Recent discussions surrounding the circulation of personal data, documents, and images on the internet have raised pertinent questions about the origins of this information and the validity of claims linking it to a breach of Morocco's security information systems. However, the National Police Directorate and the General Directorate for Territorial Surveillance have categorically denied any breach of their information systems or security databases. This official denial emphasizes the importance of discerning between genuine cybersecurity intrusions and the recycling of previously leaked data from external systems accompanied by fabricated content.

According to Hassan Kharrouj, a researcher and expert in digital technology and artificial intelligence, there exists a significant distinction between an actual cybersecurity breach and the re-circulation of data that has already been leaked from third-party systems. The official statement clarifies that the recently published personal data “was not, in any way, the result of a cybersecurity breach of security information systems,” but rather stems from outdated information downloaded from databases and information systems managed by insurance companies and health and social coverage organizations.

Moreover, the statement warned against the proliferation of manipulated photographs presented as images of employees within security services, along with the circulation of documents that are reportedly altered or forged, falsely claimed to be official security documents. The analysis put forth by Kharrouj includes elements that suggest the inauthenticity of these materials, such as the use of uniforms and military ranks that do not exist in Morocco's security apparatus, as well as incorrect visual identities and glaring linguistic errors.

In a technical assessment of this situation, Kharrouj argues that the statement from the National Police Directorate and the General Directorate for Territorial Surveillance provides information that allows for a clear differentiation between two distinct technical issues: a cybersecurity breach of a security information system and the republication of data previously acquired from third-party information systems. He asserts that the circulated data, as indicated in the statement, “does not belong to security databases,” but relates to outdated information sourced from external information systems overseen by insurance companies and health coverage entities, which has already become available on the dark web.

The expert emphasizes that the existence of valid data related to individuals or employees does not, in itself, constitute technical evidence of a breach within the respective organizations, as proving a breach necessitates identifying the system that was accessed, the means of access, and providing verifiable technical traces. Consequently, Kharrouj sets a stricter standard for evaluating the claims being circulated, stating that anyone asserting a genuine breach should present verifiable technical evidence, such as indicators of the breach, access pathways, time logs, file fingerprints, and data related to database structure.

Thus, the mere publication of images or documents, even when accompanied by real personal data that has previously been leaked, is insufficient to prove a breach of a specific information system, as clarified by Kharrouj. His technical analysis aligns with the official statement regarding the circulated documents and images, suggesting that the use of incorrect visual identities and unauthorized uniforms and ranks within Morocco's national security, alongside linguistic errors and administrative discrepancies, constitutes indicators that warrant scrutiny of the authenticity of these materials before treating them as official documents.

Kharrouj posits that the amalgamation of outdated data with forged documents or images can fall under methods of deception and social engineering, where accurate or previously leaked information is utilized to construct a false narrative, providing the fabricated content with an initial appearance of credibility. In this manner, the objective may not solely rest on breaching the targeted system but rather on convincing the audience that a breach has indeed occurred, by intertwining genuine old data with artificial elements.

Furthermore, Kharrouj highlights that the analysis of data sources and structure, along with the technical examination of documents and images, remains essential to evaluating such claims, rather than relying solely on the dissemination of files or screenshots as definitive evidence. One of the key points emphasized in the official statement is that the relevant security information systems “do not primarily connect to open internet networks,” which Kharrouj considers crucial in understanding the security architecture of sensitive systems.

He elaborates that safeguarding sensitive systems relies, among other mechanisms, on separation from open networks, stringent access control, and defined permissions, alongside continuous monitoring and auditing. He also notes that the protection of personal data is not limited to a single tool or technical measure but is part of a broader system encompassing prevention, monitoring, analysis, incident response, and digital forensic investigation.

Kharrouj asserts that dealing with cybersecurity incidents extends beyond repelling an attack or uncovering fake content; it involves preserving digital evidence, tracing the aftermath of electronic operations, and attempting to ascertain accountability, all in coordination with the relevant judicial authorities. This issue illustrates another facet of the challenges faced in contemporary cybersecurity, as targeting institutions is no longer solely linked to attempts to breach their servers or steal their databases, but can also include creating a digital narrative suggesting a breach has occurred when it has not.

Kharrouj warns of the dangers of this approach, which may involve using previously leaked data from another source, then recontextualizing it accompanied by forged documents or images, thereby potentially confusing public opinion and complicating the task of pinpointing the original source of information for non-experts.

From this perspective, he argues that combating digital campaigns relies not only on securing systems but also on the ability to analyze circulated content, identify data sources, assess the authenticity of documents, and trace digital footprints that may lead to those responsible for producing or disseminating false content. Kharrouj concludes that Morocco has accumulated institutional and technical expertise in cybersecurity and protecting critical infrastructures, as well as combating cybercrime, pointing out that the national security apparatus possesses specialized competencies in areas including digital forensic analysis, monitoring cyber attacks, and preserving digital evidence.

In contrast, the statement from the National Police Directorate and the General Directorate for Territorial Surveillance confirms that investigations and security inquiries will continue under the supervision of the competent public prosecutor's office, aimed at apprehending and stopping those involved in fabricating and disseminating false content to the public. The discussion revolves around the question of evidence: a claim of a security breach is not necessarily substantiated by circulating personal data or published images and documents on the internet, but requires verifiable technical traces linking that data to the claimed breached system. According to Kharrouj, the circulated materials, in light of the information disclosed by the official statement, do not provide this type of proof, suggesting instead a repurposing of old data integrated within content that the official statement claims is fabricated and forged, rather than any technical evidence confirming the successful breach of security information systems.

As reported by hespress.com.