Britain’s highest court handed down a ruling on 27 July 2026 that dismantles one of the most powerful procedural shields available to authoritarian states conducting spyware campaigns against dissidents on UK soil. The UK Supreme Court held, by a 3–2 majority, that remotely infecting a computer physically located in the United Kingdom constitutes an act carried out in the United Kingdom — stripping the Kingdom of Bahrain of its state immunity from civil suit and clearing the path for two London-based pro-democracy activists to take their case to trial. Foreign governments that deploy surveillance software against targets in Britain, without ever sending an agent into the country, now face the same civil liability in English courts as those that send operatives in person. (Exchange rate as of 28 July 2026; conversions are approximate.)
Who Bahrain Allegedly Targeted and Why
The case centers on Dr Saeed Shehabi, 71, a journalist and leader of the Bahrain Freedom Movement and founder of the Bahraini opposition organization Al Wefaq, who has lived in the United Kingdom since 1973, was granted asylum in 1985, and became a British citizen in 2002. According to Leigh Day, over the following decades he became one of the most prominent voices of the Bahraini opposition abroad, writing for Arabic-language publications and organizing protests in London. Bahrain later stripped Shehabi of his citizenship, citing national security concerns.
The second claimant is Moosa Mohammed, a photographer and pro-democracy activist who arrived in Britain in 2006 after being arrested and allegedly tortured by Bahraini police, according to his legal team at Leigh Day. He was granted refugee status in 2007.
Both men were, at the time of the alleged surveillance, actively working to document and expose human rights abuses inside Bahrain — communicating with political prisoners, journalists, and torture victims, and publishing accounts of the regime’s conduct online. The Bahraini Ministry of Foreign Affairs later publicly condemned their activities; in 2021, both were included on a list of Bahraini nationals whose citizenship had been revoked, according to Computer Weekly.
What FinSpy Does — and What Bahrain Allegedly Got Access To
FinSpy — also marketed as FinFisher — is a government-grade commercial Remote Access Trojan developed and sold by the UK/German Gamma Group to law enforcement and intelligence agencies as a “lawful interception” tool, per its MITRE ATT&CK classification. Its capabilities, once deployed on a target machine, are comprehensive: the software logs every keystroke, captures screenshots, harvests files, passwords, and messages, intercepts encrypted communications, tracks the device’s physical location, and — most intrusively — remotely activates the target’s microphone and camera, transforming the device into a listening post without the owner’s knowledge, Red Hat documents. Later versions employed up to four layers of obfuscation, including infection at the firmware level via the Master Boot Record and UEFI, making the software difficult to detect even by security researchers, Kaspersky researchers reported in Dark Reading.
According to court documents cited by The Record, the alleged FinSpy infection of the claimants’ laptops — which they allege began in September 2011 — enabled Bahraini agents to access and exfiltrate messages, emails, calendar records, contact lists, browsing history, photographs, databases, and documents. It also allegedly allowed the remote activation of their laptops’ cameras and microphones. At the time, both men were in daily contact with sources inside Bahrain who trusted them with sensitive information about political persecution. The knowledge that those contacts may have been exposed caused both men to suffer significant psychiatric harm, their legal team says.
The claimants learned their computers had been compromised only in August 2014, when WikiLeaks published a trove of internal Gamma Group documents and the advocacy organization Bahrain Watch identified Shehabi and Mohammed as specific targets of the alleged Bahraini campaign.
Despite its “lawful interception” branding, FinSpy attracted sustained documentation of alleged misuse. Since 2011, Amnesty International and the Citizen Lab at the University of Toronto documented its deployment against activists and journalists in Bahrain, Ethiopia, Egypt, the UAE, Uganda, and Turkey — in most cases with no judicial oversight, Amnesty International reported. Bahrain was among the earliest and most documented cases. In 2015, the OECD’s UK agency ruled that Gamma International, FinSpy’s British distributor, had violated human rights standards seven times through its sales — making it the first piece of software in the OECD’s history to be found in breach of the organization’s human rights guidelines. FinFisher GmbH declared insolvency in 2022 amid export control investigations.
Three Courts, One Question
The legal battle began in 2020, when Shehabi and Mohammed filed their claim at the High Court in London, seeking damages from Bahrain for harassment under the Protection from Harassment Act 1997 and for the psychiatric injury they suffered upon discovering the alleged surveillance, Leigh Day confirmed.
Bahrain’s response was not to contest the underlying facts on their merits — the government denies the hacking — but to argue that the lawsuit could not be heard at all. Under the State Immunity Act 1978, foreign states generally cannot be sued in UK courts. The Act’s Section 5 creates an exception: immunity is removed for personal injury or property damage “caused by an act or omission in the United Kingdom.” Bahrain’s argument was that its alleged agents had operated FinSpy from servers located outside Britain, meaning no relevant act had occurred on UK soil.
Sir Julian Knowles of the High Court rejected that argument in February 2023. The Court of Appeal unanimously agreed in October 2024, drawing a widely quoted analogy: remotely hacking a computer in the UK was comparable to burglars breaking into a house and stealing the contents of a safe — the fact that the burglars never crossed the threshold did not mean the act occurred somewhere else, Leigh Day reported.
Bahrain appealed to the Supreme Court, its final option.
How the Supreme Court Split and Why It Matters
The Supreme Court’s decision in The Kingdom of Bahrain v Shehabi and another [2026] UKSC 25 was handed down on 27 July 2026. Lord Lloyd-Jones, Lord Hamblen, and Lady Simler formed the majority; Lord Leggatt and Lord Burrows dissented, Matrix Chambers confirmed.
The majority’s analysis turned on the ordinary language of Section 5. Bahrain had advanced three alternative readings, each requiring either that the most causative act occurred in the UK, that every causative act occurred there, or that a foreign state’s agents were physically present on British soil. The majority rejected all three. The statute, they held, required only that some act causally connected to the injury occur in the United Kingdom — and remotely hacking a computer physically located in Britain satisfied that threshold, the Solicitors Journal reported.
The majority illustrated what Bahrain’s preferred interpretation would permit: a foreign state could remotely detonate a bomb in the UK via a drone, breach NHS hospital systems causing patient deaths, or interfere with aircraft landing at Heathrow — and face no civil liability in British courts. Parliament, the majority concluded, could not sensibly have intended the statute to permit those outcomes, ICLG reported.
The majority further rejected Bahrain’s argument that customary international law required a physical-presence test, finding a growing body of state practice supporting the broader territorial exception — though they acknowledged no prior case had extended immunity removal to a situation where the wrongdoer was never physically present in the target state, the Solicitors Journal noted.
What the Dissent Warns — and Why Parliament May Have to Act
The 3–2 split is not merely a narrow margin — it signals a genuine legal fault line that goes beyond this case.
Lord Leggatt, with whom Lord Burrows agreed, argued that Section 5 of the State Immunity Act 1978 should be interpreted consistently with the European Convention on State Immunity — the 1972 treaty that the Act was partially enacted to implement. That Convention’s equivalent provision explicitly requires that the foreign state’s agents have been physically present in the territory. By interpreting the Act to remove that presence requirement, the majority has, in the dissent’s view, placed the UK in breach of its obligations under a treaty it voluntarily ratified, Farrer & Co explained.
Jehad Mustafa, Head of Farrer & Co’s Sovereign Advisory practice and an expert on state immunity law, described the consequences as likely profound. “By holding that a foreign state can face proceedings in England for sovereign conduct overseas, the UK has become an outlier in the international community,” Mustafa said. “The decision will likely make London the preferred forum for a range of claims against states. Some may welcome this, but it will likely have a major effect on the UK’s international relations,” he told Farrer & Co.
Parliament has not yet responded to the ruling. The Foreign Office has not issued a public statement. Depending on the diplomatic consequences — and on how many foreign states face new litigation in London courts as a result — UK lawmakers may face pressure either to legislate an explicit cyber-operations exception to the State Immunity Act, or to revisit the country’s obligations under the European Convention. Neither path is straightforward.
Bahrain Is Not Alone: London’s Growing Spyware Docket
This ruling arrives in a London legal landscape that has been quietly becoming the world’s most active forum for state-spyware litigation.
In January 2026, the High Court ordered the Kingdom of Saudi Arabia to pay £3,025,662.83 (approximately $4,018,000 at current rates) in damages to Ghanem Al-Masarir, a London-based satirist and human rights activist whose iPhones were infected with Pegasus spyware — developed by Israeli company NSO Group — in 2018, Leigh Day announced. The court also found that Saudi Arabia had directed a physical attack against Al-Masarir outside Harrods in August 2018. That case was also brought by Leigh Day, and also turned on the Section 5 exception to state immunity. Saudi Arabia’s appeal was later struck out after the kingdom failed to pay £210,000 (approximately $279,000) in court costs.
A third case — brought by Bahraini blogger Yusuf Al-Jamri, who received asylum in the UK in 2018 and alleges his iPhone was hacked with Pegasus in 2019 — is also proceeding in the High Court. And WhatsApp’s lawsuit against NSO Group continues in US federal court, testing a parallel question: whether spyware vendors, not just purchasing governments, bear civil liability, Al Jazeera reports.
The Supreme Court’s ruling strengthens every one of these cases. Any state that has deployed spyware against a target in the UK — and there are documented cases involving governments across the Middle East, Central Asia, and East Africa — now faces a straightforward path to civil suit in British courts, provided the target can link the alleged infection to a device physically present in the UK at the time.
What This Ruling Does Not Decide
It is critical to be precise about what the 27 July 2026 ruling actually resolves. The Supreme Court addressed only one question: whether Bahrain can claim state immunity to block the case from being heard. The answer is no.
Whether Bahrain’s agents actually deployed FinSpy against Shehabi and Mohammed — and whether that deployment caused the psychiatric harm they claim — has not been determined. Those questions are entirely untested. The case now returns to the High Court, where the merits will be examined for the first time unless the parties reach a settlement. Bahrain has consistently denied the hacking.
Stanley Kwenda, Strategic Communications Advisor at Amnesty International, welcomed the ruling. “In establishing that the remote infection of devices from abroad constitutes an ‘act in the UK’, this ruling opens new avenues for justice and sends a signal that tech-enabled transnational repression will no longer be tolerated,” Kwenda said. “This is an important step for the two claimants and other spyware victims both in the UK and internationally who have been fighting for accountability,” Amnesty International reported.
Ida Aduwa, solicitor at Leigh Day, described the ruling as a clear message to overseas states that using intrusive surveillance technology against peaceful political activists “will face justice in the courts,” Computer Weekly reported.
For Shehabi himself — who has lived in London for more than five decades and spent over thirty of them as a documented target of alleged Bahraini surveillance — the ruling has a personal weight that goes beyond precedent. “It has taken many long and difficult years to reach this moment,” he said after the ruling. “The hardest part of being targeted by state-sponsored hacking is the feeling that nowhere is safe,” Middle East Eye reported.
Freedom House Documents the Wider Pattern
The Shehabi ruling does not exist in a vacuum. Freedom House, in its April 2026 report “Collaboration and Resistance: Tracking Transnational Repression in 2025,” documented 126 new incidents of physical transnational repression in 2025 — defined as state-led cross-border campaigns targeting diaspora members through violence, surveillance, and intimidation, the report found. Across the full decade from 2014 to 2025, Freedom House has recorded 1,375 direct, physical incidents committed by 54 governments in 107 countries. Digital surveillance — including spyware — is tracked separately as a non-physical tactic, meaning the true scope of state-sponsored digital repression is wider still.
The Freedom House database covers physical acts; alleged FinSpy deployments against Bahraini dissidents in London sit in the digital category. But the ruling in Shehabi is precisely the kind of accountability mechanism that Freedom House has called for. “More and more governments are attempting to silence critics who have fled their home countries to seek freedom. This disturbing trend should be a wake-up call for policymakers around the world,” Freedom House CEO Jamie Fly said in April 2026. “Democracies must do more to combat this authoritarian abuse of their sovereignty and their freedoms.”
Frequently Asked Questions
What does “state immunity” mean, and why had it protected Bahrain until now?
State immunity is a legal doctrine under which foreign governments are generally shielded from being sued in another country’s courts. It developed from the principle that one sovereign state should not sit in judgment over another. The UK’s State Immunity Act 1978 codifies this protection with specific exceptions — including Section 5, which removes immunity when personal injury is caused by “an act or omission in the United Kingdom.” Until this ruling, there was no decided case extending that exception to remote cyber operations where the foreign state’s agents were never physically present in the UK. Bahrain argued that issuing commands from abroad was not an act “in the United Kingdom.” The Supreme Court has now closed that gap — at least as a matter of UK domestic law — though the dissent warns the UK may now be out of step with its international treaty obligations.
Can the ruling force Bahrain to pay damages?
Not yet. The Supreme Court ruled only that Bahrain cannot use state immunity to block the case from going to trial. The underlying merits — whether Bahrain’s agents actually infected the claimants’ laptops with FinSpy, and whether that caused the psychiatric harm claimed — have not been determined. The case now returns to the High Court for that examination. If Bahrain is found liable, enforcing a damages award against a sovereign state is a separate legal challenge, as the Saudi Arabia-Al-Masarir case illustrates: the High Court awarded the Saudi dissident more than £3,025,662.83 (approximately $4,018,000) in January 2026, but enforcement against Saudi state assets remains an ongoing process.
Why does the dissent matter if the majority won?
The two dissenting justices — Lord Leggatt and Lord Burrows — argued that Section 5 should be read in line with the European Convention on State Immunity, which explicitly requires that a foreign state’s agents be physically present in the forum country for the territorial exception to apply. The UK ratified that Convention; if the majority’s interpretation conflicts with its obligations under the Convention, Parliament may face pressure to either legislate a clearer cyber-operations exception to the State Immunity Act, or to renegotiate or withdraw from the Convention. Legal experts at Farrer & Co have predicted that the ruling will make London the preferred forum for a range of claims against states — a development with significant diplomatic implications for UK foreign relations.
What steps can dissidents targeted by state spyware in the UK take after this ruling?
Any person in the UK who has credible evidence that a foreign government infected a device physically located in Britain with surveillance software can now pursue a civil claim against that government in UK courts — without the immunity defense blocking the case at the threshold. The practical requirements remain substantial: claimants need forensic evidence of the infection (typically from a reputable digital security lab such as the Citizen Lab at the University of Toronto), evidence linking the infection to the foreign government, and legal representation with experience in state immunity litigation. Organizations including Amnesty International, Access Now, and Front Line Defenders provide digital security assistance to at-risk individuals; Leigh Day and Bindmans have both established track records litigating state-spyware cases in the UK.
Click Here For The Original Source.
