Decoding the world of cybersecurity

Spyware claim clears UK immunity hurdle

A divided Supreme Court has ruled that foreign-state hacking of a computer in Britain can constitute an act in the UK, allowing a civil spyware claim against Bahrain to proceed.

Spyware claim clears UK immunity hurdle
Summary
  • The Supreme Court dismissed Bahrain’s appeal by a three-to-two majority.
  • Remote hacking of a computer located in Britain can qualify as an act in the UK under the State Immunity Act.
  • The allegations against Bahrain were assumed for the immunity hearing and have not been proved at trial.

The UK Supreme Court has removed a state-immunity barrier from a civil claim alleging that Bahrain remotely infected two computers in Britain with spyware.

In a three-to-two judgment delivered on 27 July, the court dismissed Bahrain’s appeal against earlier decisions allowing proceedings brought by Dr Saeed Shehabi and Moosa Mohammed to continue. The ruling concerns jurisdiction and state immunity, not whether Bahrain carried out the alleged surveillance.

Shehabi, a Bahraini opposition figure and journalist who has lived in Britain since 1973, and Mohammed, a photographer and democracy activist resident in the UK since 2006, allege that people acting for Bahrain hacked or infected their computers from around September 2011.

The suspected operators were likely outside Britain, while both claimants and their computers were in the UK. They say they suffered psychiatric harm after learning about the alleged compromise in 2014 and contend that the conduct amounted to harassment.

Bahrain sought to end the proceedings under the State Immunity Act 1978. Foreign states generally have immunity from the jurisdiction of UK courts, although section 5 creates an exception for personal injury or property damage caused by an act or omission in the United Kingdom.

The court’s judgment summary records that the majority found no requirement for the responsible person to be physically present in Britain. An act can be carried out through a device, automated system, or remote means, so hacking a computer located in the UK can amount to an act in the UK for the purpose of the statutory exception.

Lord Lloyd-Jones, Lord Hamblen, and Lady Simler formed the majority. Their judgment treated the alleged surveillance as a serious interference with British territorial sovereignty, regardless of whether the person operating the spyware remained abroad.

Territory is no longer confined to the operator

The ruling gives digital interference a territorial location based partly on the system and surveillance affected, rather than solely on the physical position of the person issuing the command. Remote state operations routinely cross national borders without an agent entering the country where the effect is produced.

Under the majority’s reasoning, distance does not prevent an act from occurring in Britain when a device located there is caused to perform surveillance. The judgment compares remote action with other conduct carried out through machinery, where the operator’s location does not remove the act from the territory in which it occurs.

Lord Leggatt and Lord Burrows dissented. Leggatt concluded that an act normally occurs where the actor is located, while its effects may be experienced elsewhere. He warned that treating the location of an effect as the location of an act creates uncertainty and conflicts with the international-law framework governing state immunity. Burrows also considered the legislation capable of an interpretation aligned with the European Convention on State Immunity.

The split judgment leaves limits that future cases will need to test. The decision turns on section 5, the alleged personal injury, and the connection between the spyware activity and computers in Britain; it does not determine every form of remote state conduct.

Nor does the ruling establish attribution. The Supreme Court heard the appeal on assumed facts and did not decide whether Bahrain was responsible, whether the spyware operated as alleged, or whether the claimants can prove the harm and causes of action advanced.

The proceedings can now move towards those factual issues. Civil litigation may provide one of the few mechanisms through which people targeted by alleged foreign-state surveillance can seek disclosure, test technical evidence, and establish responsibility.

Commercial spyware operations often involve vendors, intermediaries, infrastructure providers, government customers, and targeted devices spread across several jurisdictions. The judgment places the location of the compromised computer within that accountability chain and prevents physical distance alone from resolving the immunity claim.

×