New Supreme Court spyware ruling has lessons for cyber exclusions

Judges split 3-2 on whether hacking a UK computer from abroad counts as an "act" in the UK - a question that echoes the attribution problem underwriters have been wrestling with since 2022

New Supreme Court spyware ruling has lessons for cyber exclusions

Cyber

By Matthew Sellers

A Supreme Court judgment handed down on 27 July has nothing to do with insurance. It's a dispute about state immunity, spyware and two London-based activists suing the Kingdom of Bahrain. But buried in the reasoning is a question that will sound familiar to anyone who has spent time on a cyber war exclusion: when a hack is carried out remotely, does it matter where the hacker was physically sitting?

What the case was about

The claimants, Dr Saeed Shehabi and Mr Moosa Mohammed, are pro-democracy activists and prominent critics of the Bahraini government who have lived in the UK for decades. They allege that from 2011, people acting for Bahrain infected their computers with spyware called FinSpy, giving access to their files, communications, camera and microphone. On the facts assumed for the appeal, the operators were working from outside the UK, running the spyware through a server based in Bahrain. The claimants say they only learned of the surveillance in 2014, after WikiLeaks and an organisation called Bahrain Watch published information about the program, and that discovering what had happened caused them psychiatric injury.

Bahrain argued it was immune from being sued in a UK court at all. The relevant provision, section 5 of the State Immunity Act 1978, removes a foreign state's immunity for personal injury or property damage "caused by an act or omission in the United Kingdom." Bahrain's case was that the relevant act, typing instructions into a computer, happened wherever its operatives were located, which was outside the UK. The claimants argued that hacking a computer sitting in London is itself something done in the UK, regardless of where the hacker was.

The Supreme Court split 3-2 in the claimants' favour. Lord Lloyd-Jones, Lord Hamblen and Lady Simler held that remotely manipulating a device in the UK is an act within the UK for the purposes of the statute, whether or not the hacker ever set foot here. Lord Leggatt and Lord Burrows dissented, both concluding that this reading put the UK in breach of its obligations under the 1972 European Convention on State Immunity, which requires the person responsible to have been physically present in the country where the harm occurred.

Why it's relevant to cyber underwriters

The judgment doesn't touch on insurance and won't be cited in a coverage dispute directly. But the underlying question, how much weight to put on the physical location of an attacker versus the location of the target, sits close to the attribution problem that's shaped Lloyd's cyber war exclusions since 2022.

Following Russia's invasion of Ukraine, Lloyd's began requiring standalone cyber policies to carry an exclusion for state-backed attacks, built around the LMA's model clauses (LMA5564 through LMA5567, later updated into "A" and "B" versions). Those clauses ask whether an attack can be attributed to a state and whether it had a war-like or major national-impact effect. Both questions are hard to answer in practice, particularly the first. Brokers have noted that state-linked cyber capability now extends well beyond the handful of countries usually associated with it, and that the line between a nation-state operation and ordinary cybercrime leaves clients more exposed when they have any government-facing business.

The Bahrain case doesn't settle a coverage question, but it shows how UK judges reason through a closely related one. The majority's view was that once a device physically located in the UK is compromised, it doesn't matter whether the person responsible ever left their own territory. Lord Leggatt's dissent argued the opposite: that collapsing the distinction between an act and its remote effects makes it unclear where any given "act" is legally deemed to happen, which is close to the definitional problem that has dogged the LMA clauses. As Kennedys and others have pointed out when analysing recent Middle East cyber spillover, most carriers now carry some form of war exclusion, but working out whether an incident is genuinely state-directed rather than carried out by state-linked actors without formal sanction is a forensic exercise that can take months, often longer than insurers have to make a claims decision.

What it doesn't decide

The Supreme Court was interpreting a 1978 statute on when a foreign state can be sued in a UK court, not construing a policy wording. Nothing in the judgment says how an insurer should apply the national-infrastructure threshold in LMA5567A, or how a court would treat "objectively reasonable" attribution language in a contract.

What it does provide is one of the few detailed judicial examinations of how English law treats the geography of a remote hack, an issue that had barely been tested before this case and the related Al Maktoum phone-hacking litigation cited in the judgment. For brokers with clients who have state-adjacent exposure, or underwriters drafting the next round of attribution wording, it's worth keeping on file, even though it never mentions insurance once.

Related Stories

Keep up with the latest news and events

Join our mailing list, it’s free!