Courts & Litigation Cybersecurity & Tech Foreign Relations & International Law

U.K. Supreme Court Opens Door for Spyware Victims to Sue Foreign States

Siena Anstis, Natalia Krapiva, Kate Pundyk
Friday, August 28, 2026, 10:50 AM

The Kingdom of Bahrain cannot claim immunity from a suit by exiled dissidents over harm caused by spyware surveillance on U.K. soil.

External facade of the Supreme Court of the United Kingdom (Dietmar Rabich, https://tinyurl.com/36jt9vrh, CC BY-SA 4.0, https://creativecommons.org/licenses/by-sa/4.0/deed)

On July 27, the Supreme Court of the United Kingdom issued its highly anticipated decision in The Kingdom of Bahrain v. Shehabi and another (Shehabi). The majority of the court confirmed that the Kingdom of Bahrain is not immune from litigation stemming from the hacking of the devices of Bahraini dissidents living in the United Kingdom with FinSpy spyware. FinSpy gives its operator broad access to a target’s computer, including their communications, files, camera, and microphone.

This decision is a significant development. Cross-border hacking with spyware such as FinSpy (or the more notorious Pegasus) is a growing concern in the United Kingdom, where exiled human rights defenders, journalists, and members of a political opposition group have sought to hold foreign states accountable for repressive monitoring through civil proceedings over the past few years. The Supreme Court’s ruling on immunity in Shehabi provides exiles in the U.K. with greater certainty that claims against foreign states for spyware hacking will be viable at the jurisdictional stage, opening substantive pathways for victims to obtain redress.

This case is significant for the global fight against digital transnational repression and spyware abuse, as it demonstrates how jurisdictions are diverging in their treatment of cross-border hacking. In the United States, the Foreign Sovereign Immunities Act’s (FSIA’s) territorial tort exception has been read to require the entire tort to occur on U.S. soil. Across the Atlantic, the European Court of Human Rights (ECtHR) held that a hack occurs in its country of origin rather than where the victims were located. The U.K. Supreme Court chose not to follow either example. Such different interpretations highlight that, despite the victory in Shehabi, the transnational nature of repressive spyware and digital attacks more generally makes it difficult for cases to advance.

The Judgment

The claimants, Saeed Shehabi and Moosa Mohammad, are both Bahraini dissidents living in the United Kingdom. Their 2020 complaint alleged that, starting in 2011, their devices were targeted with FinSpy spyware. This spyware, originally developed and marketed by Gamma International, a U.K.-based company later known as FinFisher GmbH (a German entity), facilitates intrusive surveillance of a target’s activities—including access to communications, internet use, and the information stored on the targeted device. Shehabi and Mohammad claimed Bahrain’s pervasive FinSpy surveillance amounted to harassment that resulted in diagnosed psychiatric injuries. These injuries served as the basis for their tort claim.

Bahrain challenged the court case, arguing that it was immune from suit. The claimants invoked the Section 5 exception to state immunity under the U.K.’s State Immunity Act (SIA). Section 5 of the SIA provides that a foreign state is not immune in legal proceedings involving claims of death, personal injury, or damage to or loss of tangible property that is “caused by an act or omission in the United Kingdom.” The interpretation of Section 5 of the SIA—in particular whether the author of the injury had to be in the U.K. for the immunity of the foreign state to be lifted and the case to proceed—became the central issue in the Shehabi case.

In 2023, the U.K. High Court of Justice—a trial-level court, broadly comparable to a U.S. district court—ruled that Bahrain was not immune from legal proceedings, holding that remotely infecting a U.K. computer with spyware constitutes a tortious act that occurred in the United Kingdom. The Court of Appeal upheld this conclusion, noting that the hacking of devices located in the United Kingdom infringed on the U.K.’s territorial sovereignty, and so should be treated as an act within the U.K. Confirming the lower courts’ judgments, the majority of the Supreme Court ruled that the wording of Section 5 of the SIA was “clear and unambiguous.” As with the lower courts, the majority was satisfied that several causative acts underlying the plaintiffs’ injuries—including infection, access, infiltration, and surveillance—occurred in the U.K. and thus there was a valid exception to state immunity.

The Supreme Court’s majority analysis was grounded in the plain meaning of the SIA statute. The phrase “an act or omission in the United Kingdom” in Section 5 of the SIA requires simply that a causative act or omission has occurred in the U.K. It does not require that all causative acts take place in the U.K.—there simply needs to be “an act” that arises in the U.K. that “causes personal injury or damage to property” (and it is “irrelevant whether other acts or omissions occur elsewhere”).

Further, the alleged act relied on by the plaintiff need not be the “initiating, precipitating or responsible act.” Nor did a state agent have to be present within the forum state’s territory. As the court observed, requiring the presence of the foreign agent in the territory of the forum state would be “unduly restrictive” and fail “to take account of the fact that modern technology enables acts to be carried out remotely from abroad.” In short, the majority concluded that Section 5 of the SIA “means there is no sovereign immunity for a foreign state for proceedings in respect of personal injury caused by an act (or acts) in the United Kingdom, even if other causative acts take place abroad and the actor is not present in the United Kingdom.”

The majority concluded that several causative acts were implicated in the alleged personal injury against the claimants, including the transmission of files to install FinSpy on devices located in the U.K., the installation of FinSpy, running the spyware, exfiltrating or causing information to be exfiltrated from the devices, and activating or causing the device’s microphones and/or cameras to be activated and used for recordings.

These assumed facts, the majority concluded, constituted “a causative act or series of acts in the United Kingdom” involving the surveillance of persons in the U.K. “by means of the hacking of computers in the United Kingdom.” While these acts may have been initiated from abroad, the acts still took place within, and involved an “interference with the territorial sovereignty” of the U.K., and caused injury to the respondents. As a result, the court cleared the jurisdictional hurdle allowing the case to go back to the High Court to proceed on merits.

What This Case Means for Spyware Litigation in the U.K.

The Shehabi case is a significant milestone for future spyware litigation in the United Kingdom. The Kingdom of Saudi Arabia brought the first claim of sovereign immunity in a spyware case to block a case filed by Ghanem Al-Masarir, a Saudi dissident living in the U.K. Al-Masarir alleged that Saudi Arabia had infected his phone with NSO Group’s Pegasus spyware, causing him psychological injury, in addition to orchestrating a physical attack against him.

Saudi Arabia initially argued for state immunity under the SIA. The U.K. High Court, however, ruled that the suit could proceed on the basis that at least some of the personal injuries had been committed within the U.K. In 2026, after Saudi Arabia stopped defending the case, the U.K. High Court ruled in favor of Al-Masarir on summary judgment, making it the first successful substantive judgment against a foreign state using spyware to target a civil society actor in the U.K.

In Shehabi, the U.K. Supreme Court definitively confirms that foreign state immunity does not bar claims against states for remotely installed spyware, rendering the United Kingdom a promising forum for cross-border spyware accountability. The Supreme Court’s decision in Shehabi is significant as foreign states will now struggle to argue they are immune from legal proceedings in the context of transnational hacking cases.

Indeed, the hacking alleged by Shehabi and others is not an isolated case. A number of other dissidents, journalists, and human rights advocates have filed legal claims in the United Kingdom. Yusuf Al-Jamri, a prominent blogger from Bahrain living in the U.K., filed a claim in 2024 against Bahrain, alleging that it targeted his iPhone with Pegasus spyware in 2019. In 2024, the High Court of Justice allowed him to serve his claim. The High Court specifically stayed the case until the release of the Shehabi judgment. Yahya Assiri, a Saudi human rights defender living in the U.K., also brought a claim in 2024 against Saudi Arabia, alleging that the kingdom targeted him with spyware between 2018 and 2020. Rania Dridi, a U.K. citizen and journalist, filed a claim against the United Arab Emirates in September 2023, alleging that the UAE targeted her with Pegasus spyware between 2019 and 2020, as part of wider surveillance against Al Jazeera journalists. And Faustin Rukundo, a Rwandan opposition figure in the U.K., has also brought a case against Rwanda for the use of Pegasus spyware against him. As all these cases are against foreign states, the issue of foreign state immunity is in play.

Besides clearing the muddy waters of foreign state immunity in U.K. law, the Shehabi case hopefully lowers the pretrial barriers (and costs) to bringing a claim. Immunity disputes have drawn out spyware litigation for years. Shehabi was filed in 2020 and took six years to resolve the pretrial jurisdictional immunity issue. The U.K. Supreme Court’s ruling means this should no longer be the case, likely providing a more efficient route to resolving the suits’ merits and resulting in lower overall costs for civil society claimants. This is a promising development, particularly with the lack of options for claimants in other countries such as the United States. There, the FSIA has been interpreted to require the whole tort to occur in the U.S., an approach rejected by both the majority and the dissent in Shehabi.

While the Supreme Court’s immunity decision is a big step forward for transnational spyware litigation, there will be other challenges. In particular, future claimants will have to establish that their claim falls within the scope of Section 5 of the SIA, which is confined to “death or personal injury” and “damage to or loss of tangible property.” A claimant must plead one of those qualifying heads to fit within Section 5 of the SIA and defeat immunity. As Lord George Leggatt observed in his dissenting opinion in Shehabi, claims framed solely around economic loss or the exposure of private information—with no pleaded personal injury or property damage—will fall outside the exception. However, once a claimant overcomes this obstacle, consequential loss flowing from that injury is potentially recoverable.

Indeed, the successful outcome in Al-Masarir suggests that spyware victims are well placed to prove the type of injury required under Section 5 of the SIA. Drawing on expert evidence, Al-Masarir was able to establish that his iPhones were hacked with Pegasus spyware, resulting in “the exfiltration of data from those mobile phones and that this conduct was directed or authorized by the KSA or agents acting on its behalf.” Based on this hacking, he was then able to establish causes of action for misuse of private information, harassment, and trespass to goods.

Al-Masarir successfully claimed damages for personal injury, including general damages (pain, suffering, and loss of amenity), past losses (medical costs and loss of earnings), and future losses (medical costs, travel costs, and loss of earnings). Drawing on expert evidence, Al-Masarir established psychiatric injury from the discovery of Pegasus on his device, which included a “vivid account of the devastating impact on his mental health of this discovery.” The court ultimately awarded Al-Masarir around 100,000 British pounds in general damages for psychiatric injury and over 2.5 million pounds in consequential lost earnings on the basis that his depression had ended his career as a YouTube content creator.

It should be noted that Saudi Arabia did not mount a real defense in Al-Masarir for the summary judgment, as the kingdom stopped participating in the proceedings after the court found it did not have immunity. Because of this, it remains unclear how such claims would play out in the face of a substantive defense by a foreign state. There is no doubt that issues of causality and attribution (such as proving that the foreign state was the operator of the spyware and that personal injury resulted) will dominate future trials in the U.K. That said, the Al-Masarir case demonstrates the central importance of compelling evidence from technical experts in such proceedings.

What This Case Means for Digital Transnational Repression More Broadly

Shehabi is a victory for U.K. victims of acts of transnational repression. Transnational repression arises when states seek to intimidate, suppress, or silence dissidents, human rights defenders, journalists, or others seeking to challenge state power from abroad. Such behavior is necessarily extraterritorial or cross-border and implicates a range of methods, such as killings, physical intimidation, and surveillance, that occur outside the territory of the perpetrating state.

From a legal perspective, the majority decision in Shehabi is a sensible outcome. As the majority notes, deciding otherwise would “lead to arbitrary distinctions.” Under the dissenting opinion’s approach, whether a state enjoys immunity would turn on where the responsible actor was physically present. A state that sends agents into the U.K. to kill a target—as Russia did in the killing of dissident Alexander Litvinenko—would not be immune. But a state that achieved the same outcome while keeping the causative acts abroad, for example by using a drone operated outside the country, could claim immunity. From a policy perspective, the majority decision is also a positive development—particularly in the U.K., which is known as a fertile territory for transnational repression—as it may provide some deterrence against foreign states engaging in such activities.

However, the logic underlying the decision in Shehabi raises interesting questions in other legal contexts. In particular, victims of digital transnational repression will likely seek accountability against the foreign perpetrating state by arguing there has been a breach of regional or international human rights treaties (where state immunity does not arise). Because digital transnational repression involves extraterritorial human rights violations, these cases raise whether the perpetrating state owes human rights obligations to victims of digital transnational repression located outside the perpetrating state’s territory.

Take one example: The ECtHR has long held that, under the European Convention on Human Rights, states owe human rights obligations only to individuals located within the territory of the state. There are limited exceptions to this, such as where the infringing state exerts effective control over an area outside its national territory or where it exercises physical control or power over a specific person located outside its national territory.

In Wieder and Guarnieri v. the United Kingdom, the ECtHR held that surveillance by the U.K. of individuals located outside the United Kingdom was actually undertaken by U.K. intelligence agencies that were acting, to the “best of the Court’s knowledge,” within the U.K. The ECtHR rejected the state’s argument that interference with the private life of the applicants “occasioned by the interception, storage, searching and examination of their electronic communications could not be separated from their person and would therefore have produced effects only where they themselves were located—that is outside the territory of the United Kingdom.” In that case, the ECtHR concluded that the interception of the communications of foreign targets actually occurs in the territory of the surveilling state, and that the surveillance target’s physical location outside the territory of the offending state did not preclude the state’s responsibility under the Convention.

While the ECtHR and the U.K. Supreme Court addressed completely different legal questions, the logic underlying these decisions is hard to reconcile. The ECtHR concluded that extraterritorial surveillance by a state (in that case, the U.K.) should be understood as occurring within the territory of the state undertaking the surveillance and not where the targets were located, which was outside the U.K. This interpretation allowed the ECtHR to conclude that there was no issue of the extraterritorial scope of human rights obligations (which might have prevented the case from being resolved on the merits).

Yet, in the U.K. Supreme Court’s decision, the majority appears to conclude that the causative acts (which are similar to those in the ECtHR case—interception, searching, and surveillance) took place where the target was located (outside the territory of the perpetrating state). This leaves us with the question: Which is it? Is surveillance an act that takes place within the territory of the surveilling state or where the target is located? Or both?

*          *          *

The Shehabi case now returns to the U.K. High Court of Justice, where it will proceed on the merits. Other hurdles will persist in the proceedings, such as proving attribution, causation, and injury to the required standard. There are also lingering questions regarding how the logic of this decision will apply in other contexts, such as before the ECtHR. In any case, by removing the blunt defense of state immunity from these cases, the U.K. Supreme Court has dealt a meaningful victory to individuals and organizations fighting spyware and other forms of digital transnational repression.


Siena Anstis is a senior legal advisor with the Citizen Lab at the Munk School of Global Affairs and Public Policy (University of Toronto) and a PhD fellow in law at the University of Oslo. Previously, she worked as a litigation associate at Morrison & Foerster in New York City and clerked at the Supreme Court of Canada. Her scholarly work has been published in a range of publications, including the McGill Law Journal, the Canadian Bar Review, and the Oxford Journal of Human Rights Practice.
Natalia Krapiva is a Senior Tech-Legal Counsel at Access Now. She heads Access Now’s strategic litigation and oversees risk‑prevention efforts for the Digital Security Helpline and its beneficiaries. Earlier in her career, Natalia served as a prosecutor in the Brooklyn District Attorney’s Office and worked with a range of domestic and international criminal justice and human rights bodies. She earned a B.A. in Political Science from Columbia University and a J.D. from UC Berkeley School of Law, and she is licensed to practice law in New York State.
Kate Pundyk is a researcher at the Citizen Lab (University of Toronto) and a JD/BCL candidate at McGill University. She was previously a researcher at Yale’s Humanitarian Research Lab, the Mass Atrocities in the Digital Era initiative at the Yale Genocide Studies Program, and the Oxford Internet Institute. She has master’s degrees in both regulating artificial intelligence and diplomacy from Oxford, where she studied as a Rhodes Scholar.
}

Subscribe to Lawfare