UK Supreme Court Rules Spyware Victims Can Sue Foreign Governments

0
1

Key Takeaways

  • The UK Supreme Court held that Bahrain is not immune from suit under the State Immunity Act (SIA) because at least one causative act of the alleged FinSpy hacking occurred in the United Kingdom.
  • Section 5 of the SIA lifts immunity for claims of death, personal injury, or tangible‑property damage caused by “an act or omission in the United Kingdom”; the act need not be the initiating act nor require the foreign state’s agent to be physically present in the UK.
  • The decision creates a clear jurisdictional pathway for victims of cross‑border spyware (e.g., FinSpy, Pegasus) to pursue civil claims against foreign states in UK courts.
  • While the ruling removes the immunity hurdle, claimants must still prove personal injury or tangible‑property damage and establish attribution and causation at trial.
  • The judgment highlights divergent approaches internationally: the US FSIA requires the whole tort to occur on US soil, whereas the ECtHR locates the act in the surveilling state’s territory; the UK Supreme Court adopted a middle ground focusing on where the harmful act took place.
  • The ruling may deter future transnational digital repression by increasing the risk of legal accountability for foreign states that target UK‑based dissidents with spyware.
  • Ongoing challenges include proving that the foreign state operated the spyware, linking the intrusion to psychiatric or other personal injury, and navigating potential conflicts with extraterritorial human‑rights jurisprudence.

Background of the Shehabi Litigation
On 27 July 2024 the United Kingdom Supreme Court delivered its judgment in The Kingdom of Bahrain v. Shehabi and another (Shehabi). The claimants, Saeed Shehabi and Moosa Mohammad, are Bahraini dissidents residing in the UK who alleged that, beginning in 2011, their electronic devices were compromised with FinSpy spyware—a surveillance tool capable of accessing communications, files, cameras, and microphones. They contended that the pervasive monitoring caused diagnosable psychiatric injuries and formed the basis of a tort claim against Bahrain for personal injury. Bahrain invoked state immunity, arguing that the suit should be barred under the UK’s State Immunity Act 1978 (SIA). The claimants relied on Section 5 of the SIA, which removes immunity for claims of death, personal injury, or damage to tangible property caused by “an act or omission in the United Kingdom.” The central question was whether the remotely executed hacking satisfied that territorial requirement.


Lower Court Reasoning
Both the High Court of Justice (2023) and the Court of Appeal upheld the claimants’ position, reasoning that infecting a UK‑located computer with spyware constitutes a tortious act occurring within UK territory. The High Court emphasized that the act of remote infection interfered with the UK’s territorial sovereignty, while the Court of Appeal added that the hacking infringed upon the UK’s territorial integrity, thus qualifying as an act “in the United Kingdom” for the purposes of Section 5. Their decisions set the stage for the Supreme Court’s definitive interpretation of the SIA’s territorial exception.


Supreme Court’s Statutory Interpretation
The Supreme Court’s majority held that the wording of Section 5 is “clear and unambiguous.” It determined that the provision requires only one causative act or omission to have taken place in the UK; it does not demand that all acts constituting the injury occur domestically, nor does it require the foreign state’s agent to be physically present. The court rejected an unduly restrictive reading that would necessitate the foreign actor’s presence, noting that modern technology enables harmful acts to be performed remotely from abroad. Consequently, the majority concluded that a foreign state is not immune from proceedings concerning personal injury caused by an act (or series of acts) occurring in the UK, even if other causative steps transpire elsewhere.


Application to the FinSpy Allegations
Applying this principle, the majority identified several causative acts linked to the alleged personal injury: transmission of files to install FinSpy on UK‑based devices, installation of the spyware, its execution, exfiltration of data, and activation of microphones or cameras for recording. Although the initial command may have originated outside the UK, each of these steps occurred within UK territory and amounted to an interference with the UK’s territorial sovereignty. The court therefore found that a valid exception to state immunity existed, clearing the jurisdictional hurdle and allowing the case to return to the High Court for consideration of the merits.


Implications for Spyware Litigation in the UK
The Shehabi ruling is a watershed moment for victims of cross‑border spyware targeting UK‑based activists, journalists, and opposition figures. By confirming that foreign states cannot hide behind immunity when at least one element of the hacking occurs in the UK, the decision lowers a significant pretrial barrier that has historically prolonged such cases. The judgment is expected to reduce litigation costs and expedite substantive hearings, offering a more efficient route to redress. Notably, the ruling distinguishes the UK approach from the US Foreign Sovereign Immunities Act (FSIA), which has been interpreted to require the entire tort to occur on US soil—a standard the UK Supreme Court explicitly rejected.


Broader Landscape of Related Claims
Since the Shehabi case was filed in 2020, numerous similar claims have emerged in UK courts. Yusuf Al‑Jamri (Bahraini blogger) alleged Pegasus infection of his iPhone in 2019; Yahya Assiri (Saudi human‑rights defender) claimed spyware targeting between 2018 and 2020; Rania Dridi (UK‑based journalist) accused the UAE of Pegasus surveillance linked to Al Jazeera; and Faustin Rukundo (Rwandan opposition figure) pursued a claim against Rwanda for Pegasus use. All of these actions hinge on the immunity question resolved in Shehabi, and the High Court has already allowed several to proceed, staying them pending the Supreme Court’s decision. The Al‑Masarir case against Saudi Arabia, which resulted in a summary judgment after Saudi Arabia withdrew its defence, illustrates the type of damages—general damages for psychiatric injury and consequential loss of earnings—that may be attainable once immunity is set aside.


Challenges Remaining on the Merits
While Shehabi removes the immunity obstacle, claimants must still satisfy the substantive requirements of Section 5: proving death, personal injury, or tangible‑property damage. Claims based solely on economic loss or the mere exposure of private information, without a pleaded personal injury, will not fall within the exception, as noted in Lord George Leggatt’s dissent. Moreover, plaintiffs will need to demonstrate attribution—that the foreign state (or its agents) operated the spyware—and causation linking the intrusion to the alleged injury. Expert technical evidence will be crucial, as evidenced by the Al‑Masarir proceedings where forensic analysis established Pegasus presence and its psychiatric impact.


Relevance to Digital Transnational Repression
The decision also speaks to the broader phenomenon of digital transnational repression, wherein states use surveillance technologies to silence dissent abroad. By locating the harmful act within the victim’s territory, the UK Supreme Court offers a pragmatic tool for holding repressive states accountable, potentially deterring future extraterritorial hacking. However, the ruling creates tension with extraterritorial human‑rights jurisprudence, such as the European Court of Human Rights’ stance that surveillance acts are deemed to occur within the surveilling state’s territory. Reconciling these divergent approaches will be an ongoing challenge for lawyers and policymakers seeking consistent protection for victims of cross‑border digital abuse.


Looking Ahead
The Shehabi case now returns to the High Court of Justice for a trial on the merits. The removal of the immunity defence streamlines the procedural path, but the proceedings will still demand rigorous proof of who deployed the spyware, how the intrusion caused personal injury, and what damages are warranted. As more victims come forward, the UK is poised to become a leading forum for transnational spyware accountability, setting a precedent that may influence other jurisdictions grappling with the same technology‑driven repression. The case underscores the importance of clear statutory interpretation in adapting legal frameworks to the realities of modern, cross‑border cyber threats.

SignUpSignUp form

LEAVE A REPLY

Please enter your comment!
Please enter your name here