The cyberwar hitting Morocco since 2025 extends to the Ceuta crisis

The cyberwar hitting Morocco since 2025 extends to the Ceuta crisis

Morocco has been facing a cyberwar launched by the hacker group Jabaroot for a year and a half, which has successively hit its security centers and sensitive public institutions. The publication this week, in the midst of the Ceuta migration crisis, by the same hackers of a list with the personal data of 70,381 alleged Moroccan spies has unleashed a small media earthquake in Spain and Europe. While the press of the Maghreb country remained silent, the enigmatic Jabaroot group (power, in Arabic) also seems to have interfered in internal political struggles. These pirates ―initially linked to Algeria― now threaten to make new sensational revelations public, such as the identity of the leaders of Rabat who “orchestrated” the overflow of the Spanish autonomous city through the entry of more than 70,000 migrants.

Read more Pogacar falls with 32 kilometers to go and abandons La Vuelta in the eighth stage

Although the four spreadsheets disseminated by Jabaroot mainly include base agents, the presence of senior officials from the General Directorate for Territorial Surveillance (DGST, internal intelligence) and the General Directorate of National Security (DGSN, national police) of Morocco stands out. The best-known personality in political terms is the director of both organizations, Abdelatif Hamuchi, a trusted man of King Mohammed VI and known in the media as “the super agent.”

In its usual style, the Moroccan government has denied through the DGSN-DGST Security Unit any intrusion into its information systems or security databases. In a statement, published three days after the leak, it specified that the information disseminated was obtained from insurance company files such as Saham and from the Social Security Treasury about their employees. The own databases, meanwhile, have not been affected as they are subject to the strictest cybersecurity standards, they assure. “These are old data (…) and altered or falsified documents presented as official,” the Moroccan services specify without further detail.

Jabaroot has presented its leak as a message directed at Spain amid the migration crisis. Its cyber pirates have claimed to have unpublished information about the migrant avalanche on July 30 and 31. The Telegram account with the revelations lasted 72 hours until it was closed this week. Every so often the pirates usually open a new one. The threats that the group published during the last month continue to feed the network. In one of them, it is claimed that they have messages exchanged between high-ranking Moroccan government officials proving that they were behind the massive entry into Ceuta.

Likewise, Jabaroot raised this question on its networks: “Who is interested in the Pegasus data related to Pedro Sánchez?”. Jabaroot refers to the Pegasus case and the possible involvement of Morocco in the hacking with the Israeli program that the official mobile phones of Sánchez and three of his ministers suffered in May 2021, in the midst of a diplomatic crisis with the authorities of Rabat due to a previous massive immigrant incursion in Ceuta.

The cyberwar hitting Morocco since 2025 extends to the Ceuta crisis
Abdelatif Hamuchi, in November 2016 in Marrakech.Fadel Senna (AFP)

The data disseminated by Jabaroot are organized in tables with a different number of columns, depending on the spreadsheet. The information accompanying the full name of the person varies: ID number, affiliation as an official, public payroll registration (assigned by the General Treasury of Morocco), the initials of their police rank or within the Moroccan intelligence services, bank account code, date of birth and “recruitment.”

An analysis of the names carried out by the French newspaper Le Monde has also identified regional directors and heads of counterterrorism, counterespionage, operations, human resources, budgets departments, among others, in the list. The French media points to a payroll department as the probable source of the leak.

Le Monde claims, according to its own investigation, that the leak was the work of five former DGST agents (four officers and a police commissioner who broke with the service and went into exile in Europe), who demand changes at the head of Morocco’s security institutions.” These claim to have witnessed the misuse of personal information in phone tapping.

It is difficult to verify the effective presence of spies in Jabaroot’s leaks, given the validity of the files, prior to 2020, and the inclusion in the list of all kinds of officials from the Moroccan security services. Several people listed are already dead, such as Abdelhak Khiame, DGST agent and first director of the Central Judicial Investigations Office, who died in 2022. The first doubt that arose about the massive dissemination of a list with “spies” of the government is the large number of people involved. To put it in context, CIA agents number around 20,000, according to a revelation by The Washington Post.

Read more A group of military personnel attempts to carry out a coup d’état in Niger

The publication of the list has also been the perfect breeding ground for the spread of hoaxes through anonymous accounts on social networks like X. For example, the one that identifies the name Mohamed Bouharrat with one of those convicted for the 11-M attack in the 2007 trial. The truth is that one of the convicts was named that and the year of the conviction also matches the supposed “recruitment” that appears in the list, as well as the birth year in 1979. But later the media Newtral verified that they were different people. The terrorist Bouharrat was born on May 1 of that year, according to the National Court sentence that sentenced him to 12 years in prison, and the birth date of the one appearing in the disseminated list is September 24, 1979.

Virtual chain threats

Jabaroot was first identified on the front of the cyberwar against Morocco in April 2025. The press of the Maghreb country initially linked it to a group of Algerian hackers, but its identity remains unknown. It has hit the administration from all sides, from traffic fines of the National Road Safety Agency to cadastral certifications, passing through the payrolls of senior officials of the royal palace. Last year they claimed responsibility for infiltrating the internal system of the Moroccan Ministry of Justice and claimed to handle confidential data of the minister, Abdelatif Uahbi, as well as 5,000 magistrates and another 35,000 officials.

Precisely the one now leading on behalf of the Moroccan government during the Ceuta crisis is the Minister of Justice, Abdelatif Uahbi, who has demanded that Spain hand over “all” unaccompanied minors of Moroccan nationality who remain in the autonomous city, whose sovereignty it claims for the Alaouite monarchy. As a prominent leader of one of the three parties of the coalition government, he is in full campaign for the legislative elections on September 23.

The cyberwar hitting Morocco since 2025 extends to the Ceuta crisis
Massive entry of Moroccans by sea to Ceuta, July 30. Joaquín Sánchez

The same Jabaroot pirates boasted of having obtained more than 10 million documents, including real estate operations of public figures, including Minister Uahbi, implicating him in alleged tax evasion. The National Agency for the Conservation of Property Titles of the Cadastre denied that its files had been violated and referred the breach to the Notaries Association consultation platform, which was closed.

The spokesperson for the Rabat government, Mustafá Baitas, then accused “hostile actors” of the cyberattacks, referring to a foreign power. Uahbi, however, declared himself a victim of “a settling of scores” by a “fifth column” that manipulates leaks from foreign actors from inside the country “spread without verification from obscure places,” evoking a silent internal power struggle.

Counterattack operations

Behind Jabaroot’s initial attacks supposedly lies the curtain of the cyberwar that has been unleashed for more than a year between Moroccan and Algerian pirates. Opposite the latter is Phantom Atlas, a consortium of Moroccan ‘hackers’, which in mid-2025 announced on Telegram that it had infiltrated Algeria’s banking system through a breach in the General Mutual of Posts and Telecommunications. On the same network, the pirates showed screenshots of transfers, account statements, and identity documents of clients of the National Bank of Algeria.

It was not the only counterattack. On that same social network, they claimed to have accessed the internet infrastructures of Algérie Télécom, the state telephone company, and the database of the Ministry of Labor, where they claimed to have detected files revealing “serious irregularities in administrative management” from public authorities in Algiers.

Read more Marc Márquez responds to Marco Bezzecchi’s challenge at the Aragon GP

Translated from

Leave a Reply

Your email address will not be published. Required fields are marked *