Light bulb Limited Spots Available: Secure Your Lifetime Subscription on Gumroad!

Jul 30, 2026 · 7 min read

UK Court: Bahrain Can Be Sued for FinSpy Hacking

A foreign government reached into two laptops in London. Britain's highest court has now decided that reaching counts as acting on British soil.

Fifteen years after two Bahraini exiles in London found their laptops turned into listening posts, Britain's highest court told the government they blame that it cannot walk away. On 27 July 2026 the UK Supreme Court dismissed the Kingdom of Bahrain's appeal by three votes to two. A state that reaches across borders to plant spyware on a computer sitting in Britain has acted in Britain, the majority held, and loses the immunity that has kept states out of English courtrooms for nearly fifty years.

Key Takeaways

  • The Kingdom of Bahrain v Shehabi [2026] UKSC 25 was handed down on 27 July 2026 by a majority of three to two, Lord Leggatt and Lord Burrows dissenting.
  • Section 5 of the State Immunity Act 1978, the personal injury exception, applies because running spyware remotely on a computer sitting in the United Kingdom counts as an act committed there.
  • Saeed Shehabi and Moosa Mohammed allege that agents of Bahrain infected their computers with FinSpy in September 2011, reaching their files, their communications, and the machines' microphones and cameras.
  • The judgment describes conduct that "involved monitoring the respondents' activities on a wide-ranging basis and by highly intrusive means" and was capable of amounting to unlawful harassment.
  • The ruling settles jurisdiction, not liability: the case returns to the High Court for the merits to be examined for the first time.
A laptop open on a desk in a London flat with the webcam indicator glowing, representing FinSpy surveillance software running on a dissident's computer

What Did the Supreme Court Actually Decide?

It decided a narrow question with wide consequences: whether a state whose agents sit abroad can be sued in England for spyware installed on machines in England. By three to two, yes.

Bahrain argued that section 5 lifts immunity only where the act causing injury happened here, and that everything its agents allegedly did happened in Bahrain, on a Bahraini server. The majority rejected the split: separating where an act is performed from where it takes effect is artificial when the act is the manipulation of a machine thousands of miles away. Solicitors Leigh Day, who brought the claim, quote the court finding section 5 "clear and unambiguous."

Headlines keep flattening one detail: nothing has been proved against Bahrain. The court ruled on jurisdiction alone.

Who Are Saeed Shehabi and Moosa Mohammed?

Two Bahraini nationals who built lives in Britain decades apart, and who both kept criticising the government they left behind.

Dr Saeed Shehabi is a journalist and pro democracy activist who has lived in the United Kingdom since 1973 and became a leading voice of the Bahraini opposition in exile. Moosa Mohammed arrived in 2006 as a refugee, after being arrested and tortured in Bahrain.

Their claimed injury is psychiatric, which matters: section 5 covers death, personal injury and damage to property. The harm is not a stolen file but the damage of learning that your home computer had been watching you, camera and microphone included, while you talked to family and sources. Amnesty International called the ruling a message against transnational repression, noting that governments "may no longer be able to hide behind state immunity."

How Did FinSpy Get Onto Their Computers?

The public record of this case does not say. What is documented is how FinSpy reached other Bahraini activists in the same period, and it arrived by email.

In July 2012 the Citizen Lab at the University of Toronto published From Bahrain With Love: FinFisher's Spy Kit Exposed, analysing messages sent to Bahraini activists that April and May. The emails promised exclusive photographs of the political situation, and some impersonated Melissa Chan, then a reporter for Al Jazeera English. The attachments installed FinSpy, which logged keystrokes, captured screenshots, recorded Skype calls and lifted saved passwords.

This was never a boutique tool. Citizen Lab's March 2013 follow up, You Only Click Twice, found FinSpy command and control servers in 25 countries, Bahrain and the United Kingdom among them. The vendor is gone: FinFisher GmbH filed for insolvency in March 2022 after Munich prosecutors seized its accounts, and the ECCHR records charges against four of its managers in May 2023.

Why Did This Take Fifteen Years?

Because the two men did not know for three years, then spent more than a decade arguing about whether a court was even allowed to hear them.

The alleged infection dates to September 2011. Discovery came in August 2014, when WikiLeaks published a cache of internal Gamma Group material and the watchdog Bahrain Watch identified Shehabi and Mohammed as targets. The High Court rejected Bahrain's immunity argument in February 2023, the Court of Appeal agreed, and Bahrain appealed again. As The Record reported, the merits now go back to the High Court.

The arithmetic deserves stating plainly. Three years of not knowing, then twelve of procedure, to win the right to a trial. That is what a state immunity defence buys.

What Changes for People Targeted in Britain?

Foreign governments can now be sued in English courts for remote surveillance of people living in Britain, even when every keystroke of the operation happened overseas.

The pattern across the last seven months is hard to miss. In January 2026 a UK court held that Saudi Arabia could be sued over Pegasus spyware attacks. In February, a satirist won £3 million against Saudi Arabia over the same spyware. Bahrain is the third such ruling since January and the first to reach the Supreme Court, so it binds every court below. Leigh Day says it founds claims the firm is pursuing against Rwanda, Saudi Arabia and Pakistan.

The implication most coverage skips: the reasoning is not about spyware at all, but about remote acts with local effects. Any state operation that manipulates a device on British soil from abroad now falls inside the same logic, whatever the payload.

Why Email Users Should Care

Every spyware story arrives eventually at the same unglamorous door: before the exploit, before the camera, before the courtroom, somebody opened a message. FinSpy's documented route to Bahraini activists was a mail promising photographs from a protest, apparently sent by a journalist they trusted. The trust did the work.

Fourteen years later the move has only gone upmarket. In April 2026 the Committee to Protect Journalists reported spear phishing against Egyptian and Lebanese journalists, including Mostafa Al-A'sar and Ahmed Tantawy, attributed to a hired espionage group. If you write about a government, your inbox is the perimeter, and whoever breaches it will look exactly like a colleague.

A second reason has nothing to do with attachments. Shehabi and Mohammed learned they had been watched three years late, from a leak, through a watchdog. Nobody warned them. Closing that gap is what a state sponsored attack warning from Google exists for.

What Should You Do Right Now?

If you are a journalist, an activist, or an exile who criticises a government, four steps raise the cost of targeting you.

  • Treat unexpected attachments as hostile, even from people you know. The Bahrain lures impersonated a named Al Jazeera reporter. Confirm through a second channel first.
  • Switch on the hardened modes your devices already ship with. Apple's Lockdown Mode disables the attachment types mercenary exploits rely on, and Apple says no device running it has been compromised by known spyware. Google's Advanced Protection Program enforces security keys.
  • Act on state backed attack alerts the same day. They are warnings, not confirmations, and the response is to rotate credentials from a different device and call a digital security responder.
  • Separate your identities. One address for publication, another for sources and family, no shared password or recovery number.

If you suspect an infection, do not wipe the machine. Forensic evidence is the basis of cases like this one, as the Maria Teresa Montaño case in Mexico showed.

The Bottom Line

Two men in London, a German surveillance product sold to a Gulf monarchy, and a 1978 statute written long before anyone could reach into a laptop from another continent. The answer in Kingdom of Bahrain v Shehabi is that the statute copes fine: if the effect lands here, the act happened here. Fifteen years to establish that, and the trial has not started. But the trapdoor is closed.

Sources: UK Supreme Court, The Kingdom of Bahrain (Appellant) v Shehabi and another (Respondents) [2026] UKSC 25, The Record, UK court rejects Bahrain immunity claim in spyware case, Leigh Day, Dissidents win in Supreme Court as it rejects Kingdom of Bahrain's appeal, Amnesty International, UK Supreme Court ruling on Bahrain spyware case, Citizen Lab, From Bahrain With Love: FinFisher's Spy Kit Exposed, Citizen Lab, You Only Click Twice: FinFisher's Global Proliferation, ECCHR, Munich based tech company FinFisher is dissolved after investigations, and the Committee to Protect Journalists, Spyware and Press Freedom.

Stop Email Tracking in Gmail

Spy pixels track when you open emails, where you are, and what device you use. Gblock blocks them automatically.

Try Gblock Free for 30 Days

No credit card required. Works with Chrome, Edge, Brave, and Arc.