In January 2026, Spain's National Court took the unprecedented step of archiving the investigation into the infamous Pegasus espionage incident for a second time. This investigation focused on the hacking of phones belonging to prominent political figures, including Prime Minister Pedro Sánchez, Defense Minister Margarita Robles, and Interior Minister Fernando Grande-Marlaska. The General Council of the Judiciary attributed this decision to a notable lack of cooperation from Israel, the country that hosts the NSO Group, the developer of the controversial Pegasus software. Four years have passed since the Spanish government confirmed the hacking incident, yet the nation still lacks an official judicial attribution regarding who orchestrated this significant breach of its political leadership's privacy.

Despite these challenges, suspicions persist and have been consistently directed towards Morocco, bolstered by investigative journalism and findings from the European Parliament since 2022.

Confirmed Details of the Espionage

The Spanish government acknowledged in May 2022 that Sánchez and Robles' phones had been compromised by Pegasus, resulting in the extraction of approximately 2.6 gigabytes of data from the Prime Minister's device and nine megabytes from the Defense Minister's. Shortly thereafter, Grande-Marlaska's case was included in the investigation. The European Parliament has linked the hacking incidents involving Sánchez and Robles to a timeframe between May and June 2021, suggesting that these attacks likely originated from outside the European Union. A report published in 2022 pointed to Morocco as a potential suspect in the espionage targeting over two hundred Spanish phones, a claim that Morocco has firmly denied.

It is crucial to delineate the implications of these allegations: while there are substantial indications and credible journalistic inquiries suggesting Moroccan involvement, there is no judicial ruling or definitive attribution from Spanish authorities. This distinction is not merely technical; it differentiates between what is established as fact and what can be regarded as a well-founded suspicion. The gravity of the situation becomes clearer when considering that the real threat posed by a Pegasus infection on a head of state’s phone extends beyond the mere exposure of private conversations. It encompasses the potential for a foreign entity to reconstruct the decision-making processes surrounding sensitive bilateral matters, including issues related to Western Sahara, Ceuta, Melilla, and migration control in the Strait.

The JabaROOT Incident: A New Dimension

On August 12, the hacktivist group JabaROOT claimed to have infiltrated databases associated with Moroccan intelligence agencies, potentially the DGST (General Directorate of Territorial Surveillance) or the DGED (General Directorate of External Surveillance). They threatened to disclose documents detailing agents, collaborators, and, notably for Spain, alleged Moroccan espionage strategies against Spain and Algeria, as well as purported joint operations with France, Israel, and the United States. However, it is imperative to approach these claims with extreme caution. To date, there has been no official acknowledgment from Moroccan authorities regarding this breach, nor has there been independent verification of the files that JabaROOT asserts to possess. Furthermore, JabaROOT has a questionable history, having previously claimed responsibility for an attack on the Moroccan National Social Security Fund, which admitted to suffering cyberattacks but also cautioned that some leaked information was inaccurate or incomplete. Investigations have revealed that various channels have reused the name JabaROOT after the original Telegram account was shut down, a common tactic in hacktivism to amplify messages or falsely claim foreign operations.

While there are public connections between Morocco, France, Israel, and the United States—particularly following Morocco's reestablishment of official relations with Israel in 2020 through a joint declaration with Washington—this does not inherently substantiate claims of clandestine operations against Spain. Such connections could simply reflect institutional interactions or analyses based on open-source data. Without technical verification, the claims made by JabaROOT remain unsubstantiated.

In conclusion, while the cases of Pegasus and JabaROOT are distinct—one representing a partially confirmed governmental case and the other an unverified claim from a seemingly dubious group—they both highlight a broader theme: Spain's southern border has evolved into a digital battleground. The complexities of these incidents underscore a troubling reality; it is increasingly challenging to ascertain who is truly responsible for cyber threats. The real concern lies not solely in determining whether Morocco is conducting a campaign of confirmed cyberattacks against Spain, but in recognizing the proliferation of actors whose actions may remain ambiguous. Hacktivist groups and collectives often claim operations without providing verifiable proof, existing in a nebulous space between digital activism, state interests, and information manipulation. As the landscape of unverifiable attacks and leaks becomes normalized, it grows ever more difficult for governments—whether Spanish or Moroccan—to differentiate between genuine threats and disinformation campaigns designed to mislead.

As reported by escudodigital.com.