On August 24, a little-known hacking collective calling itself Jabaroot – a term meaning “power” or “domination” in Arabic – dropped a bombshell: it publicly released a dataset purporting to contain the personal information of 70,000 personnel linked to Morocco’s police and intelligence networks across Europe and inside key domestic Moroccan government institutions.
Packaged across four spreadsheets, the leak includes sensitive personal details ranging from birth dates and active bank account numbers to purported professional ranks. Most entries correspond to low-profile personnel within the General Directorate of National Security (DGSN, Morocco’s national police force) and the General Directorate of Territorial Surveillance (DGST, the country’s domestic intelligence agency), but the list also names top senior officials – including Abdellatif Hammouchi, who leads both the DGSN and DGST.
Moroccan authorities have pushed back hard against the claims, arguing that all information released originated from outdated datasets held by private insurance companies, not a recent breach of internal security systems.
Jabaroot framed the release as a “gift to Spain”, dropping it just weeks after a major migrant crisis that saw more than 72,000 people cross from Morocco into the Spanish enclave of Ceuta, an incident that left 141 people dead. The collective has also threatened to publish classified mission orders it claims prove Moroccan security services colluded to organize the mass crossing, an accusation Rabat has repeatedly denied. Spanish authorities opened an investigation into the crisis after a police report alleged Moroccan law enforcement allowed and even facilitated the crossing.
The true origins of Jabaroot and the leak itself remain shrouded in mystery. While many observers have speculated the group is Algerian-based, drawing on long-standing bilateral tensions between Algiers and Rabat, reporting from French outlet Le Monde suggests the breach may instead be the work of five former DGST agents living in exile in Europe. To date, there is no conclusive evidence confirming all 70,000 people listed are active Moroccan covert spies; the dataset is thought to include regular police officers, administrative staff and non-clandestine civil servants alongside any intelligence personnel.
Cybersecurity and regional politics experts warn the leak should be interpreted with significant caution. Dr. Bassant Hassib, an assistant professor of political science specializing in cybersecurity at the European Universities in Egypt’s University of London Programmes, notes multiple red flags indicating the data is largely outdated: the most recent recruitment date listed is 2020, and the dataset includes the name of Abdelhak Khiame, the founding director of the DGST’s Central Bureau of Judicial Investigations, who passed away in 2022.
Even so, the leak carries tangible risks. A former anonymous Moroccan overseas intelligence officer confirmed to Middle East Eye that at least some of the information is authentic, including the full details of an entire informant family deployed abroad. “Usually informants are placed within embassies; it is common practice for the entire family to be hired and moved to the country to reduce any suspicion,” the source explained. The leak has already rendered all named contacts compromised, the former officer added, saying it “will cause chaos within the system; all those named are now burnt contacts, and will need to return to Morocco.” Hundreds or thousands of deployed agents will likely need to be replaced by recalled personnel.
Hassib echoed this risk, noting that even partially accurate data poses direct physical danger to covert personnel and their families, whose exposed bank details and identities make them vulnerable to targeting and harassment. She added that Jabaroot stands to gain strategically even from releasing outdated or incomplete data: by framing old stolen information as the product of a new breach, the group can inflate its perceived technical capabilities, boost its standing on platforms like Telegram, and increase its leverage for future cyber operations.
This latest leak is far from Jabaroot’s first claimed attack on Moroccan state institutions. In April 2025, the group claimed responsibility for a breach of Morocco’s National Social Security Fund (CNSS), leaking 54,000 files that compromised the personal data of nearly two million people, including employees of the Moroccan royal palace. Two months later, it announced a hack of the National Agency for Land Conservation, leaking 4 terabytes of data including 10,000 property certificates and 20,000 civil records. Days after that, it claimed to have compromised the digital infrastructure of Morocco’s justice ministry, exfiltrating sensitive personal data from 40,000 judicial officials and magistrates. Moroccan authorities have denied every one of these alleged breaches.
Geopolitical analysts say the persistent narrative that Jabaroot is an Algerian-aligned group serves political goals for both Rabat and its critics. Morocco and Algeria have a decades-long bitter rivalry centered on sovereignty claims over the disputed territory of Western Sahara, where Algiers supports the pro-independence Polisario Front. Alec Barcenilla, a North Africa geopolitics researcher and former staffer at the Spanish embassy in Rabat, notes that labeling Jabaroot as Algerian is politically useful for Morocco: “it may then instrumentalise these digital attacks to shift blame and public focus away, in a rather opportunistic way.”
Despite widespread speculation, no solid concrete evidence exists to confirm Jabaroot’s identity, leadership or core objectives. Investigative journalist Jose Bautista, who has extensive expertise on North African cyber operations, told MEE that one clear throughline has emerged: “What does seem clear is that whoever is behind Jabaroot holds highly professional profiles, significant technical capabilities, and they have access to super sensitive data.” Bautista’s sources suggest the latest leak likely draws on data obtained from a breach of either the Moroccan finance ministry or social security databases, not the internal systems of the security services themselves. Multiple credible theories exist about the group: Le Monde’s reporting suggests it could be a collective of ex-Moroccan intelligence officers angry about corruption, nepotism and institutional abuse within the Moroccan establishment, while other well-informed sources have pointed to possible backing from Algerian or even Spanish intelligence as retaliation against Rabat.
The leak also intersects with ongoing international scrutiny of Morocco’s use of Pegasus, the controversial Israeli-made spyware. Bautista was part of an international journalistic investigation published in July 2026 that linked the DGST to a wide-ranging international surveillance program that targeted senior Spanish cabinet ministers and Guardia Civil officers. The report confirmed that Morocco’s surveillance operations began internal testing as early as September 2017 before expanding rapidly across borders. Jabaroot has claimed it holds sensitive data about Morocco’s use of Pegasus, including proof of surveillance targeting Spanish Prime Minister Pedro Sanchez, and has threatened to release it – though the group has yet to follow through on this threat, just as it has not delivered on its promise to release documents detailing alleged Moroccan collusion in the Ceuta migrant crisis.
Experts note the timing of the latest leak, which comes weeks before Morocco’s national elections scheduled for September 23, is no coincidence. Hassib argues that Jabaroot’s public framing of the leak is designed to “embarrass Rabat and reinforce a narrative of Moroccan state involvement in the Ceuta crisis, thereby undermining its credibility” with the ultimate goal of causing “internal disruption, psychological impact, reputational damage and political leverage.”
Hammouchi, the head of both the DGSN and DGST who is widely described as King Mohammed VI’s most trusted “supercop”, has emerged as the primary target of the leak. Jabaroot has publicly called for the king to dismiss Hammouchi, who has faced long-standing criticism from human rights groups including Amnesty International over allegations of torture and enforced disappearances at DGST detention facilities. A 2014 French arrest warrant for Hammouchi triggered a major diplomatic rift between Paris and Rabat. Le Monde’s reporting notes that the five ex-DGST agents suspected of involvement in the leak claim they witnessed widespread misuse of personal data collected through illegal wiretaps and unauthorized background checks.
While analysts agree the leak is undoubtedly embarrassing for Hammouchi and the institutions he leads, there is no evidence to date that his position within the Moroccan government has been seriously weakened. Barah Mikail, an associate professor of political science and international relations at Saint Louis University Madrid, says the most consequential takeaway from the leak, if Le Monde’s reporting of ex-DGST involvement is accurate, is what it reveals about internal cohesion: “If the reporting that former DGST officers are involved is accurate, that would point to a problem of defection and grievance within the apparatus.”
Barcenilla added that the attack strikes at the core of Hammouchi’s public reputation as a leader defined by control, foresight and reliability: “Jabaroot’s attack is therefore also an attack on his capacity and reliability.” If the data is confirmed to be largely authentic, it could carry lasting reputational and political damage for the senior official.
Many experts, including Mikail, suggest the fact that much of the data is outdated does not automatically mean it is fake. It may indicate that the information is substantially authentic but was obtained from older datasets rather than a recent breach of internal security systems. Morocco’s consistent denial of the leak’s validity, Mikail notes, serves a clear damage-control purpose – but “this does not necessarily mean the data is false.”
