Investigation Uncovers Key Suspects in Document Leak

Recent investigations in Morocco have narrowed down the primary suspects in a significant security document leak to just four individuals. This leak involved the theft and subsequent dissemination of classified internal documents from Morocco's security services. Authorities believe these suspects may have fled to Russia to evade repercussions from the Moroccan government. The leaked files, disseminated by a group named Jabaroot, contain sensitive information regarding tens of thousands of employees associated with Morocco’s security structures. Additionally, sources familiar with the leaked documents have indicated that certain active members of the security services during the incidents that led to the massive influx of immigrants into Ceuta are implicated.

Investigators in Morocco have determined that the information in question was not obtained through an external cyberattack, but rather was likely stolen from within the agency itself. This conclusion is supported by the nature of the data, which comes from an intranet accessible only to a select few personnel. Authorities suspect that the motive behind the leak was purely financial, involving individuals who were once part of the service but have since retired.

Tracing the Origins of the Security Breach

The documents in question had been stored on an intranet that only authorized personnel could access. Investigators believe that an insider with legitimate access made unauthorized copies of the files, allowing them to be extracted from Morocco's systems. This investigation has led to a clearer understanding of who may have secured this sensitive information and the timeline of events surrounding the breach.

The analysis indicates that the documents used for the leak are approximately two years old, meaning they could have been outside the control of the Moroccan authorities for an extended period. This timeframe suggests that the information was available to be leaked long before it began circulating publicly, despite the continued operational activities of the Moroccan security services.

As investigations progressed, the number of potential suspects was significantly reduced by focusing on individuals who met two criteria: they had access to the intranet at the time of the breach and subsequently left their positions. This careful analysis has led to the identification of four primary suspects, while dismissing others who were initially considered.

Furthermore, there are concerns that these suspects may have left Morocco and are currently in Russia, thus placing themselves beyond the reach of Moroccan authorities and shielding themselves from possible reprisals. In contrast, seeking refuge in countries like Germany or Turkey would not afford them the same level of protection due to Morocco's stronger diplomatic presence there.

Although publicly labeled as hackers due to their involvement in the leak, the method by which these documents were acquired diverges significantly from conventional cyberattack strategies. The breach originated from within the Moroccan security structure itself.

The leaked documents are particularly significant for Spain, as they contain references that could help reconstruct actions taken by members of Morocco's security apparatus during the migratory crisis in Ceuta. The files predominantly affect personnel from the General Directorate of Territorial Surveillance (DGST), which is primarily responsible for internal intelligence and security in Morocco.

It is crucial to distinguish the leaked documents from a separate list that circulated online, which purportedly names Moroccan spies and collaborators in Spain. This second list, which emerged almost simultaneously with the initial leak, has caused confusion but does not originate from the same source as the Jabaroot documents. Sources who downloaded the Jabaroot files early on confirmed that this list of alleged collaborators was not part of the original documentation.

Moreover, the Jabaroot files do not contain specific sections dedicated to Spain or organized lists by country. The emergence of this second list has led to both sets of information being inaccurately presented as a singular leak, which is misleading.

It is essential to recognize that the external competencies of Morocco's intelligence services primarily fall under the General Directorate of Studies and Documentation (DGED), while the DGST is focused on internal security. Therefore, the sources consulted caution against automatically labeling individuals listed in the second document as agents of the DGST, as this lacks sufficient foundation.

As Morocco continues its efforts to ascertain who facilitated the leak and why it has come to light, the investigations have successfully narrowed the circle of suspects to four individuals. Meanwhile, the analysis of documents continues, posing a potential threat to expose some of the most sensitive actions undertaken by the services of King Mohammed VI.

As reported by okdiario.com.