Jabaroot: Behind the hacker group's claim of a 70,000‑name leak in Morocco's police and intelligence - Middle East Eye

Direct Source Verification: This story is aggregated from Middle East Eye (middleeasteye.net). Full reporting rights and copyright belong to the primary publisher.
Morocco suffered an alleged security breach on 24 August, when hacker collective Jabaroot claimed to have released 70,000 names from the country’s police and intelligence network stationed in Europe “and within strategic Moroccan institutions”. 

Morocco suffered an alleged security breach on 24 August, when hacker collective Jabaroot claimed to have released 70,000 names from the country’s police and intelligence network stationed in Europe “and within strategic Moroccan institutions”. 

Compiled in four spreadsheets, the list mostly consists of unknown individuals within Morocco’s General Directorate of National Security (DGSN), the national police, and the General Directorate of Territorial Surveillance (DGST), the domestic intelligence. It details personal information such as birth dates, bank account numbers and supposed professional ranking.

The list also names some high-ranking officials, including the head of the DGSN and DGST, Abdellatif Hammouchi.

Morocco denied the attack, saying the data came from old information obtained from databases operated by insurance companies.

Jabaroot, which means “power” or “domination” in Arabic, released the data on Telegram, calling it a “gift to Spain”, coming weeks after the migrant crisis in which 72,000 people crossed into the Spanish enclave of Ceuta from Morocco. 

According to Le Monde, while many suspect Jabaroot to be an Algerian group, the leak could actually be the work of five former DGST agents, living in exile in Europe. 

Currently, nothing proves that these 70,000 people are all Moroccan spies. Some files may concern police officers, administrative staff or civil servants with no clandestine activity.

Dr Bassant Hassib, assistant professor of political science in the University of London Programmes at the European Universities in Egypt (EUE), with expertise in cybersecurity, says Jabaroot’s announcement should be treated with caution.

There are several methods to assess and authenticate a leak, she told Middle East Eye, including checking whether the recruitment dates are plausible.

“This leak’s most recent hire date was reportedly 2020, suggesting outdated information. It is also necessary to check if the names on the list are intelligence/security agents or admin employees,” Hassib said. An indicator that the data is old is the mention of Abdelhak Khiame, the first director of the Central Bureau of Judicial Investigations, part of the DGST, who died in 2022.

MEE learned from a former Moroccan overseas intelligence officer that some of the names on the list are in fact correct. The anonymous source said that after partially going through the data, they identified at least one entire informant family whose details and job ranking were authentic. 

“Usually informants are placed within embassies; it is common practice for the entire family to be hired and moved to the country to reduce any suspicion within the family,” they said. 

“[The leak] will cause chaos within the system; all those named are now burnt contacts, and will need to return to Morocco,” the former intelligence agent said.

They added that the job of any foreign agent is purely to collect information: “We listen, and we pass it back; we are trained on how to do this.”  

With potentially hundreds or thousands of contacts “burned”, the intelligence source says previously deployed staff will probably be called back overseas to replace those implicated in the leak. 

Even if the data is only partially correct, the leak endangers the agents, Hassib said.

“It poses a physical safety risk to name individuals and their families, especially if they are covert personnel, given that their name and bank details are enough for targeting or harassment,” she said. 

Jabaroot can benefit from publishing data even if it is outdated or incorrect. The collective can claim it is the result of a new breach while reusing older data from previous attacks, Hassib explained. 

“This can inflate the appearance of ongoing access and capability, boosting its standing on their main operational platforms like Telegram and increasing its value and leverage for future attacks,” she said. 

This is not the first time Jabaroot has claimed a leak of sensitive information about Moroccan officials. 

In April 2025, the group breached the National Social Security Fund (CNSS) and reportedly leaked more than 54,000 files containing sensitive identity, employment and banking details, compromising the data of nearly two million people, including palace employees. 

Two months later, Jabaroot said it hacked the National Agency for Land Conservation (ANCFCC), leaking roughly 4 TB of data containing more than 10,000 property certificates and 20,000 civil records files.

Another alleged breach came days later, when Jabaroot said it had compromised the justice ministry’s digital infrastructure and exfiltrated sensitive personal records belonging to roughly 40,000 judicial officials and magistrates.

The Moroccan authorities denied every leak. 

In the CNSS hack, those who claimed responsibility initially presented themselves as “Algerian patriots”, though it is impossible to say for certain whether these were the same individuals as in the latest leak.

The claim that Jabaroot is Algerian is commonly supported by Morocco’s “propaganda apparatus” as investigative journalist Jose Bautista, with extensive knowledge of the topic, told MEE. 

The association with Algeria is “politically useful”, said Alec Barcenilla, a researcher specialised in North Africa geopolitics, who has worked at the Spanish embassy in Rabat.

Morocco and Algeria have a long-standing rivalry that centres on the disputed territory of Western Sahara, where Algiers backs the pro-independence Polisario Front against Morocco's claims of sovereignty.

Both countries have come under cyberattacks. In 2025, the X account of the Algerian state news agency APS was compromised and renamed “Moroccan Sahara” to target Algiers's stance on the disputed territory. The hackers are suspected to be Moroccan.

For Morocco, it is beneficial if Jabaroot is known as Algerian because “it may then instrumentalise these digital attacks to shift blame and public focus away, in a rather opportunistic way”, Barcenilla said. 

The reality, however, is there is very little known about Jabaroot.

“There is no solid evidence on who they are, where they get their information from, and what the objectives are,” Bautista said. 

“What does seem clear is that whoever is behind Jabaroot holds highly professional profile(s), significant technical capabilities, and they have access to super sensitive data,” he added, saying that his sources believe that the latest leak could be a result of a hack of the Moroccan finance ministry or social security databases.

The journalist outlined that there are plausible theories about the collective, which he said come from reputable media outlets and those with extensive knowledge, yet no hard evidence exists.

Many of Bautista’s sources believe several people are behind Jabaroot, rather than a single person. He cited the theory published in Le Monde that Jabaroot could be a group of Moroccan hackers angry about corruption, nepotism and problems within the Moroccan establishment. 

On the other hand, Bautista noted that other well-informed people have pointed the finger at Algerian and even Spanish intelligence as a kind of revenge against Morocco.  

Bautista formed part of a network of journalists who produced, on 16 July, an investigation on Morocco’s use of Pegasus, an Israeli spy software.

In July 2021, the Pegasus Project - an international investigation by Forbidden Stories and Amnesty International - accused Rabat of targeting more than 10,000 phone numbers with NSO Group’s spyware.

These hacks affected Moroccan journalists and dissidents, but also senior foreign officials, including French President Emmanuel Macron, Belgian Prime Minister Charles Michel and Algerian Chief of Staff Said Chengriha.

Although Moroccan authorities have consistently denied the accusations, new waves of technical evidence have continued to emerge over the years - including in July, following revelations from an intelligence‑service whistleblower.

The 2026 report directly links the DGST to high-level international spying, including the targeting of top Spanish cabinet ministers and Guardia Civil officers. It also reveals that Morocco’s surveillance programme began as early as September 2017 with internal system testing before rapidly expanding beyond its borders.

Bautista noted that Jabaroot has claimed to have information about how Morocco uses Pegasus and has threatened to reveal it, “including how Rabat spied on Spanish PM Pedro Sanchez”.

Yet again there is nothing concrete to support its claims, Bautista said, noting that Jabaroot has not always followed through on threats in the past.

In the new release, dubbed “OpCeuta”, Jabaroot has also threatened to publish "agent mission orders" allegedly proving the collusion of Moroccan security and intelligence services in organising the mass departures to Ceuta, which resulted in 141 deaths. 

An investigation has been opened in Spain after a police report described Moroccan law enforcement as broadly permissive and even facilitating the mass crossing. Rabat has denied any involvement.

Jabaroot, meanwhile, has not yet followed through on this threat.

Professor Hassib called Jabaroot’s framing “a way to embarrass Rabat and reinforce a narrative of Moroccan state involvement in the Ceuta crisis, thereby undermining its credibility”, especially with Morocco's elections approaching, on 23 September.

She believes the latest leak, which comes at a critical time, aims “to cause internal disruption, psychological impact, reputational damage and political leverage”. 

Reflecting on his discussions with both Moroccan and Spanish intelligence, Bautista said that what happened in Ceuta “must be understood in the context of hidden fights between Moroccan and Spanish intelligence, and in relation to what we published in the Pegasus report”.

“Moroccan intelligence did not like what we reported [about Pegasus]; they thought that Spain was somehow behind the access that we had to sensitive Moroccan intelligence officers,” he said.

Hammouchi, who became head of the DGST in 2005 and then DGSN in 2015, is a key target of the latest leak. Amid the release, Jabaroot said the “king must act and dismiss Hammouchi”. 

Hammouchi, described in the press as King Mohammed VI's “supercop”, has faced repeated complaints from human rights groups, including Amnesty International and Action by Christians for the Abolition of Torture, regarding alleged torture and secret detention practices at DGST sites.

In 2014, a French judge issued a warrant to question him while he was visiting Paris, triggering a major diplomatic rift between France and Morocco.

According to Le Monde, the five former DGST agents allegedly behind the leak say they have witnessed the misuse of personal information gathered via wiretaps and background checks.

Barah Mikail, an associate professor of political science and international relations at Saint Louis University in Madrid, called the leak undoubtedly “embarrassing for Hammouchi and the institutions that he leads”. 

Yet, there is no actual evidence that his position within the palace has been seriously weakened, he added.  

The more important issue, Mikail said, is internal loyalty.

“If the reporting that former DGST officers are involved is accurate, that would point to a problem of defection and grievance within the apparatus.”

Researcher Barcenilla said Hammouchi’s national and international “brand” is that of control, anticipation and reliability. “Jabaroot’s attack is therefore also an attack on his capacity and reliability.” 

If the data is real, he added, it could cause reputational and political damage for Hammouchi. 

Mikail sees the fact that some of the published data has been proven to be outdated as an indication that it “may be substantially authentic, but without necessarily having resulted from a recent intrusion into the security services’ own systems”. 

So far, Morocco has been clear in its stance against the leak’s validity. This denial has a damage-control function, Mikail noted. “But this does not necessarily mean the data is false,” he said. 

Original Source
https://www.middleeasteye.net/news/jabaroot-behind-hacker-group-claim-70000%E2%80%91name-leak-Morocco-police-intelligence
Visit Middle East Eye ↗
SHARE STORY:
𝕏 f in

Related Coverage in Politics