Kingdom of Bahrain v Shehabi — UK Supreme Court denies immunity for cross-border spyware attack

Case
The Kingdom of Bahrain v Shehabi and another
Court
UK Supreme Court
Judge
Lord Lloyd-Jones (Queen Elizabeth II, on the advice of the Prime Minister and Lord Chancellor, 2022); Lord Hamblen (Her Majesty Queen Elizabeth II, 2020)
Date Decided
27 July 2026
Citation
[2026] UKSC 25
Topics
State immunity, State Immunity Act 1978, personal injury, cyber-surveillance

Background

Two Bahraini political activists residing in the United Kingdom, Dr. Saeed Shehabi and Mr. Moosa Mohammed, brought a lawsuit against the Kingdom of Bahrain. They alleged that from around September 2011, agents of Bahrain hacked their UK-based computers using a sophisticated spyware program known as “FinSpy.” The hacking was allegedly initiated and controlled from outside the UK.

The spyware gave Bahrain’s agents the ability to covertly access and copy information from the computers, intercept communications, and use the devices’ microphones and cameras for surveillance. The activists claimed this intrusive monitoring amounted to harassment under the Protection from Harassment Act 1997.

After learning about the surveillance in 2014, both men claimed they suffered psychiatric harm, a recognized form of personal injury. In response to the lawsuit, Bahrain asserted that it was protected from the jurisdiction of UK courts by the principle of state immunity.

The Court’s Holding

The UK Supreme Court held that the Kingdom of Bahrain was not immune from the lawsuit. The decision turned on the interpretation of section 5 of the State Immunity Act 1978, which provides an exception to state immunity for proceedings concerning personal injury “caused by an act or omission in the United Kingdom.”

Bahrain argued that the exception did not apply because the responsible act—the launching of the spyware attack—occurred outside the UK. The Court rejected this. It ruled that the plain language of section 5 only requires “an act” that causes the injury to take place in the UK, not “the” initiating act or “all” causative acts. The court found that the infiltration of the spyware onto the respondents’ computers and its subsequent operation within the UK constituted “an act… in the United Kingdom” for the purposes of the statute.

The Court further reasoned that Parliament had deliberately omitted a requirement, present in some international conventions, for the state’s agent to be physically present in the UK when the harm occurred. This deliberate omission signaled an intention for the exception to apply more broadly. Because a legally causative act occurred in the UK and resulted in personal injury there, the exception to immunity was triggered.

Key Takeaways

  • The personal injury exception to state immunity under section 5 of the State Immunity Act 1978 requires only that *an* act causing the harm occurs in the UK; it does not require all causative acts to be within the jurisdiction.
  • A foreign state that conducts a remote cyber-attack (e.g., using spyware) against a computer located in the UK is performing “an act…in the United Kingdom,” and can be sued for personal injury that results.
  • The UK’s state immunity law is intentionally broader than some international treaties, and does not require the agent of the foreign state to be physically present in the UK for the personal injury exception to apply.

Why It Matters

This landmark decision confirms that state immunity is not a shield for foreign governments that conduct cross-border cyber-surveillance causing harm to individuals in the UK. The ruling adapts long-standing principles of jurisdiction to the realities of the digital age, where significant harm can be inflicted remotely from across national borders.

The judgment reinforces the principle of the UK’s territorial sovereignty. It ensures that individuals harmed on UK soil by the actions of a foreign state have a potential path to justice in British courts, even if the interference was initiated from thousands of miles away. It sets a significant precedent for holding states accountable for transnational torts committed via technology.

✉️ Get tomorrow’s cases before your first coffee
Daily Case Law is our free morning digest — the most substantive new decisions, filtered to your jurisdictions and topics, each linking back here for the full analysis.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top