Jabaroot, the hackers leaking Moroccan intelligence data and threatening to reveal Sánchez spying
The hacktivist group Jabaroot has allegedly published data on more than 70,000 Moroccan intelligence officers and threatens to disseminate information about surveillance of members of the Spanish Government via Pegasus.

Jabaroot threatens to expose spying on Sánchez and exposes Moroccan intelligence
A month after the crisis in Ceuta began, a new actor has emerged that threatens to reveal the true cause of the massive arrival of tens of thousands of migrants and those responsible for the illegal assault on the autonomous city. This is Jabaroot, a term meaning "powerful" in Arabic. According to ABC, it is a group of uncertain origin that burst into the public sphere after publishing the identities of allegedly more than 70,000 agents from Morocco's intelligence services.
On Monday, 24 August, the name Jabaroot began circulating in Spanish media. The group published on Telegram four spreadsheets with the names of tens of thousands of supposed members of the security and intelligence forces of the Alaouite kingdom, "stationed in Europe and in strategic Moroccan institutions", as they specified. The documents, reviewed by ABC, include both anonymous individuals and senior officials from the General Directorate of National Security (DGSN) and the General Directorate of Territorial Surveillance (DGST), among them its top official, Abdellatif Hammouchi, commonly described in the press as the "super police chief" or the "viceroy" of King Mohammed VI. Each record includes service number, identity document, bank account, and dates of joining and birth. The official media in Rabat downplayed the leak. The Médias24 portal stated that "it is very likely that the names were obtained through cyberattacks against previous organisations".
A blurred identity between Algeria and Morocco
Who comprises Jabaroot and what their actual objectives are remains a mystery. It is not even clear whether it is a single person or a collective. The name emerged in April 2025, amid a full diplomatic standoff between Rabat and Algiers, following the hacking of the account of Algerian news agency APS by computer hackers affiliated with Morocco. The group signs its operations under the seal JabaRoot DZ—the official code for Algeria—and presents itself as a platform for patriotic pro-Algerian "hacktivism" that claims to defend the Sahrawi cause and denounce Moroccan cyber-espionage against Algeria and several European governments. Its declared number-one objective is Hammouchi and corruption in Morocco.
José Miguel Rosell, co-founder and managing partner of the cyber-security firm S2 Grupo, whose cyber-intelligence division LAB52 monitors the activity of such actors, defines the group thus: "Apparently Jabaroot does not ask for money for the information, apparently it publishes it, which means it is an activist group". Its method is a drip feed: it announces control of large volumes of data, but releases only fragments. Telegram is its centre of operations—communiqués, polls and screenshots as proof of access. "These groups operate by leaving what are called implants in their targets. They may have stolen the information two years ago and been holding it waiting for the moment to use it", warns Rosell.
Friendly fire from within Rabat?
Identifying the perpetrator is particularly difficult, although there are indications pointing to within the Moroccan apparatus itself. A cyber-security expert source who prefers not to reveal their identity states: "The rumour mill says the information comes from friendly fire. And the entire structure of the intelligence chief has been exposed. It very probably is people who want to ruin something very specific without harming the rest, which is why they have not accessed—or have not published—data from the DGED, Moroccan foreign intelligence". The same source adds: "Although Algeria has always had capacity in these cyber wars, in this case it is a group that offers much more sensitive information and which very probably obtains it through sources from within. The origin of the group very probably is Algerian, but they have a source within Morocco and that source has to be of very high rank".
Along the same lines, Le Monde published after the attack that the leak of identities was the work of five former agents of the Moroccan DGST: four officers and a commissioner who broke with the service and went into exile in Europe, and who are demanding changes in the security hierarchy of the kingdom. That hierarchy is headed by Hammouchi, decorated by the Spanish Interior Minister with the Grand Cross of Merit of the Civil Guard only months before the outbreak of the Ceuta crisis.
A history of leaks against Morocco
Jabaroot has been conducting top-level leaks since the previous year, all of them linked to Morocco. The first was against the CNSS, Moroccan social security, with the dumping of around 54,000 files containing banking and salary data of two million workers. Then came salary and labour data from the Royal Family holding, information from the notarial platform Tawtik, records about the royal palace and Moroccan auxiliary forces, among other targets.
Now the group threatens to go further: publish who is behind the entry of more than 72,000 people into Ceuta and disseminate information about surveillance of Pedro Sánchez and several members of his Government through Israeli software Pegasus, currently in Moroccan hands according to industry sources. The question of who has an interest in that information coming to light—and at what moment—is the crux of the investigation being followed by both Spanish intelligence services and cyber-security analysts monitoring the group.
Source: ABC