A group calling itself Jabaroot says it has obtained records on roughly 70,000 members of Morocco’s security and intelligence services, reigniting scrutiny of the kingdom’s surveillance apparatus just weeks after a deadly border crossing at Ceuta.
What Happened
On August 24, Jabaroot posted four spreadsheets to Telegram containing what it describes as personnel data from two of Morocco’s most powerful security bodies: the DGSN (national police) and the DGST (domestic intelligence and counterterrorism). Spanish media have pegged the total at just over 70,000 individual entries. Both agencies answer to Abdellatif Hammouchi, who holds an unusually broad concentration of security authority in the country. No government body has verified the files’ authenticity.
Inside the Files
The spreadsheets reportedly include service ID numbers, national identity numbers, bank account details, birth dates, and recruitment dates, with DGSN and DGST staff mixed together rather than kept separate. Entries reportedly include regional directors and department heads tied to counterespionage work and budget oversight. Notably, Hammouchi’s own birth date — not previously public — appears in the data, suggesting at least part of it wasn’t scraped from open sources.
The files appear dated: the newest recruitment entries are from 2020, and at least one listed individual has since died. Even so, outside security analysts who reviewed the material reportedly consider the names authentic, if outdated — and former Moroccan intelligence officials are said to have privately confirmed its legitimacy.
Who’s Behind It — and Why Now
Jabaroot claims this is only a fraction of a much deeper intrusion, and points to an earlier release, in April 2026, allegedly drawn from Morocco’s public-sector health insurance fund covering millions of state employees. Some reporting suggests the August leak actually originated with five former DGST insiders — four officers and a commissioner — now in exile in Europe.
The identity of « Jabaroot » itself is contested. Moroccan officials have suggested Algerian involvement; European agencies reportedly disagree, and cybersecurity researchers have instead linked the alias to an engineer of Tunisian background based in Germany. The group has a track record here, having previously leaked national social security data in April 2025.
The Ceuta Angle
Jabaroot has branded this release « #OP_CEUTA, » explicitly tying it to the late-July mass border crossing into the Spanish enclave of Ceuta, in which tens of thousands crossed and dozens died. The group frames the leak as a message to Spain and Europe, alleging that Moroccan migration flows toward Europe are state-directed, and claims to hold internal mission orders showing security officials coordinated the crossing. Morocco denies encouraging the crossings, blaming smuggling networks instead.
Why It Matters
The political timing is uncomfortable for Madrid, which honored Hammouchi with a top civil-guard decoration only months before quietly shelving its Pegasus spyware investigation for the second time. Morocco’s official silence so far has left Jabaroot’s narrative largely unanswered in European capitals.
Analysts note two separate risks here. If the data really does trace back to insurance records rather than a live network breach, the technical damage to Morocco’s intelligence infrastructure may be limited. But a roster linking names to ID numbers and recruitment years is still a counterintelligence liability — most of the officers named are likely still active. The bigger story to watch is whether Jabaroot can substantiate its claim of documentary proof tying Moroccan officials to orchestrating the Ceuta crossing; if so, this shifts from a data breach story to a diplomatic one.
This post is based on reporting from Le Monde, La Razón, El Mundo, El Confidencial, Ara, Escudo Digital, Resecurity, and The North Africa Journal.
#Jabaroot #Ceuta #Morocco #hackers #DGSN #DGST #El_Hammouchi
Soyez le premier à commenter