In January 2026, Spain's National Court dismissed the investigation into the alleged espionage involving the use of Pegasus software against the phones of key political figures, including Prime Minister Pedro Sánchez, Defense Minister Margarita Robles, and Interior Minister Fernando Grande-Marlaska, for the second time. The reason for this dismissal, as reported by the General Council of the Judiciary, was the lack of cooperation from Israel, the home of NSO Group, the company behind the software. Four years after the government confirmed the infection, Spain still lacks an official judicial attribution regarding who was behind this significant case of political phone surveillance in a democratic context.
Despite this, suspicions, bolstered by journalistic investigations and support from the European Parliament, have consistently pointed towards Morocco since 2022. The Spanish government confirmed in May 2022 that the phones of Sánchez and Robles had been infected with Pegasus, resulting in the extraction of 2.6 gigabytes of data from the president's device and nine megabytes from the defense minister's. Shortly thereafter, Grande-Marlaska's case was added to the list. The European Parliament placed the attacks on Sánchez and Robles between May and June 2021, suggesting they originated from outside the European Union. A 2022 report identified Morocco as a potential culprit responsible for spying on over two hundred Spanish phones. Morocco, however, has firmly denied any involvement.
It is crucial to clarify what this all means: there is substantial evidence, credible journalistic investigations, and a mention by the European Parliament, but there is no judicial ruling or definitive official attribution from Spanish authorities. This distinction is not just a minor technicality; it underscores the difference between what can be stated as fact and what can only be indicated as a founded suspicion. The undeniable severity of the risk this case exposes is concerning. The real danger of a Pegasus infection on a head of government’s phone extends beyond the exposure of private conversations; it lies in the potential for a foreign power to reconstruct how state decisions are made on sensitive matters such as Western Sahara, Ceuta, Melilla, or migration control in the Strait of Gibraltar.
The Latest Episode: JabaROOT
On August 12, the hacktivist group known as JabaROOT claimed to have accessed databases linked to Moroccan intelligence services, potentially the DGST, responsible for internal security, or the DGED, responsible for external espionage. They threatened to disclose documentation concerning agents, collaborators, and, particularly sensitive for Spain, alleged Moroccan espionage plans against Spain and Algeria, as well as supposed joint operations with France, Israel, and the United States. The group has since begun to release this information.
Here, caution must be exercised to the utmost degree. It is important to state clearly that, as of today, there is no official Moroccan confirmation of the intrusion, nor is there independent technical verification of the files that JabaROOT claims to possess. The group also has a history that invites skepticism; they claimed responsibility for a 2025 attack on the Moroccan National Social Security Fund, which acknowledged suffering cyberattacks but warned that some of the leaked information was inaccurate or incomplete. Subsequent investigations have revealed that various channels have reused the name JabaROOT after the closure of its original Telegram account, a common practice in hacktivism to amplify messages or claim responsibility for others' operations.
The existence of public connections between Morocco, France, Israel, and the United States (Rabat restored official relations with Israel in 2020 through a joint declaration with Washington) does not, by itself, prove the existence of clandestine joint operations against Spain. They could merely represent institutional contacts or open-source analysis within a database. Without technical verification, JabaROOT remains a claim rather than a confirmed fact.
Connecting the Dots
While Pegasus and JabaROOT are not the same story, conflating them would be a significant error. One is a case with partial government confirmation and an actual legal investigation, albeit archived without attribution. The other is, for now, an unverified assertion from a group of uncertain identity. However, both episodes, set against the backdrop of a bilateral relationship marked by recurrent tensions over Western Sahara, Ceuta, Melilla, and the migration crisis, suggest a broader issue that transcends either individual case: Spain's southern border has also become a digital front, and within this arena, it is increasingly difficult to ascertain who is attacking whom.
This probably represents the real risk that we should take away from this situation; it is not that Morocco, as a state, is launching direct and confirmed cyberattacks against Spain, something that neither of the two sources permits us to assert with the certainty sometimes attributed to certain headlines. Instead, the risk lies in the proliferation of actors with uncertain attribution: hacktivist groups, collectives claiming operations without the ability to substantiate them, recycled and reused names operating in the gray area between digital activism, state interests, and information manipulation. As this ecosystem of unverifiable attacks and leaks becomes more normalized, it becomes increasingly challenging for any government—be it Spanish or Moroccan—to distinguish a real threat from a disinformation operation designed to appear as such. This, and not the attribution of a specific attack, is what Spain should be monitoring with more attention than it has so far demonstrated.
As reported by escudodigital.com.