Jabaroot leaks 70,000 Moroccan agents: ex-spy in Germany following largest hack of Rabat intelligence service
A hacker known as Jabaroot has exposed the data of more than 70,000 agents from Moroccan security services. European intelligence agencies assess the information as genuine but outdated.

Largest documented breach against Moroccan intelligence rocks European services
More than 70,381 agents from two Moroccan security bodies have been exposed following a massive leak that El Mundo characterises as the largest documented breach against Morocco's intelligence services since their establishment. It affects the General Directorate for Territorial Surveillance (DGST, interior intelligence) and the General Directorate of National Security (DGSN, police), and European counter-intelligence services consider it possibly the severest blow suffered by a North African intelligence service in Europe in recent decades.
Behind the operation is a group—or individual—operating under the name Jabaroot, an Arabic term meaning "powerful". The actor or actors have published the data on Telegram channels and threaten further releases.
Mission orders pointing to assault on Ceuta
The most explosive part of the leaked documents package is not the agents' names, but extracts of mission orders for personnel deployed to Castillejos before and during the assault on Ceuta on 30 July. Those orders would constitute, if authentic, documentary proof that agents of the Moroccan state coordinated the mass entry into the Spanish border city.
Jabaroot names Abdellatif Hammouchi—decorated by former Spanish minister Marlasca with the Grand Cross of the Order of Merit of the Civil Guard—as the highest person responsible for the operation, alongside Fouad Ali el Himma, principal adviser to King Mohamed VI. The hacker promises to publish the complete orders in future releases.
Who is Jabaroot: clues point to a "lone wolf" in Germany
Although Morocco has attributed the leak to Algeria, its main regional rival, European intelligence services discount that origin despite Jabaroot himself presenting as part of a group of "Algerian patriots". For European analysts, the collective actually conceals a single person with privileged knowledge of the interior of Moroccan security services, operating from outside the country.
French cyber-security firm CybelAngel traced variants of the Jabaroot alias on platforms such as Telegram and found a connection to another alias: 3N16M4, used by the same actor on GitHub. This platform functions as a professional portfolio for developers and organises ethical hacking tournaments called "Capture The Flag". The user 3N16M4 participated in several of these tournaments, which allowed investigators to identify the country from which he habitually connected. The enquiries pointed to someone who "may be an IT engineer", who identifies as "Tunisian" and who "lives in Germany". The firm Zecurion independently reached the same conclusion.
Spanish strategic intelligence firm NAVAK Intelligence adds a further element to the profile: the level of penetration achieved by Jabaroot "is difficult to explain without prior privileged access". Its hypothesis is that this is a former Moroccan spy with training in information systems who emigrated to Germany and from there executes an operation comparable, in terms of impact, to what Edward Snowden carried out with NSA data in 2013.
European services verify the data: "those names exist"
Intelligence services throughout Europe and parts of the Maghreb are working to verify the authenticity of the documents, which include names of Moroccan agents who would have operated in different countries across the continent. From the Spanish CNI, which would have monitored some of them, to the security services of the Netherlands or France, enquiries have so far been positive: the names exist and in some cases correspond to individuals already known to European intelligence.
The total volume of stolen data amounts to several gigabytes, which hampers rapid processing. The provisional assessment from the services consulted is that the material appears genuine, although the list could be old and outdated.
The fugitive agent: a murky link between Pegasus and the "Ceuta operation"
Among the Excel documents leaked on Telegram appears the name of Mehdi Hijaouy, described as former deputy head of Moroccan foreign intelligence (DGED) and for years direct adviser to Fouad Ali el Himma. Caught in the internal war between Morocco's two main intelligence agencies, Hijaouy left the country with state secrets, passed through France and arrived in Spain in 2024, where he narrowly escaped extradition before disappearing.
Sources from the DGST claim he is hiding in a municipality on the outskirts of Madrid under CNI protection. Other accounts claim that Spanish services attempted to hand him over and that he escaped, remaining at large and subject to a search and capture order by the National Court.
The intelligence publication Escudo Digital identifies him as the technical architect of the Pegasus operation against Spain: the surveillance of Pedro Sánchez, several ministers and journalists that the National Court archived in January 2026 due to lack of cooperation from Israel, creator of the spyware programme.
Jabaroot issues fresh warning about Pegasus data
On one of his Telegram channels, Jabaroot himself posed the following question yesterday: "Who is interested in Pegasus data related to Pedro Sánchez?". For now there is no evidence that the hacker has actual access to that information, but the message has reignited alarm among the security services tracking him.
Source: El Mundo