On August 24, Morocco experienced a significant alleged security breach when the hacker group known as Jabaroot claimed to have released personal information of 70,000 individuals associated with the country's police and intelligence agencies stationed in Europe, as well as within key Moroccan institutions. The leaked data, organized into four spreadsheets, primarily includes details about lesser-known members of Morocco's General Directorate of National Security (DGSN) and the General Directorate of Territorial Surveillance (DGST). This sensitive information encompasses personal identifiers such as birth dates, bank account numbers, and purported job ranks, raising concerns about the security and privacy of those implicated. Notably, the leak also names high-ranking officials, including Abdellatif Hammouchi, the head of both the DGSN and DGST.
In response to the breach, Moroccan authorities have denied the authenticity of the data, asserting that it originates from outdated information collected from insurance company databases. Jabaroot, whose name translates to 'power' or 'domination' in Arabic, disseminated this information via Telegram, framing it as a 'gift to Spain.' This declaration comes in the aftermath of a migrant crisis where approximately 72,000 individuals crossed into the Spanish enclave of Ceuta from Morocco, heightening regional tensions.
According to reports from Le Monde, speculation surrounds Jabaroot's origins, with many suspecting it to be an Algerian collective. However, there are suggestions that the leak may be the result of actions taken by five former DGST agents currently in exile in Europe. While the leaked files may include a mix of individuals, it remains unclear whether all those named are indeed spies or if they are merely administrative staff or civil servants lacking any covert activities.
Dr. Bassant Hassib, an assistant professor of political science with a specialization in cybersecurity, advises caution regarding Jabaroot's claims. She highlights the importance of assessing the validity of such leaks through various methods, including checking the recruitment dates for plausibility. The most recent hiring date documented in the leak is from 2020, suggesting that much of the information may be outdated. Additionally, a notable entry includes Abdelhak Khiame, the first director of the Central Bureau of Judicial Investigations, who passed away in 2022, indicating the data's potential obsolescence.
Insights from a former Moroccan intelligence officer reveal that some of the names on the leaked list are indeed accurate. According to this anonymous source, after reviewing portions of the data, they were able to identify a complete informant family whose details and employment ranks were verified. This poses a significant threat to the integrity of the intelligence network, as the exposure of such contacts could lead to chaos within the system. The former agent noted that individuals identified in the leak would likely need to return to Morocco to avoid further complications.
The implications of this data breach are dire, especially considering the potential risks to the physical safety of those named, as their identities and financial details could make them targets for harassment or retaliation. Even if the data is partially inaccurate, its mere existence threatens those involved, as highlighted by Dr. Hassib's analysis on the situation.
Jabaroot's actions are not without precedent; the group has claimed responsibility for previous leaks targeting sensitive Moroccan government data. In April 2025, they allegedly hacked the National Social Security Fund, leaking over 54,000 files containing critical identity, employment, and banking details. Beyond this, they also targeted various other government entities, showing a pattern of digital assaults against Moroccan institutions. Each time, the Moroccan government has denied these claims, maintaining that the data is either fabricated or outdated.
Furthermore, the geopolitical context complicates matters, with long-standing tensions between Morocco and Algeria influencing narrative framing. Allegations of Jabaroot being an Algerian group serve as a strategic tool for Morocco, potentially diverting public scrutiny away from domestic issues. As investigative journalist Jose Bautista points out, the true identity and motives behind Jabaroot remain largely speculative, with theories ranging from disgruntled Moroccan hackers to foreign intelligence agencies seeking to undermine the Moroccan state.
In light of these events, the potential for Jabaroot to leverage future attacks or threats looms large, particularly as they have hinted at possessing information regarding Morocco's use of sophisticated surveillance technologies like Pegasus. The group has threatened to disclose details that could expose Moroccan intelligence's activities in connection with recent migrant crises, further complicating the political landscape as Morocco approaches its upcoming elections on September 23.
In summary, the Jabaroot data leak not only raises urgent questions about the security of Moroccan intelligence personnel but also reflects broader geopolitical tensions in the region. As the situation unfolds, the implications for both domestic stability and international relations remain to be seen.
As reported by middleeasteye.net.