UK court rejects Bahrain immunity claim in spyware case
The alleged hacking by officials in Bahrain “allowed access to and exfiltration of information on the computers, interception of communications conducted using the computers and use of the computers’ microphones and cameras to surveil the respondents,” according to the court opinion.
The United Kingdom’s Supreme Court ruled Monday that Bahrain can’t hide behind state immunity to block a lawsuit filed by two dissidents alleging the government infected their devices with spyware.
Saeed Shehabi and Moosa Mohammed allege Bahrain secretly installed FinSpy spyware on their laptops, likely in 2011. Government agents then spied on them as they worked with Bahraini political prisoners, journalists and torture victims, they allege.
The men now live in the U.K., where they filed a lawsuit contending that they are owed damages from Bahrain for the mental harm they suffered.
Source: https://therecord.media/uk-court-rejects-bahrain-immunity-claim-spyware-case
Related breach coverage
- Clover Health Investments Discloses Data Breach2026-07-21
Using social engineering, hackers compromised employee accounts with access to personal and health information. The post Clover Health Investments Discloses Data Breach appeared first on SecurityWeek.
- Critical Flaw Allowed to Azure Cosmos DB Pwnage2026-07-31
Named CosmosEscape, the vulnerability exposed the primary key for Cosmos DB accounts, granting full read and write access. The post Critical Flaw Allowed to Azure Cosmos DB Pwnage appeared first on SecurityWeek.
- South Korea Warns of State-Backed Watering Hole Attacks2026-07-31
South Korea warned that nation-state actors are using phishing and compromised websites to silently infect citizens and businesses. South Korea agencies (The National Intelligence Service, the National Police Agency, the Korea Internet & Security Agency, and the Financial Security Institute) jointly published an advisory warning that a state-backed hacking group is actively targeting South Korean […]
- Why brand impersonation is becoming an initial access vector2026-07-30
Brand impersonation now drives initial access, using fake sites and apps to deliver malware, making rapid takedowns essential to disrupt attacks. Attackers recently poisoned more than 700 websites, including sites run by Harvard, Oxford, and DuckDuckGo. They used a fake Cloudflare page to trick visitors into running a ClickFix attack that installed malware. Researchers tracing […]