UK Supreme Court Rules Foreign States Can Be Sued for Remote Spyware Attacks
In a landmark 3-2 decision, the UK Supreme Court ruled that foreign governments cannot use state immunity to block lawsuits over remote cyberattacks that target individuals on British soil.
- Human Rights Defenders
- Views the ruling as a vital, long-overdue mechanism to hold authoritarian regimes accountable for transnational digital repression.
- Legal & Corporate Risk Analysts
- Focuses on the technical recognition that remote network intrusions are legally equivalent to physical territorial breaches, setting a precedent for future corporate and state litigation.
- State Sovereignty Traditionalists
- Argues that expanding domestic jurisdiction over foreign intelligence operations violates customary international law and historical diplomatic norms.
At a glance
- The UK Supreme Court ruled 3-2 that foreign states cannot claim immunity for remote cyberattacks causing injury in the UK.
- The case involves two Bahraini dissidents who allege their laptops were infected with FinSpy malware in 2011.
- Justices determined that remotely manipulating a device located in Britain constitutes an 'act in the United Kingdom.'
- The ruling allows the dissidents to proceed with their lawsuit seeking damages for psychiatric harm.
- The decision sets a major global precedent for holding governments accountable for transnational digital repression.
The borderless nature of cyber-surveillance has long collided with the rigid, territorial rules of international diplomacy. If a government intelligence operator in the Middle East clicks a button to infect a laptop sitting on a desk in London, where did the attack actually happen? For years, states have operated under the assumption that because the physical keystroke occurred within their own borders, they were legally untouchable in the victim's country.
The UK Supreme Court has now provided a definitive answer that upends that assumption. In a landmark 3-2 decision handed down in late July 2026, the court ruled that the act occurs where the device is compromised. This effectively strips foreign states of their sovereign immunity for remote cyberattacks that cause harm on British soil, establishing a new frontier for digital accountability.[1][5][8]
The case that forced this legal reckoning, Kingdom of Bahrain v Shehabi, centers on two prominent Bahraini dissidents living in exile in the UK: Dr. Saeed Shehabi and Moosa Mohammed. Both men allege that their personal computers were covertly infected with commercial spyware by agents acting on behalf of the Bahraini government.[2][4]
The software in question is FinSpy, a sophisticated surveillance suite developed by the now-defunct German firm FinFisher. Unlike standard malware designed to steal passwords or display advertisements, FinSpy is marketed exclusively to law enforcement and intelligence agencies as a tool for total environmental control.[3][8]
Once deployed, the spyware does not merely exfiltrate static files. It logs every keystroke, intercepts encrypted communications, tracks the device's physical location, and can covertly activate the computer's microphone and camera to monitor the user's physical surroundings in real time.[4][8]
Shehabi and Mohammed allege that their devices were infected around September 2011, during the height of the Arab Spring protests, allowing Bahraini intelligence to monitor their communications with political prisoners and other activists for years. They only discovered the breach in 2014 following data leaks published by WikiLeaks and the watchdog group Bahrain Watch.[2][3][7]
In 2020, the two men filed a civil lawsuit against the Kingdom of Bahrain in the UK High Court. Because English law requires a specific type of damage to bypass certain legal hurdles, they sued for the severe psychiatric injury caused by the prolonged harassment and profound invasion of their privacy.[7][8]
In 2020, the two men filed a civil lawsuit against the Kingdom of Bahrain in the UK High Court.
Bahrain categorically denied the hacking allegations. However, rather than arguing the facts of the intrusion at this stage, the kingdom's legal defense relied on a much older shield: the State Immunity Act 1978. They argued that as a sovereign nation, Bahrain was immune from the jurisdiction of British courts.[6][8]
The core of Bahrain's argument rested on geography. Their lawyers contended that even if the hacking occurred exactly as alleged, the agents who initiated the cyber operation were located in Bahrain, not the UK. Therefore, the British legal system had no authority to intervene in the actions of a foreign state operating from its own soil.[5][8]
This forced the Supreme Court to interpret Section 5 of the State Immunity Act, known as the "territorial tort exception." This clause states that a foreign country is not immune from lawsuits regarding personal injury or property damage "caused by an act or omission in the United Kingdom."[1][5]
The majority opinion, delivered by Lord Lloyd-Jones, Lord Hamblen, and Lady Simler, concluded that the remote manipulation of a computer located in the UK constitutes an act within the UK. They rejected the premise that the foreign state's agents had to be physically present in Britain for the exception to apply.[8]
To illustrate the absurdity of Bahrain's interpretation, the majority justices offered a series of modern hypothetical scenarios. They noted that if physical presence were strictly required, a foreign state could remotely detonate a drone in London, or hack National Health Service (NHS) computers causing patient deaths, and still claim absolute legal immunity.[8]
The decision was not unanimous. Dissenting justices Lord Leggatt and Lord Burrows warned that the majority's interpretation could place the UK in breach of customary international law. They argued that international conventions have historically required the "author of the injury" to be physically present in the forum state when the tortious act occurs.[1][8]
Despite the dissent, the ruling bridges a critical gap between 20th-century legislation and 21st-century cyber warfare. By legally recognizing that a digital intrusion is a physical event on British territory, the judiciary has expanded the reach of domestic tort law to cover the realities of modern transnational repression.[1][5]
For authoritarian regimes that increasingly rely on commercial spyware to track dissidents, journalists, and human rights defenders across borders, the legal landscape has fundamentally shifted. The UK is no longer a safe harbor where foreign intelligence services can operate digitally without fear of civil liability.[2][4]
The implications extend far beyond this single lawsuit. Legal analysts note that the State Immunity Act 1978 has served as a model for similar legislation throughout the common law world, including in Australia and Singapore. Courts in those jurisdictions may now look to the UK Supreme Court's reasoning when handling their own state-sponsored hacking cases.[5]
With the jurisdictional shield removed, the case of Kingdom of Bahrain v Shehabi will now return to the High Court for a full trial on the merits. For the first time, a foreign state will be forced to answer for its alleged digital intelligence operations in a British courtroom, shifting the debate from theoretical immunity to concrete digital forensics.[2][7]
Terms to know
- State Immunity
- A principle of international law that generally protects a sovereign state from being sued in the domestic courts of another country.
- Territorial Tort Exception
- A legal carve-out allowing foreign states to be sued for personal injury or property damage caused by their actions within the host country's borders.
- FinSpy
- A commercial surveillance software suite, formerly sold by the German company FinFisher, capable of covertly extracting files and activating device cameras and microphones.
- Transnational Repression
- Actions taken by a government to target, harass, or silence dissidents, journalists, and political opponents living in exile abroad.
- Customary International Law
- Unwritten rules of international law derived from the consistent practice of states out of a sense of legal obligation.
Sources
[1]EJIL: Talk!Human Rights DefendersLocation, Location, Location: The UK Supreme Court's Judgment in Shehabi v. Bahrain
Read on EJIL: Talk! →
[2]Amnesty InternationalHuman Rights DefendersUK Supreme Court rejects Bahrain's invocation of state immunity against liability for spyware hacking against pro-democracy activists
Read on Amnesty International →
[3]The RecordLegal & Corporate Risk AnalystsUK court rejects Bahrain immunity claim in spyware case
Read on The Record →
[4]Computer WeeklyLegal & Corporate Risk AnalystsBahrain cannot claim sovereign immunity for spyware attack against UK dissidents, top UK court rules
Read on Computer Weekly →
[5]WilmerHaleLegal & Corporate Risk AnalystsUK Supreme Court Holds That Foreign States Carrying Out Spyware and Hacking Operations Are Not Entitled to State Immunity from Tort Claims
Read on WilmerHale →
[6]The GuardianState Sovereignty TraditionalistsBahrain is to tell the UK's supreme court that it enjoys sovereign immunity from claims it placed surveillance software on the computers of two dissidents
Read on The Guardian →
[7]Jerusalem PostUK Supreme Court rejects Bahrain immunity claim in dissidents' spyware lawsuit
Read on Jerusalem Post →
[8]ICLGLegal & Corporate Risk AnalystsBahrain cannot claim state immunity over alleged UK spyware campaign
Read on ICLG →
Comments
Every angle. Every day.
Get meta stories with full source coverage and perspective breakdowns delivered to your inbox.


