Cliquez ici pour lire en français
Morocco’s National Police (DGSN) and territorial surveillance agency (DGST) have formally denied being hacked, after a group calling itself JabaRoot released files it claims were pulled directly from the security services’ databases.
The affair, which has fueled days of debate over sensitive data protection and the resilience of digital infrastructure, began with the release of documents containing personal information reportedly tied to more than 70,000 agents — names, dates of birth, ID numbers, and administrative references among them.
Cybersecurity: systems the authorities call untouchable 🛡️
Responding to accusations of a cyber intrusion, Morocco’s joint security pole (DGSN-DGST) says none of its IT platforms were compromised. According to the authorities, the leaked information reportedly came from old databases tied to insurance companies and social security bodies — not from the security systems themselves.
Officials also point to the high level of protection built into their infrastructure. They say certain strategic databases run on isolated environments, with no internet connection at all — an architecture often favored to reduce the risk of external attacks and mass data theft.
Digital disinformation and forged content ⚠️
Beyond the data question, authorities are also calling out a campaign built on altered documents, fake visual identities, and manipulated photographs. Several elements published by JabaRoot are said to contain inconsistencies, including the use of military ranks that don’t exist in Morocco, along with language errors the authorities say expose the content as fraudulent.
The affair highlights a growing phenomenon: using forged content to lend credibility to cyber influence operations. In a media environment where information spreads instantly, verifying sources has become as strategically important as securing the systems themselves.
An investigation to identify those responsible 🔎
An investigation is ongoing under the supervision of the relevant public prosecutor’s office to identify those behind the leak. According to some press reports, the data may be linked to older leaks involving former intelligence service employees.
Beyond Morocco’s specific case, the episode is a reminder that cybersecurity is no longer just about protecting networks. It now also covers data governance, the fight against disinformation, and institutions’ ability to preserve public trust in the face of digital threats.
Should public institutions communicate more openly about their cybersecurity measures to build citizens’ trust against digital threats? Let us know in the comments.
📱 Get our latest updates every day on WhatsApp, directly in the “Updates” tab by subscribing to our channel here ➡️ TechGriot WhatsApp Channel Link 😉
