Morocco: Hacker Jabaroot returns with ultimatums regarding the Ceuta crisis

None of the claims — from Jabaroot's leak to the infiltration allegations to the social-media mobilization findings — constitute confirmed fact on their own. But their convergence has turned what began as a migration story into a broader test of Spanish-Moroccan relations, EU border sovereignty, and the accountability of intelligence services on both sides of the Strait of Gibraltar.

A hacking collective known as Jabaroot has issued one of its most consequential threats yet: the potential exposure of more than 70,000 members of Morocco’s internal security services, including operatives from the General Directorate for Territorial Surveillance (DGST) and the General Directorate of National Security (DGSN), the country’s police force. The group has tied the threat directly to Morocco’s alleged handling of the migration crisis at the Spanish enclave of Ceuta, where tens of thousands of people crossed the border in a matter of days in late July.

To establish credibility, Jabaroot published a sample batch of roughly twenty profiles on its Telegram channel, reportedly containing names, dates of birth, service entry dates, and internal notes belonging to DGST personnel. The group says the full dataset — covering both DGST and DGSN staff — is ready for release should its demands go unmet.

Who Is Jabaroot?

Jabaroot is not a new actor. The collective first surfaced in 2025 during a period of heightened tension between Morocco and Algeria, and has since built a track record of breaching Moroccan state institutions. Past operations attributed to the group include a breach of the Caisse Nationale de Sécurité Sociale (CNSS), Morocco’s national social security fund, which the institution itself confirmed, along with intrusions targeting the Ministry of Justice and the publication of financial details tied to the Royal Household.

Moroccan officials have suggested the group operates on behalf of Algeria, Morocco’s regional rival, though independent cybersecurity researchers say this attribution remains unconfirmed. At least one private intelligence firm has floated an alternative theory: that the operation is the work of a single former Moroccan security agent rather than a state-backed group. What analysts largely agree on is that the group’s previous leaks have generally proven authentic, even if some individual data points — such as certain CNSS records — were later disputed as inaccurate.

The Ceuta Connection

Jabaroot’s latest campaign is explicitly framed around the Ceuta crisis. According to the group, Morocco’s DGST — headed by Abdellatif Hammouchi, who also oversees the DGSN — orchestrated or manipulated the border surge as a pressure tactic against Spain. The collective has called on Moroccan intelligence personnel it says entered Ceuta to return home, warning that continued operations there would trigger further disclosures.

The group has also issued a broader list of political demands, including:

  • Official apologies and a national day of mourning for those who died or went missing during the crossing
  • Suspension of Morocco’s legislative elections, originally scheduled for September 23
  • An independent investigation into abuses committed against migrants, with accompanying sanctions
  • Structural reforms to Morocco’s judiciary and economy
  • A formal probe into an incident involving an officer allegedly assaulting an unarmed Moroccan national

Jabaroot says it intends to hand its evidence of what it calls an external espionage network to Spanish judicial authorities.

What Actually Happened at the Border

The scale of the Ceuta crossing is difficult to overstate. In late July, more than 70,000 people entered the enclave in a short span of time — a number comparable to the city’s own population of roughly 85,000. Spanish police unions say they issued repeated warnings to national authorities in the run-up to the crisis, flagging the risk of a mass crossing. Those warnings, according to reporting from Reuters, went unheeded.

Compounding the political sensitivity, Spanish security sources have suggested that individuals identified as Moroccan intelligence operatives may have crossed into Ceuta alongside migrants — a claim that, if substantiated, would shift the episode from an immigration matter into the realm of counter-espionage and national security. Spanish authorities have not yet publicly detailed how many alleged agents were identified, what units they belonged to, or what became of them.

A separate assessment, attributed to Spanish intelligence circles, offers a more measured read: rather than actively orchestrating the exodus, Morocco may have simply declined to stop it, allowing the crisis to build before leveraging it diplomatically. That distinction matters — but Spanish officials reportedly view both scenarios as warranting serious investigation, particularly since Morocco went on to demonstrate, within days, that it could rapidly curb crossings. Moroccan forces subsequently arrested several hundred people attempting to reach Ceuta, according to the Associated Press and Reuters.

A Digital Mobilization Campaign

Adding another dimension to the story, the private intelligence firm Golden Owl has reported identifying a large, decentralized network of social media accounts and Facebook groups that appear to have coordinated messaging encouraging the border crossing — reportedly using coded language designed to evade content moderation. Investigators stop short of tying this network directly to the Moroccan state, but the findings suggest the surge was not a purely spontaneous event.

The Pegasus Backdrop

The current allegations arrive against the backdrop of years of surveillance controversies involving Morocco. A July 2026 investigation by the journalism consortium Forbidden Stories alleged that Moroccan intelligence deployed Pegasus spyware against a senior Spanish Guardia Civil intelligence official — during a period when Spanish personnel were reportedly training their Moroccan counterparts — and that other Spanish personnel were also targeted. This follows the previously documented 2021 case in which Spanish Prime Minister Pedro Sánchez’s own phone was found to have been infected with Pegasus, an incident whose perpetrator was never conclusively established by Spanish judicial investigators.

Open Questions for Madrid and Brussels

Taken together, the episode raises questions that extend well beyond Jabaroot’s leak itself:

  • Why did Spanish authorities fail to act on repeated warnings ahead of the crossing?
  • Were Moroccan intelligence operatives genuinely present among the migrants, and if so, what happened to them?
  • Who organized the online mobilization that helped drive the surge?
  • Is Ceuta’s security effectively dependent on Rabat’s discretion rather than European control of its own external border?

None of the claims — from Jabaroot’s leak to the infiltration allegations to the social-media mobilization findings — constitute confirmed fact on their own. But their convergence has turned what began as a migration story into a broader test of Spanish-Moroccan relations, EU border sovereignty, and the accountability of intelligence services on both sides of the Strait of Gibraltar.

Visited 519 times, 1 visit(s) today

Soyez le premier à commenter

Laisser un commentaire

Votre adresse de messagerie ne sera pas publiée.


*