What the Supreme Court Actually Decided on July 27
On July 27, 2026, a five-justice panel of the UK Supreme Court split 3-2 in Kingdom of Bahrain v Shehabi and another, cited as [2026] UKSC 25. Lord Lloyd-Jones, Lord Hamblen and Lady Simler formed the majority; Lord Leggatt and Lord Burrows dissented. The case had reached the country's highest court after the High Court and then the Court of Appeal, in [2024] EWCA Civ 1158, both rejected Bahrain's claim to state immunity.
The Supreme Court's majority held that a foreign state is not entitled to immunity from civil proceedings where its agents install spyware on a computer located in the United Kingdom and that causes psychiatric harm, even when the state's own agents never physically entered the country. That clears the case to proceed to a full trial in the High Court, where Bahrain's actual involvement and any damages will be decided on the facts.
The FinSpy Infection Behind the Case
Dr Saeed Shehabi and Moosa Mohammed are Bahraini pro-democracy activists who have lived in London for years. They allege that, beginning around September 2011, agents acting for the Kingdom of Bahrain infected their computers with FinSpy spyware, a surveillance tool capable of harvesting files, communications and keystrokes from an infected device. According to the Supreme Court's case summary, the two activists say they discovered the intrusion around August 2014, through disclosures connected to WikiLeaks and the Bahrain Watch research group, and that discovering they had been under surveillance for years caused them lasting psychiatric harm.
Bahrain's defense throughout the litigation was not that the hack did not happen, but that as a sovereign state it was immune from being sued over it in a UK court at all. That immunity argument, not the underlying facts of the hack, is what the Supreme Court has now rejected.
Why Location Was the Entire Legal Battle
Section 5 of the State Immunity Act 1978 strips a foreign state of immunity for proceedings over personal injury caused by an act or omission in the United Kingdom. The dispute that reached five Supreme Court justices was not whether Shehabi and Mohammed suffered harm, but whether spyware operated from Bahrain and aimed at computers sitting in London counts as an act in the UK at all.
The majority reasoned that the legally relevant conduct is where the operation is carried out against its target, meaning an act can be territorial even when the person directing it never crosses a border themselves; the judgment reportedly drew a comparison to a drone strike or a remote attack on NHS systems, where nobody would seriously argue the harm occurred only where the operator's console happened to sit. Lord Leggatt and Lord Burrows dissented on exactly this point, arguing that an official operating spyware from Bahrain is acting in Bahrain, and that the United Kingdom is merely where the consequences were felt rather than where the act itself took place.
Original Thesis: The Spyware Was Never a Foreign Import
Most coverage of this ruling has focused on what it means for the reach of state immunity into cyber operations. The detail that changes the calculation for UK policy is where FinFisher, also marketed as FinSpy, actually came from. According to litigation Privacy International brought against UK export authorities and research published by Citizen Lab, the spyware was developed and sold by Gamma International, a business registered in Andover in the United Kingdom, operating alongside a Munich-based sister company.
That means this is not simply a precedent about foreign states reaching into Britain from abroad. It is a precedent that lands on a UK-based commercial supply chain, one that has already faced years of separate scrutiny over whether its export licensing for authoritarian buyers complied with UK law. A tool built and marketed from British soil, once sold onward to a foreign government, has now produced a ruling that exposes that government to a UK lawsuit for exactly how the tool got used, which raises the stakes for any UK-domiciled surveillance vendor selling into markets with weak human rights records: the buyer's later conduct can now come back through a British courtroom in a way that also puts uncomfortable scrutiny on where the tool was built.
What Happens Next, and What This Ruling Does Not Do
The Supreme Court did not rule that Bahrain in fact authorized the hack, and it set no damages figure. What it decided is narrower and, in practical terms, more consequential: Bahrain cannot use state immunity to keep the case out of a UK courtroom. The claim now returns to the High Court for a full trial on the merits, where Shehabi and Mohammed will need to prove Bahrain's involvement and the extent of their psychiatric harm.
For any foreign government running, or considering running, a surveillance operation against a person physically present in the UK, immunity is no longer an automatic shield the moment a UK court is asked to hear the claim. And for any UK-based company building tools that make that kind of operation possible, this ruling is a reminder that the exposure does not end at the export license; it can resurface years later as a domestic lawsuit over what a foreign customer did with what it bought.
Read next: A 1947 Diary Just Set Europe's VPN Liability Rule | A Meta Ruling That Reaches Every UK Platform



