In a striking development, a group identifying itself as Jabaroot has claimed to have accessed sensitive records pertaining to approximately 70,000 members of Morocco's intelligence and security services. This revelation has intensified scrutiny on the kingdom's surveillance capabilities, particularly in the wake of a tragic incident involving a mass border crossing at Ceuta. Analysts are now examining the potential ramifications of this data leak, which could have significant implications for both national security and international diplomatic relations.
On August 24, 2026, Jabaroot disseminated four spreadsheets via Telegram, purporting to contain personnel information from two major Moroccan security agencies: the DGSN (General Directorate of National Security) and the DGST (General Directorate of Territorial Surveillance). Spanish media reports suggest that the total entries exceed 70,000, with both agencies operating under the authority of Abdellatif Hammouchi, a figure known for his extensive control over Moroccan security operations. To date, no official government entity has confirmed the authenticity of the leaked files.
The contents of these spreadsheets are alarming, as they reportedly include crucial information such as service ID numbers, national identity numbers, bank account details, birth dates, and recruitment years. Notably, the data appears to merge personnel from both the DGSN and DGST, rather than maintaining a clear distinction between the two. Among the entries, significant positions such as regional directors and department heads involved in counterespionage and budget management are reportedly listed. Of particular interest is the inclusion of Hammouchi's birth date, which had not been publicly available, indicating that some of the data may not have been sourced from accessible information.
While the files appear to be outdated, with the most recent recruitment entries dating back to 2020 and at least one listed individual confirmed deceased, security analysts who have reviewed the documents believe the names to be genuine, albeit no longer current. Former officials from Moroccan intelligence have purportedly corroborated the legitimacy of the leaked material in private discussions.
Jabaroot has asserted that this leak represents only a small segment of a more extensive breach, referencing a prior release in April 2026 that allegedly drew from Morocco's public-sector health insurance database, which covers millions of state employees. Some reports suggest that the August leak may have originated from five former DGST members—four officers and a commissioner—currently living in exile in Europe.
The identity of the group Jabaroot has sparked considerable debate, with Moroccan officials hinting at possible Algerian involvement. However, European agencies have expressed skepticism regarding this claim, with cybersecurity experts tracing the alias back to a Tunisian engineer residing in Germany. This group has a history of data breaches, with a prior incident involving the leak of national social security data in April 2025.
Significantly, Jabaroot has branded this release as «#OP_CEUTA,» directly linking it to the tragic events of late July, when tens of thousands attempted to cross into Spain's Ceuta enclave, resulting in numerous fatalities. The group positions this leak as a message to Spain and Europe, alleging that Moroccan migration flows are orchestrated by state officials and claiming to possess internal orders indicating coordination by security personnel during the crossing. The Moroccan government has vehemently denied these allegations, attributing the situation to smuggling networks instead.
The timing of this political revelation poses a challenge for Madrid, which recently honored Hammouchi with a prestigious civil guard award shortly before discreetly suspending its investigation into the controversial Pegasus spyware for the second time. The lack of official comment from Morocco thus far has allowed Jabaroot's narrative to thrive, raising questions in European capitals about the implications of this data breach.
Analysts have identified two primary risks stemming from this situation. Firstly, if the data is indeed linked to insurance records rather than indicating a direct network breach, the technical damage to Morocco's intelligence infrastructure may be limited. Nonetheless, the existence of a list that associates names with ID numbers and recruitment years poses a significant counterintelligence risk, particularly as many individuals named in the documents are likely still active in their roles. The more pressing issue to monitor is whether Jabaroot can validate its claims of having documentary evidence connecting Moroccan officials to the orchestration of the Ceuta crossing; if this is substantiated, it could transition the narrative from a mere data breach to a full-blown diplomatic incident.
As reported by moroccomail.fr.