Ghanem Al-Masarir v Kingdom of Saudi Arabia

[2026] EWHC 119 (KB)

Case details

Case citations
[2026] EWHC 119 (KB)
Court
High Court (King's Bench Division)
Judgment date
26 January 2026
Judgment text

This feature is available to zoomLaw Pro members.

Subjects
Tort Civil procedure Privacy and harassment
Keywords
summary judgment state surveillance Pegasus spyware misuse of private information harassment trespass to goods assault expert evidence damages indemnity costs
Outcome
judgment for the claimant
Judicial consideration

This feature is available to zoomLaw Pro members.

Summary

Summary judgment may be granted where a defendant has had a proper opportunity to participate, has no real prospect of defending the claim, and there is no compelling reason for a trial. A defendant that deliberately refuses to engage cannot complain if the court makes factual findings and draws reasonable inferences on the evidence available, including findings of serious wrongdoing.

Covert spyware surveillance of personal devices may constitute misuse of private information, harassment and trespass to goods. The court applies the ordinary two-stage privacy test, and a course of covert surveillance may amount to harassment once discovered by the victim. Altering the physical configuration and functioning of a device through spyware is capable of constituting trespass.

Factual background

The claimant, a Saudi national and political commentator living in the United Kingdom, claimed damages against the Kingdom of Saudi Arabia for hacking by Pegasus spyware, a physical assault, misuse of private information, harassment, trespass to goods and assault.

The defendant initially challenged jurisdiction on state-immunity grounds. Julian Knowles J rejected that challenge and found, on the balance of probabilities, that the defendant was responsible for the spyware attack and physical assault: [2022] EWHC 2199 (QB); [2023] QB 475. The Court of Appeal dismissed the defendant’s appeal after it failed to comply with orders for security for costs. The defendant thereafter filed no defence and took no further part.

The issues were whether summary judgment should be entered, whether the pleaded civil wrongs were established on the unchallenged evidence, and the appropriate damages and costs.

Held

  1. Summary judgment. The claimant had permission, or did not require permission, to apply under CPR 24.4(1), because the defendant had filed an acknowledgment of service and had already had an opportunity to challenge jurisdiction. The court accepted the principles in European Union v Syrian Arab Republic [2018] EWHC 1712 (Comm). Summary judgment was also preferable because it produced a merits judgment and was likely to be easier to enforce than default judgment.
  2. Under CPR 24.3, the defendant had no real prospect of defending the claim and there was no compelling reason for a trial. The claimant’s evidence was credible and supported by expert and technical evidence. The defendant had served no defence or responsive evidence and had deliberately declined to participate. In those circumstances the court could make findings and draw reasonable inferences, provided there was a sound factual basis. The approach in King v Stiefel [2021] EWHC 1045 (Comm) and Stanbic Bank Ghana Ltd v Rajkumar Impex Private Ltd was accepted.
  3. The evidence established that the claimant’s iPhones had been infected with Pegasus and that the surveillance was directed or authorised by the defendant or its agents. The defendant was also responsible for the physical attack.
  4. Misuse of private information. Applying the two-stage test in McKennitt v Ash [2008] QB 73 and ZXC v Bloomberg [2022] 2 WLR 424, the claimant had a reasonable expectation of privacy in the data and communications accessed. The surveillance involved exceptionally grave invasions of privacy, and no countervailing justification existed.
  5. Harassment. The repeated and extensive surveillance amounted to a course of conduct which caused alarm, fear and distress and which the defendant knew or ought to have known amounted to harassment. The statutory defences were unavailable. The court applied the principles in Hayes v Willoughby [2013] 1 WLR 935, Majrowski v Guy’s & St Thomas’s NHS Trust [2007] 1 AC 224 and Gerrard v Eurasian Natural Resources Corp Ltd [2021] EMLR 8.
  6. Trespass and assault. Spyware altered the physical configuration and functioning of the iPhones and interfered with the claimant’s possessory interest in them. The hacking therefore constituted trespass to goods. The physical attack constituted assault and had no lawful justification.
  7. Summary judgment was entered for the claimant on the whole claim. Damages of £3,025,662.83 were awarded, together with interest included in the assessment. The claimant received the costs of the claim and application on the indemnity basis, assessed at 80% of the sums in the schedules.

The court’s approach to earlier authorities

This feature is available to zoomLaw Pro members.

Appellate history

  1. High Court (King’s Bench Division): Julian Knowles J rejected the defendant’s state-immunity challenge and found on the balance of probabilities that it was responsible for the spyware attack and physical assault: [2022] EWHC 2199 (QB); [2023] QB 475.
  2. Court of Appeal: the defendant’s appeal was dismissed after it failed to provide security for costs and comply with the court’s orders.
  3. High Court (King’s Bench Division): summary judgment entered for the claimant on the whole claim.

Key cases cited

This feature is available to zoomLaw Pro members.

Cases citing this case

This feature is available to zoomLaw Pro members.