. Any access should be revoked as soon as it is no longer needed by the individual to perform their job role and some form of multi-factor authentication should also have been implemented with the token handed back or disabled once the individual leaves.
I will concede that no IT security system is unhackable I think it is fair to say that with a best practice security policy implemented, enforced and regularly updated it would have been far harder for Pinto to gain access to City's emails and he may well have moved on to easier targets.