UK spyware and transnational surveillance

UK Supreme Court's Narrow Ruling Opens British Courts to Transnational Spyware Victims

A 3-2 Supreme Court ruling lets two Bahraini dissidents sue Bahrain over 2011 FinSpy hacking, redrawing state immunity for cyber-era harm.

Bahrain v Shehabi: The Numbers Behind the Ruling People of Internet Research · UK 3-2 Supreme Court vote margin The narrowest possible majority re… 2011 Year alleged infection began Victims allege FinSpy was installe… ~3 yrs Years until discovery The dissidents learned of the hack… 6 yrs Years in UK litigation Filed in London's High Court in 20… peopleofinternet.com
Bahrain v Shehabi: The Numbers Behind … People of Internet Research · UK 3-2 Supreme Court vote margin 2011 Year alleged infection began ~3 yrs Years until discovery 6 yrs Years in UK litigation peopleofinternet.com

Key Takeaways

A narrow majority, a wide precedent

On 27 July 2026, the UK Supreme Court ruled 3-2 that the Kingdom of Bahrain cannot claim state immunity to block a civil lawsuit brought by two London-based dissidents who allege Bahraini agents infected their laptops with FinSpy spyware in 2011 (Kingdom of Bahrain v Shehabi, UKSC/2024/0152). Saeed Shehabi, a journalist and founder of a Bahraini opposition party, and Moosa Mohammed, a Bahraini refugee, say the malware let unknown operators log keystrokes, exfiltrate files, intercept communications, and activate their laptops' cameras and microphones — while they worked with political prisoners, journalists and torture victims in Bahrain (The Record). They learned of the intrusion only in August 2014, via disclosures from WikiLeaks and the watchdog group Bahrain Watch, and sued in London's High Court in 2020 for the psychiatric injury that discovery caused.

The legal question was narrow but consequential: does section 5 of the State Immunity Act 1978 — which strips immunity for "death or personal injury... caused by an act or omission in the United Kingdom" — apply when the hacking itself was directed by agents sitting outside Britain, but its effects landed on victims and machines physically in the UK? The Court held that it does. Because the malware executed and operated on computers in the UK, and the psychiatric harm crystallised there, the claim falls within the personal-injury exception even though nobody acting for Bahrain needed to set foot in the country. The 3-2 split — one of the closest possible margins on the UK's top bench — shows how contested that reading was even among justices sympathetic to the outcome.

The case for caution

State immunity is not an anachronism to be waved away lightly. It exists because reciprocity between sovereigns underpins ordinary diplomacy: a Britain that lets its courts adjudicate the conduct of foreign intelligence services should expect its own agencies to face equivalent suits abroad, including in jurisdictions far less scrupulous about due process than the UK's. Immunity doctrine also keeps foreign-policy disputes — which are often better resolved through diplomatic channels, sanctions, or intelligence-sharing leverage — out of civil courtrooms not designed to weigh classified evidence or geopolitical consequences. Bahrain's dissenting justices were right to worry aloud that stretching "act in the United Kingdom" to cover effects of conduct initiated entirely overseas could, in principle, expose a much wider range of state-to-state digital friction — cyber-espionage, disinformation operations, even routine signals intelligence — to private litigation never contemplated by a 1978 statute drafted for embassies and expropriated ships, not malware.

Why the majority got it right anyway

That caution, however, has to be weighed against what happens if courts refuse to adapt at all. Commercial spyware — FinSpy among the more notorious examples, developed by the Gamma Group and marketed for years to governments with weak rule-of-law constraints — has made remote, borderless surveillance of exiled critics cheap and deniable. A dissident who flees to London for safety gains little protection if the state they fled can still monitor their devices from Manama, and if UK courts treat the resulting harm as legally invisible because the hacker's fingers never crossed a border. The majority's reasoning does not invent new liability; it applies an existing, narrowly drawn exception — personal injury caused by conduct with effect in the UK — to a fact pattern the drafters of the 1978 Act simply could not have anticipated. That is incremental judicial adaptation, not regulatory overreach, and it leaves the immunity shield fully intact for the vast run of diplomatic and state conduct it was built to protect.

Critically, the ruling settles only jurisdiction, not liability. Bahrain still denies the hacking occurred and can contest the substance at trial; Shehabi and Mohammed must still prove their case on the facts. What the judgment removes is the procedural shortcut that let a state avoid ever being asked to answer for alleged conduct on UK soil.

The wider signal for spyware governance

Amnesty International called the ruling a message that "tech-enabled transnational repression will no longer be tolerated," and predicted it would open avenues for other spyware victims to sue in UK courts (Amnesty International). That prediction is plausible and, on balance, welcome. Britain has positioned itself — through initiatives like the Pall Mall Process on commercial cyber-intrusion tools — as an advocate for curbing spyware abuse without banning the underlying technology outright, recognising that lawful-intercept and offensive-cyber capabilities have legitimate uses in policing and national security. A judiciary willing to let victims seek civil redress, case by case, evidence by evidence, is the proportionate complement to that stance: it raises the cost of targeting dissidents on British soil without imposing blanket export controls or extraterritorial regulation that would sweep up legitimate security research and lawful government purchasers alike. Courts, not blunt statutory bans, are well suited to sorting genuine abuse from legitimate use — provided, as here, they do so through careful, split-decision reasoning rather than sweeping pronouncement.

For governments weighing whether commercial spyware campaigns against exiles are worth the risk, the arithmetic just changed. The case now returns to trial on the merits — where Bahrain's denials, and the evidence behind Shehabi and Mohammed's claims, will finally be tested.

Sources & Citations

  1. UK Supreme Court case page, Kingdom of Bahrain v Shehabi (UKSC/2024/0152)
  2. State Immunity Act 1978, section 5
  3. The Record: UK court rejects Bahrain immunity claim in spyware case
  4. Al Jazeera: UK court dismisses Bahrain's bid to block activists' spyware lawsuit
  5. Amnesty International statement on the ruling