The recent emergence of the cyber threat posed by JabaROOT has made headlines on August 12, with claims that carry significant political and diplomatic implications. According to information gathered by Estrella Digital, this group asserts it has gained access to systems associated with Moroccan intelligence, claiming to possess internal documentation detailing agents, collaborators, targets, and operations.

However, the authenticity of the files, including their date, origin, and the means by which they were allegedly obtained, requires independent technical analysis. As of now, there has been no official confirmation from Moroccan authorities regarding this alleged breach.

JabaROOT Threatens to Release Sensitive Intelligence Information

JabaROOT claims to hold personal data linked to Moroccan intelligence services. The group has threatened to disclose this information along with documents that, according to their assertions, would allow for the reconstruction of operations, contacts, and surveillance objectives both within and outside Morocco. This assertion potentially impacts the two main branches of the kingdom's intelligence apparatus: the General Directorate for Territorial Surveillance (DGST), which deals with domestic security, and the General Directorate for Studies and Documentation (DGED), responsible for foreign espionage. So far, the group has not provided sufficient public evidence to determine which agency may have suffered the breach or whether the data comes from a single database.

The indiscriminate release of names, addresses, phone numbers, or family information poses a severe risk to the safety and privacy of the individuals involved.

Spain and Algeria Identified as Top Targets

One of the most sensitive aspects of this claim is the alleged existence of Moroccan espionage plans targeting both Spain and Algeria. JabaROOT asserts that the files would reveal objectives, recruitment methods, and operations conducted or planned in these two countries. In the case of Spain, any authentic document would have immediate implications for national security. Spain and Morocco maintain a close cooperation on issues such as immigration, terrorism, drug trafficking, and border control; however, they also experience significant diplomatic tensions over Ceuta, Melilla, Western Sahara, and the migration crisis of May 2021.

The most delicate precedent is the Pegasus case, wherein the National Court investigated the hacking of phones belonging to Prime Minister Pedro Sánchez and several ministers. This investigation was provisionally shelved for the second time in January 2026 due to a lack of cooperation from Israel, and the investigation did not attribute the authorship to any particular individual or service, as reported by the General Council of the Judiciary. Notably, JabaROOT's claims do not demonstrate any connection to Pegasus, nor do they allow for the attribution of that attack to Morocco. Such a relationship could only be considered if the files contain verifiable technical data, coherent dates, internal orders, or references that could be cross-checked with the National Court's proceedings.

Regarding Algeria, the threat arises in a context of diplomatic rupture and regional rivalry. Rabat and Algiers compete for influence in the Maghreb and hold opposing views on Western Sahara. This scenario has also fueled a digital war marked by groups claiming to be patriotic Moroccan or Algerian hackers.

JabaROOT also alleges that the documentation includes coordinated operations between Morocco and countries such as France, Israel, and the United States. This is one of the most serious aspects of the revelation and simultaneously one that necessitates caution. Morocco has established diplomatic, military, and security cooperation with these nations. Rabat resumed official contacts with Israel in 2020 through a declaration signed alongside the United States that included references to security cooperation. Morocco, France, and Israel also participate in international police cooperation mechanisms. However, the existence of these public alliances does not prove the conduct of clandestine joint operations nor does it confirm JabaROOT's narrative.

The mention of foreign countries or services within a database is insufficient on its own; the documents could simply reflect institutional contacts, intelligence analyses, surveillance objectives, or information gathered from open sources. The context of each file will be crucial.

JabaROOT, a group with a track record but an unclear identity, first emerged publicly in 2025 after claiming responsibility for the attack on the National Social Security Fund of Morocco (CNSS). The institution acknowledged it had suffered cyberattacks, with documents revealing employment and economic data of around two million individuals, although the CNSS itself warned that some of the information was inaccurate or incomplete. Subsequently, the group took responsibility for attacks on the Ministry of Justice and the Moroccan cadastre systems, but the affected institutions denied some of these intrusions or downplayed their extent. These contradictions necessitate a distinction between confirmed attacks, seemingly authentic leaks, and simple claims.

The identity of those operating under the name JabaROOT remains unclear. Subsequent investigations have noted the emergence of new channels that reused the same name following the closure of the original Telegram account. This precedent does not automatically invalidate the new threat, but it does require verification of the continuity of the channel, the digital signature of the files, and the technical relationship with previous attacks. In the world of hacktivism, it is common for different actors to reuse familiar names to amplify messages or claim responsibility for operations not their own.

As reported by estrelladigital.es.