This is the largest documented breach against Morocco's security services since their establishment, and possibly the biggest counterintelligence blow suffered by a North African service in Europe in recent decades: 70,381 agents exposed from two agencies: the General Directorate for Territorial Surveillance (DGST or internal intelligence) and the National Security Directorate (DGSN, or police).
Among the leaked documents is something more explosive: excerpts from the mission orders of agents who traveled to Castillejos before and during the assault on Ceuta on July 30. These orders, which Jabaroot threatens to fully disclose, serve as evidence that Moroccan state agents traveled to the border city to coordinate the massive entry. The leak points to Abdellatif Hammouchi (awarded by Minister Marlasca with the Grand Cross of the Order of Merit of the Civil Guard) as the operation's top leader, alongside Fouad Ali el Himma, the main advisor to King Mohamed VI, but promises new documents in future releases.
Who is behind this revelation? We only have the name of a supposed group of hackers that has previously acted with some success in Morocco: Jabaroot, which means "powerful" in Arabic. Although Morocco blames Algeria, its major regional rival, European intelligence services dismiss that origin, despite Jabaroot claiming to be part of a group of "Algerian patriots." Jabaroot made his debut by stealing data from the Moroccan National Social Security Fund and about the royal palace staff and properties.
According to European intelligence services, behind the hacker group Jabaroot actually hides a single person, a kind of "lone wolf" who knows the ins and outs of Moroccan security services but operates far from Morocco. Several cybersecurity companies have followed his trail and drawn some conclusions. The French company CybelAngel searched for variations of Jabaroot's alias used on platforms like Telegram and found it linked to another alias: 3N16M4, which the same hacker used on sites like GitHub.
GitHub is a platform where programmers store and share their code. It's like a professional portfolio for developers that organizes ethical hacking tournaments called "Capture The Flag": cybersecurity challenges like decrypting passwords, finding vulnerabilities, and penetrating simulated systems. The user 3N16M4 participated in several tournaments, allowing investigators to see which country he usually connected from. The investigations led them to someone who "may be a computer engineer," who identifies as "Tunisian" and "lives in Germany." Shortly after, another competing company, Zecurion, reached the same conclusion.
The Spanish cybersecurity group Navakintelligence adds another interesting point to the profile: Jabaroot's level of penetration "is hardly explainable without prior privileged access," leading to the hypothesis that he is a former Moroccan spy with information systems training, who emigrated to Germany and now conducts an operation comparable to Edward Snowden's data breach of the NSA (US National Security Agency) in 2013.
Intelligence services across Europe and part of the Maghreb are trying to verify the authenticity of the documents, which provide names of Moroccan agents who may have operated in different countries across the continent. From the CNI, which monitored some of them, to security services like those of the Netherlands or France, the investigations so far have been positive: those names exist and in some cases are familiar to European intelligence. Although the volume of stolen data is several gigabytes and processing it will be challenging, everything appears real for now, although the list may be old and outdated.
As a curiosity, in one of the Excel documents leaked on Telegram, the name of Mehdi Hijaouy, a former obscure Moroccan agent number two of the external intelligence (DGED) and for years a direct advisor to Fouad Ali el Himma, the main advisor to King Mohamed VI and the mastermind behind the "Ceuta operation" according to Jabaroot, appears. Caught in the internal war between the two main Moroccan intelligence agencies, he fled the country with state secrets, passed through France, and arrived in Spain in 2024, where he was nearly extradited before disappearing.
Sources from the DGST claim he is hiding in a village on the outskirts of Madrid under the CNI's protection, although other versions suggest that Spanish services tried to hand him over, but he fled, remaining missing and wanted by the National Court. What makes his case particularly explosive is that the publication Escudo Digital, specialized in intelligence, identifies him as the technical architect of the Pegasus operation against Spain: the espionage of Pedro Sánchez, several ministers, and journalists that the National Court closed in January 2026 due to Israel's lack of cooperation, the creator of the spy program.
Yesterday, Jabaroot himself asked in one of his Telegram channels: "Who is interested in Pegasus data related to Pedro Sánchez?" although there is no evidence that this hacker has access to that information yet.
