Morocco’s Jabaroot Hack Sparks Alarm After Reported Leak of 70,000 Security Personnel Records
Morocco is facing renewed questions about
cybersecurity, intelligence secrecy and the protection of sensitive government
information after the hacker group known as Jabaroot reportedly released
data linked to approximately 70,000 members of the country’s security and
intelligence services.
The alleged leak, which surfaced through Telegram,
has become one of the most significant cybersecurity controversies to affect
Morocco in recent years. However, an important question remains unresolved: how
much of the leaked information is authentic, current, and accurately attributed?
According to reporting by Le Monde, the files reportedly contain
information associated with personnel from Morocco's security institutions,
including the General Directorate of National Security and the General
Directorate of Territorial Surveillance. The newspaper noted that the
authenticity of the complete dataset could not be independently established.
The development follows earlier threats and claims
attributed to Jabaroot, which had connected its campaign to wider political and
security tensions surrounding the recent crisis involving the Spanish enclave
of Ceuta.
What Did Jabaroot Reportedly
Release?
The reported data dump consists of several
spreadsheets containing names and other personal or professional details of
individuals allegedly connected to Morocco's security structure.
According to Le Monde, the information reportedly
includes identification details, employment information and, in some cases,
highly sensitive personal data. Senior officials were also said to appear in
the material alongside ordinary personnel and administrative staff.
However, cybersecurity incidents involving leaked
databases require careful verification.
The presence of a person's name in a leaked file
does not automatically prove that the individual is an intelligence operative.
Some of the records may relate to police officers, administrators or other
public employees. Questions have also been raised about the age of the data,
with some employment records reportedly appearing to date back several years.
That distinction is critical because early
descriptions of the incident suggested that tens of thousands of
"spies" had been exposed. Available reporting does not support such a
definitive conclusion.
Jabaroot’s Earlier Threats
Against Morocco’s Security Apparatus
Before the reported mass release, Jabaroot had
already issued threats involving Morocco's security institutions.
An August 20 report by Maghreb Online said the group claimed to possess
files relating to personnel connected to the DGST and DGSN. The hackers
reportedly released a small sample of alleged personnel records while
threatening a larger disclosure.
The same report said Jabaroot attached political
demands to its campaign, including calls for investigations and institutional
reforms connected to the aftermath of the Ceuta migration crisis.
These claims should nevertheless be treated with
caution. The report itself acknowledged that the documents and allegations
required independent verification and that there was no definitive proof
establishing that the Moroccan government had deliberately orchestrated events
surrounding Ceuta.
The Ceuta Crisis Adds a Political
Dimension
The Jabaroot controversy is not unfolding in
isolation.
It has emerged against the backdrop of heightened
tension between Morocco and Spain following the large-scale movement of
migrants toward Ceuta. The crisis generated political debate, security concerns
and renewed scrutiny of how Morocco and Spain manage their shared border.
Jabaroot reportedly attempted to link its cyber
campaign to the Ceuta episode, making allegations concerning Morocco's security
establishment and threatening to disclose additional documents.
However, allegations concerning the involvement of
security agencies in organising or facilitating the migration crisis remain unproven,
based on the information currently available.
Le Monde reported that the hackers also threatened
to release documents they claimed could demonstrate links between Moroccan
security institutions and the events surrounding the mass movements toward
Ceuta. As of the publication of the report, those additional claims had not
been independently substantiated.
Why Did the Jabaroot Telegram
Channel Disappear?
Another twist emerged on August 21 when Maghreb
Online reported that a Telegram channel associated with Jabaroot had
disappeared shortly after the group issued threats concerning Moroccan security
personnel.
The group had allegedly claimed to possess
extensive databases containing names, identification information and other
personnel details associated with the DGST and DGSN.
The disappearance of the channel created
uncertainty over whether the campaign had ended, whether the group had moved to
another platform or whether further disclosures would follow.
The subsequent publication of a much larger
dataset, as reported by Le Monde on August 26, suggests that the controversy
was far from over.
Who Are the DGST and DGSN?
The alleged leak primarily concerns two major
institutions within Morocco's security structure:
DGST - The Direction
Générale de la Surveillance du Territoire (DGST) is generally associated
with domestic intelligence, counterterrorism, and counterintelligence
activities.
DGSN - The Direction
Générale de la Sûreté Nationale (DGSN) is Morocco's national security and
policing organisation.
Both institutions are led by Abdellatif
Hammouchi, a prominent figure within Morocco's security establishment.
Because the reported files allegedly combine
personnel from different institutions, analysts have warned against
automatically describing everyone listed as an intelligence agent.
A History of Cybersecurity
Incidents Linked to Jabaroot
Jabaroot has become a notable name in discussions
about Moroccan cybersecurity since emerging publicly in 2025.
The group has previously claimed responsibility for
attacks involving Moroccan institutions and databases. Earlier incidents
reportedly included the exposure of information connected to Morocco's social
security system, as well as claims involving the Ministry of Justice and other
sensitive institutions.
According to Maghreb Online, Jabaroot built much of
its reputation through a series of alleged cyberattacks and data disclosures
beginning in 2025.
Le Monde similarly reported that previous leaks
associated with the group involved millions of social security records and
other sensitive information.
Nevertheless, previous leaks do not automatically
authenticate every new claim. Each dataset must be independently examined.
Could the 70,000 Records Be Authentic?
This is the central question.
Le Monde reported that the nature of the
information contained in the files could indicate that the material originated
from an internal administrative system or payroll-related database. At the same
time, there were signs that some of the information might be outdated,
including references to individuals who had died and employment records that
did not appear to include recent recruits.
That means several possibilities remain open:
- The
data could be substantially authentic but old.
- The
files could contain authentic records mixed with inaccurate or manipulated
information.
- Some
entries may belong to personnel who are not intelligence officers.
- The
origin of the dataset may differ from the claims made by those who
released it.
Until Moroccan authorities, independent
cybersecurity specialists, or other credible investigators authenticate the
material, definitive conclusions would be premature.
The Wider Cybersecurity Risk for
Morocco
Regardless of the final authentication outcome, the
incident highlights the enormous risks associated with government databases
containing sensitive personal information.
A breach involving security personnel can create
multiple dangers, including:
- Identity
theft and fraud.
- Exposure
of personal and financial information.
- Risks
to active or former security personnel.
- Counterintelligence
concerns.
- Blackmail
or social engineering threats.
- Diplomatic
and political consequences.
- Loss
of public confidence in government cybersecurity.
The case also demonstrates why government
institutions must treat data protection, access controls, encryption,
segmentation, and incident response as national security priorities rather
than merely technical issues.
Morocco’s Silence and the Need
for Verification
At the time of Le Monde's report, the Moroccan
institutions named in connection with the alleged leak had not publicly
provided a detailed response addressing the authenticity or scope of the files.
In politically sensitive cyber incidents, official
silence can create an information vacuum that is quickly filled with
speculation.
A credible response would ideally address several
questions:
- Was
a government system breached?
- Are
the leaked records authentic?
- How
recent is the data?
- Which
institutions were affected?
- Are
current personnel at risk?
- Have
affected individuals been notified?
- What
cybersecurity measures are being taken?
Until those questions are answered, many claims
surrounding the Jabaroot leak will remain allegations rather than established
facts.
The Bigger Picture:
Cybersecurity, Intelligence and Morocco-Spain Relations
The Jabaroot controversy sits at the intersection
of several sensitive issues.
It involves cybersecurity, intelligence operations,
personal data protection, migration, and already delicate relations between
Morocco and Spain.
The Ceuta crisis has intensified speculation about
the role of security institutions and the broader geopolitical relationship
between Rabat and Madrid. At the same time, allegations involving surveillance
technologies and intelligence activities have added further complexity to the debate.
But separating verified facts from political
accusations will be essential.
As Maghreb Online itself noted, allegations about
deliberate state involvement in the Ceuta crisis require evidence and
transparent investigation before they can be treated as established facts.
Conclusion
The reported Jabaroot leak of information linked to
around 70,000 Moroccan security and intelligence personnel represents a
potentially serious cybersecurity and national security development.
If the material is authenticated, it could rank
among the most significant known exposures of sensitive Moroccan government
personnel data. However, the available evidence also requires caution.
Not everyone named in the files can automatically
be described as an intelligence operative; the age and completeness of the data
remain uncertain, and some of the wider allegations surrounding the Ceuta
crisis have not been independently proven.
For now, the Jabaroot controversy remains a
developing story involving a mixture of reported data leaks, political
accusations, cybersecurity concerns and unresolved questions about authenticity.
The next major development will likely depend on
whether Moroccan authorities, independent cybersecurity experts, or
investigative journalists can conclusively verify the origin and accuracy of
the alleged 70,000-person dataset.
Frequently Asked Questions
What is Jabaroot?
Jabaroot is a hacker group that has claimed
responsibility for several cyberattacks and data leaks involving Moroccan
institutions since 2025. Its identity and composition have been the subject of
competing claims and speculation.
Did Jabaroot expose 70,000
Moroccan spies?
Not necessarily. Reports describe approximately
70,000 names linked to Moroccan security and intelligence institutions, but
experts have warned that the files may include police officers, administrative
personnel, and other employees rather than exclusively intelligence agents.
Has the leaked data been
independently verified?
The authenticity of the complete dataset has not
been conclusively established. Reporting has identified indications that some
information may originate from internal administrative systems, but questions
remain about its accuracy, completeness and age.
Is the Jabaroot leak connected to
the Ceuta crisis?
Jabaroot has publicly linked its campaign to
allegations surrounding the Ceuta migration crisis. However, claims that
Moroccan authorities deliberately orchestrated the events remain unproven based
on the information currently available.
Why is the alleged leak
important?
A confirmed breach involving thousands of security
personnel could create serious risks involving privacy, personal security,
counterintelligence, fraud, and national cybersecurity.
Author: BROKEN NEWS Editorial Team
Publication Date: August 26, 2026

0 Comments