The hacktivist collective known as JabaROOT DZ (also written Jabaroot) has published what it says is a full personnel database covering Morocco's two principal security bodies: the General Directorate for Territorial Surveillance (DGST), the domestic intelligence service, and the General Directorate of National Security (DGSN), the national police. Reported record counts differ: teleSUR and Mundo América both cite a precise 70,381 agents, while Escudo Digital, The European Conservative, Seguidores.online and other outlets describe the set as "around 70,000." Every source available for this brief is secondary press. There is no victim statement, no regulator filing and no CERT advisory confirming the breach, and Rabat has not publicly acknowledged it. What follows should be read as a well-corroborated claim under active verification, not a confirmed incident record.
What Happened
JabaROOT DZ telegraphed this release before making it. On or around 20 August 2026, Maghreb Online reported the group had issued an ultimatum threatening to expose more than 70,000 members of Morocco's internal security services, and published a proof sample of roughly twenty DGST profiles to its Telegram channel to establish credibility. The full dataset, the group said, was ready to go if its demands were not met.
The release followed days later. Accounts differ slightly on timing: News Now Nigeria dates the publication to Monday 24 August 2026, while teleSUR reported on 25 August that the group "announced the disclosure Monday," and Escudo Digital logged the download link's appearance on 25 August. The group distributed the material under the campaign tag #OP_CEUTA and framed it publicly as a "gift to Spain," explicitly tying the leak to the mass border crossing into the Spanish enclave of Ceuta on 30 July 2026.
Beyond the personnel data itself, JabaROOT DZ made a direct political accusation. It named Abdellatif Hammouchi, who heads both the DGST and the DGSN, and royal adviser Fouad Ali El Himma as having planned the migratory pressure on Ceuta. The group claims to hold excerpts of mission orders for agents deployed to Castillejos (Fnideq) before and during the crossing, and has threatened to release those in full. Mundo América characterises those excerpts as the most explosive element of the dump. Note the causality here is the attacker's claim, repeated by press, and is not independently established.
Verification signals are partial and pull in slightly different directions. The European Conservative, citing El Confidencial, reports that former Moroccan intelligence officers assessed at least part of the examined material as authentic. Mundo América reports that European security services analysing the data consider it real but outdated. Escudo Digital stated at time of publication that it was still verifying authenticity. Seguidores.online notes that neither the authorities nor the hackers have offered independent confirmation of the full veracity of the leak.
On attribution, Moroccan officials have pointed to Algeria, per both Maghreb Online and Mundo América. Mundo América reports that European intelligence services dismiss that origin, notwithstanding the group's own self-description as "Algerian patriots." The name reportedly means "powerful" in Arabic.
What Was Taken
Field-level descriptions vary by source, and the composite picture is broader than any single report:
- Core identity data (consistent across sources): full names, dates of birth, and national identity document numbers for DGST and DGSN personnel.
- Employment data: year of recruitment or service entry date, employee/staff numbers, and rank. Seguidores.online attributes the employee-number and recruitment-year fields to El Confidencial's review; Maghreb Online reported service entry dates plus internal notes in the pre-release sample.
- Financial and payroll identifiers: Escudo Digital is alone in reporting that the set includes PPR numbers (the Moroccan civil service payroll identifier) and bank account information. Treat that as single-source until corroborated.
- Senior leadership subset: teleSUR reports sensitive data on 21 senior officials of both agencies, including Hammouchi himself.
- A second list: News Now Nigeria reports an additional file containing data on roughly 1,400 further individuals.
- Operational documents: claimed mission-order excerpts for agents sent to Castillejos, not yet fully published.
The population is not limited to intelligence officers. The European Conservative notes the documents also cover police officers and administrative employees of the security apparatus, which is consistent with DGSN's inclusion.
Sensitivity here is close to worst case. A cross-referenced set of name, national ID, date of birth, payroll identifier and recruitment year is sufficient to de-anonymise serving officers, reconstruct organisational cohorts by intake year, and, if the bank details are genuine, enable targeted financial fraud or coercion. Mundo América describes it as the largest documented breach of Morocco's security services since their founding and possibly the most damaging counterintelligence blow to a North African service in Europe in decades. That the data may be somewhat dated, per the European services quoted, reduces operational currency but does not undo the identification of individuals who in many cases still serve.
A separate and distinct Spanish matter is being reported alongside this one and should not be conflated with it: Seguidores.online reports that the professional association Justicia Guardia Civil (JUCIL) has filed a complaint with Spain's National Court over a file containing information on more than 500 Civil Guard, National Police and Armed Forces personnel. No source links that file to JabaROOT DZ.
Why It Matters
For defenders, three things stand out.
First, this is a personnel-database compromise, not a systems compromise, and the damage model is entirely different. There is no ransomware note, no encrypted estate, no service outage to restore. The harm is permanent disclosure of identity data for people whose safety depends on that data staying private. There is no remediation that recovers it. Once a covert officer's name, DOB and national ID are public, the mitigation is protective, not technical.
Second, hacktivist collectives with geopolitical motives are now running staged, media-aware disclosure campaigns rather than dumping and disappearing. JabaROOT DZ published a twenty-record teaser, issued an ultimatum, released the bulk set on a stated timeline, and is withholding the mission orders as leverage for a further release. That is an extortion cadence applied to a political objective, and it means the incident is not over at the point of first publication.
Third, this actor has a documented history against the same target set, which makes the current release predictable in hindsight. Per Democrata's account of INCIBE reporting, JabaROOT DZ published confidential data from Morocco's Caisse Nationale de Sécurité Sociale (CNSS) on 8 April 2025: more than 53,000 files covering records for nearly half a million companies and close to two million employees, including affiliation data, worker identification numbers, salaries and contact details. INCIBE recorded the actor's stated political motive as retaliation for the hijack of the Algerian Press Service's X account, which was renamed "Sahara Marocain" before being suspended. Maghreb Online adds that CNSS itself confirmed that breach, and attributes further intrusions to the group against the Ministry of Justice and the publication of financial details tied to the Royal Household. Mundo América likewise cites the CNSS theft and royal palace staff and property data as the group's debut. A threat actor that has repeatedly and successfully hit national institutions in one country will keep hitting them.
The wider context is that a data breach has become an input to an interstate dispute. The 2026 Strategic Outlook published by Spain's Ministry of Defence, cited by The European Conservative, had already recorded Morocco's 2021 use of the entry of roughly 9,000 Moroccan citizens including 1,500 minors into Ceuta as an "instrument of pressure." The leak is now being read against that prior. Reported figures for the July 2026 crossing itself vary widely, from "tens of thousands" in most accounts to a figure of over 70,000 migrants in Seguidores.online, which no other source here supports.
The Attack Technique
No source in this set identifies the initial access vector, the exploited system, or the date of compromise for the DGST/DGSN dataset. There is no vendor advisory and no incident report to draw from. Anyone stating a technique for this specific breach is speculating.
The one adjacent technical detail on record concerns the group's earlier CNSS operation, where INCIBE noted that most of the exposed data appeared to have been stored in clear text on compromised servers. That is a data-at-rest failure, not an intrusion method, but it is the only substantiated observation about how this actor's targets were configured when breached, and it is consistent with a pattern of exfiltrating bulk records from poorly hardened internal databases rather than conducting narrow, targeted collection.
Distribution channels are clearer than acquisition. The group operates through a Telegram channel used for announcements, teasers and threats, with a download link posted to a dark web location per Escudo Digital, and secondary amplification through social media. That combination is now the standard hacktivist publication stack.
What Organizations Should Do
- Treat your HR and payroll systems as tier-one assets. In this incident the crown jewels were not source code or customer records but a personnel roster. Inventory every system holding staff identity data (HRIS, payroll, badging, background-check archives, pension and social-security integrations) and apply the same access controls, monitoring and egress alerting you apply to production data stores.
- Encrypt personnel data at rest and verify it, do not assume it. INCIBE's cleartext finding on the CNSS breach is the single most actionable technical lesson this actor has handed defenders. Audit actual on-disk state on database and backup servers rather than trusting the configuration record.
- Alert on bulk read and export patterns. A 70,000-row extraction from an HR database has a signature. Set volumetric thresholds on query results, report generation and file transfers out of personnel systems, and route them to a human rather than a dashboard.
- Build a protective-response playbook for staff exposure, separate from your breach playbook. If names, national IDs and payroll numbers for your workforce go public, the response is credit and identity monitoring, targeted phishing and social-engineering warnings to every named individual, review of physical security for high-risk roles, and forced credential rotation. Decide who owns that now.
- Model staged disclosure into your incident timeline. Assume the first dump is not the last. Assign someone to monitor the actor's Telegram and paste channels continuously through the incident so a second release does not arrive as a surprise from a journalist.
- Vet the dump before you act on it. Reporting here already reflects a mixture of authentic-but-dated content and unverified claims. If a dataset naming your organisation surfaces, validate a sample against internal records before issuing notifications, and state clearly in any public comment what you have and have not confirmed.
- Reduce retention on identity fields you no longer need. Recruitment years, historical rank records and legacy bank details for former staff expand the blast radius of any single extraction without serving an operational purpose.
Sources: JabaROOT DZ publishes link to data on 70,000 alleged Moroccan intel... | Hacker Group Claims Identities Of 70,381 Moroccan Agents | Hackers Say Rabat Deployed Moroccan Agents to Ceuta Before and Duri... | Jabaroot had already starred in a major leak in Morocco before appe... | Agent data leak: Morocco and Spain on alert | Jabaroot, the hacker who has dealt the biggest blow to Morocco News | Morocco: Hacker Jabaroot returns with ultimatums regarding the Ceut... | A group of hackers "give to Spain" the leak of 70,000 Moroccan agen...