Summary
- The Supreme Court ruled by a 3–2 majority that Bahrain cannot use state immunity to halt the claim.
- The decision concerns jurisdiction and immunity, not whether the alleged hacking occurred.
- Remote digital operations may create legal exposure where the device and alleged injury are located.
A remote spyware operation allegedly directed from outside Britain can still amount to conduct taking place inside the country, the UK Supreme Court has ruled in a decision that gives greater legal weight to the location of the target.
The UK Supreme Court dismissed an appeal by the Kingdom of Bahrain by a 3–2 majority, allowing two UK-based dissidents to continue civil proceedings over alleged spyware infections on their computers.
Dr Saeed Shehabi and Moosa Mohammed allege that people acting for Bahrain infected their devices with FinSpy from around September 2011. Bahrain denies the hacking and argued that it was immune from proceedings under the State Immunity Act 1978.
The judgment addresses that preliminary immunity question rather than determining whether Bahrain conducted the alleged operation or bears liability for the claimed harm. The underlying case can now return to the High Court, where the evidence and merits remain to be examined.
Digital conduct can occupy several places
Bahrain’s argument relied partly on the alleged spyware operators being outside the UK. The respondents and their computers were in Britain, however, and they claimed psychiatric injury after discovering that they had been monitored.
The majority concluded that the alleged surveillance could fall within the personal injury exception to state immunity because the relevant interference and effects occurred in the UK. A remote command crossing a border did not make the domestic device, data, and person legally irrelevant.
Cyber operations routinely involve an operator in one country, infrastructure in several others, software developed elsewhere, and a target device in another jurisdiction. Treating only the attacker’s physical location as decisive would leave the place where the intrusion is experienced with little legal weight.
The court’s case page provides the judgment and summary, including the dissenting reasoning. One minority judgment warned that refusing immunity could place the UK in breach of international law and affect foreign relations, confirming that the decision turns on a contested interpretation rather than a routine procedural point.
Commercial spyware sits within the evidence chain
The case concerns alleged state conduct, but civil proceedings can also expose the commercial infrastructure surrounding surveillance tools. FinSpy was developed by the now-defunct FinFisher group, part of an industry that supplied governments with software capable of accessing devices, communications, files, cameras, and microphones.
Vendors may sit several steps away from an operation, with products sold through intermediaries, deployed by state customers, and supported across borders. Litigation against a government can reveal procurement records, technical evidence, infrastructure, and supplier relationships that would otherwise remain concealed.
Technology providers, resellers, consultants, investors, and insurers connected to surveillance products therefore face exposure beyond export licensing. Civil claims, sanctions, human rights due diligence, contractual disputes, and reputational damage can follow when tools are used against journalists, dissidents, lawyers, or political opponents.
The ruling does not make every remote state cyber operation actionable in Britain. Claimants still need a recognised legal basis, evidence, jurisdiction, and an applicable exception to immunity, while governments can contest attribution, causation, and the location of the alleged injury.
Evidence preservation becomes a legal requirement
Organisations supporting employees, researchers, activists, lawyers, or executives exposed to state-linked surveillance may need to treat incident response as both a technical and legal process. Device images, logs, threat intelligence, and communications can determine whether a victim is able to establish what happened years later.
Cyber insurers and specialist risk advisers may also have to examine where harm occurs. A compromise initiated abroad can disrupt work, expose confidential information, and injure people within the UK, creating disputes over policy territory, notification, and applicable law.
Public bodies and companies purchasing surveillance or investigative technology face the opposite side of the issue. Procurement controls need to define lawful purpose, authorisation, audit logging, data retention, access, and supplier conduct, especially where tools can be operated remotely across national borders.
The narrow majority and substantial dissent mean future courts will examine the judgment carefully. Its immediate effect is more limited: Bahrain cannot end this claim solely by invoking state immunity at the preliminary stage.
Remote access allows spyware to be operated from almost anywhere, but the alleged interference still reaches a physical device and a person in a particular jurisdiction. The Supreme Court has now given that location greater weight, while leaving the underlying allegations to be tested in the High Court.




