What is Jabaroot, the mysterious group of hackers that threatens to reveal Morocco's secrets about Ceuta

The name appeared in April 2025 after a massive leak from the Moroccan Social Security. Its authors presented themselves as "Algerian patriots," but more than a year later it is still unknown who is really behind Jabaroot or if all the publications signed with that name come from the same group.

6 minutes

fotonoticia 20260710122904 1920

fotonoticia 20260710122904 1920

Add DEMÓCRATA to Google

Ask FREN

Published

Last updated

6 minutes

Most read

Jabaroot has become one of the most enigmatic actors in the digital war surrounding Morocco. The name has now returned to the forefront after those operating under this identity have disseminated information about the Moroccan security apparatus and linked their latest publications to the Ceuta crisis, accompanying them with serious accusations against officials of the kingdom that, for the moment, have not been independently proven.

Presenting it simply as a "group of Algerian hackers" does, however, assume a mystery that remains open. The leaders of the first major operation of Jabaroot defined themselves as "Algerian patriots" and justified their actions as a response to Morocco, but the identity, composition, and location of their members have never been publicly accredited.

The uncertainty has increased over time. The original channel used by Jabaroot on Telegram disappeared and subsequently new accounts using the same name emerged. The messages also changed in tone and language. Therefore, there is also no certainty that those currently publishing under the Jabaroot brand are the same people who carried out the cyberattack that shook Morocco in April 2025.

What Jabaroot means and when it appeared

"Jabaroot" is an Arabic word that can be translated as "power," "might," or "domination". The first identity that gained notoriety used the name "JabaRoot DZ," incorporating the letters "DZ," an international code associated with Algeria. Later on, some publications began to appear simply signed as Jabaroot.

The group publicly burst onto the scene on April 8, 2025, when it claimed an operation against Moroccan institutions and a huge amount of information from the National Social Security Fund of Morocco (CNSS) began to be disseminated. The institution itself acknowledged having suffered attacks against its systems and Morocco opened an investigation into what happened.

Jabaroot presented that action as retaliation for alleged Moroccan attacks against Algerian institutions. From the beginning, therefore, the collective built its identity around the political rivalry between Algeria and Morocco, although that ideological statement does not constitute proof of who technically executed the attack.

The attack that exposed the data of millions of Moroccans

The operation against Social Security was what turned Jabaroot into a known name. The leak affected information corresponding to approximately two million workers and around 500,000 companies, with tens of thousands of documents that included salary, professional, and personal data.

The impact was especially strong because among the documentation appeared data related to important businessmen and people close to the Royal House. The publication allowed for the knowledge of salaries and other private information that until then remained within the Moroccan administrative systems and provoked a significant debate about the security of public databases in the country.

The existence of a breach was acknowledged, but that does not mean that every disclosed document can be automatically considered authentic. The CNSS itself warned at the time that part of the files circulating were inaccurate, incomplete, or could have been manipulated, a caution that continues to be relevant for assessing the subsequent publications attributed to Jabaroot.

From the cadastre and Justice to the security services of Morocco

After the April attack, new leaks related to other Moroccan agencies and personalities began to appear under the identity Jabaroot. Among the targets were the Property Conservation, structures related to Justice, and later, members of the security apparatus and the royal palaces.

The publications also began to acquire an increasingly political character. Jabaroot disseminated documents about properties and assets attributed to high-ranking Moroccan officials and later information about alleged members of the security services. In August 2025, the revelations reached people linked to the General Directorate of Territorial Surveillance (DGST), the powerful Moroccan domestic intelligence service.

Precisely the nature of some of those documents fueled doubts about the origin of the information. Le Monde pointed out that certain leaks seemed to come from internal material of the Moroccan apparatus itself, a circumstance that opened a second hypothesis about Jabaroot different from the exclusively Algerian explanation.

The rivalry between Morocco and Algeria behind Jabaroot

The operations attributed to Jabaroot cannot be understood outside of the profound confrontation between Morocco and Algeria. Both countries broke diplomatic relations in 2021 and maintain opposing positions on strategic issues, especially regarding Western Sahara.

Rabat defends its sovereignty over the territory and proposes a regime of autonomy under Moroccan sovereignty, while Algeria supports the Polisario Front. This rivalry has also moved to cyberspace, where actors presenting themselves as patriotic from both countries have carried out attacks, leaks, and retaliation campaigns.

Jabaroot has positioned its messages within that confrontation. The first major leak was presented as a response to actions against Algeria, and other subsequent operations have also incorporated political claims. The fact that its messages favor Algerian positions, however, does not allow us to conclude that the group depends on the Algerian state, something for which there is no conclusive public technical attribution.

The mystery: who is really behind Jabaroot?

The disappearance of the first Telegram channel further complicated any attempt at attribution. Other channels with the name Jabaroot then emerged, and actors linked to the pro-Algerian hacker ecosystem promoted some of those new accounts. But no continuity has been accredited among all of them.

Le Monde even detected differences between the different stages. The first messages were written exclusively in English, while later publications incorporated Arabic and French and adopted a considerably more political discourse. In the world of Maghreb hacktivism, changes of identity, impersonations, and the reuse of known names are common.

That is why there is another hypothesis that is even more delicate. The French newspaper reported on speculations about a possible settling of accounts within the Moroccan security apparatus itself, in a context of rivalries between the DGST, dedicated to internal affairs, and the DGED, responsible for external espionage. The theory of former members of the services established in Europe has also circulated. None of these hypotheses have been proven, and there is no public technical evidence that allows attributing them to Jabaroot.

Why Jabaroot has reappeared now due to the Ceuta crisis

The brand Jabaroot becomes relevant again in August 2026 after its latest publications have directly introduced Spain and Ceuta into its narrative against the Moroccan security apparatus.

Those currently using this identity attribute responsibilities to high-ranking Moroccan security officials regarding the recent migratory pressure on Ceuta and claim to have sensitive information about the structures that participated in it. They have also presented their data leaks of members of the security services as retaliation against those officials.

Here it is essential to separate the existence of documents from the interpretation that Jabaroot makes of them. There is currently no independent proof that demonstrates that the group's accusations about the organization of events in Ceuta are true. These are claims made by those who currently control its channels and need external corroboration before they can be presented as facts.

What we know about Jabaroot and what remains unproven

There are several sufficiently documented elements. An identity called JabaRoot DZ appeared publicly in April 2025; it presented itself as formed by "Algerian patriots"; claimed responsibility for the attack coinciding with a real breach in Moroccan Social Security; and subsequently, documents related to other institutions and members of the kingdom's security apparatus have been disseminated under the name Jabaroot.

What remains unproven is equally important. We do not know the identity of its members, we do not know if they receive instructions from any State, and it is also not accredited that all leaks signed as Jabaroot since 2025 come from the original authors. Suspicions about a Moroccan internal operation are hypotheses, not conclusions.

The same caution must be applied to Ceuta. That Jabaroot has previously demonstrated access to sensitive information increases the interest of its publications, but an authentic leak does not automatically make the accompanying political narrative true. The accusations against Moroccan officials and the Ceuta crisis must be supported by verifiable documents or independent investigations before they can be considered accredited.

More key points, information and questions with FREN

AI-GENERATED CONTENT

What legal and judicial procedures does Morocco follow to investigate and prosecute cyberattacks like those attributed to Jabaroot?

I cannot answer your question in detail because I specialize in Spanish politics and institutions and their legislative and parliamentary framework, not in the law or judicial procedures of Morocco or other states. My search and reference tools are specifically oriented to the Spanish environment (Congress, Senate, regional parliaments, Official State Gazette and regional bulletins, Spanish governments and public institutions, as well as political and regulatory debate related to Spain).

This implies two important limitations for what you are asking:

  • Foreign legal framework: I do not have structured or specialized access to Moroccan legislation (penal codes, criminal procedure laws, cybersecurity laws, intelligence or defense regulations, etc.), nor to official databases on their processing or practical application.
  • Judicial and police practice in Morocco: I am also not designed to rigorously document how their courts, prosecutors, security forces, or intelligence services are organized and act in specific cases such as cyberattacks attributed to certain groups, companies, or actors (like the one you mention).

The type of response your question deserves — a precise description of the applicable criminal offenses in Morocco regarding cyberattacks, the competent bodies (judicial police, prosecution, criminal jurisdictions, possible specialized jurisdictions in terrorism or organized crime, etc.), and the sequence of actions (preliminary investigation, instruction proceedings, international cooperation, precautionary measures, prosecution) — requires:

  • Direct consultation of current Moroccan laws (for example, reforms of the Penal Code or specific laws on cybercrime or information security).
  • Review of documents or analyses from official Moroccan bodies (ministries, prosecution, higher council of the judiciary) or international organizations specialized in cybercrime focusing on Morocco.
  • Access to case law or, at least, case studies on how cyberattack investigations have been processed in that country.

None of this is within the scope in which I am prepared to offer reliable and verified information. If I did, I would run a very high risk of giving you a misleading answer, extrapolating from legal systems I know better (such as the Spanish one) but that are not automatically transferable to the Moroccan legal system, neither in their criminal figures nor in their procedures.

What I can do is guide you on how to search for that information more safely and precisely:

  • Consult directly official Moroccan sources, such as the websites of the Ministry of Justice, the Higher Council of the Judiciary, or the General Directorate of National Security, where laws, reforms, and statements on cybercrime are sometimes published.
  • Review reports from international organizations (for example, UN, Council of Europe if there is cooperation, INTERPOL, or agencies specialized in cybercrime) that analyze Morocco's legislation and practice in cybersecurity.
  • Search for academic or think tank works specialized in comparative law or cybersecurity in the Maghreb, which usually explain in some detail the applicable criminal offenses and procedural itinerary in each country.
  • In case of professional use (litigation, risk advice, compliance, etc.), consult a Moroccan law expert or a firm with practice in that country, who can correctly interpret the legislation and case law in force.

Within my scope, however, I could help you, for example, to:

  • Explain how Spain investigates and prosecutes cyberattacks from a criminal and procedural point of view.
  • Detail the role of the National Court, the Cybercrime Prosecutor's Office, the cybercrime units of the Police and Civil Guard, or bodies such as CCN-CERT or INCIBE.
  • Analyze Spanish legislative initiatives in cybersecurity or cyberdefense, and their parliamentary processing.

If you reformulate your question to focus on the Spanish case, on Spain's international cooperation against cyberattacks, or on the comparison between Spain and the EU in this area, I will be able to give you a detailed and contextualized answer.

What are the competencies and functions of the General Directorate for Territorial Surveillance (DGST) and the DGED in Morocco?

In Morocco, the General Directorate for Territorial Surveillance (DGST) and the General Directorate for Studies and Documentation (DGED) form the core of the State's intelligence apparatus, with an approximate functional division between internal security and external dimension. The available information mainly comes from official statements, press releases, and journalistic work, as the detailed legal framework of both structures is not published with full transparency.

DGST: intelligence and internal security

The DGST is described in multiple official Moroccan statements and in cooperation with Spain as the country's internal intelligence service. A statement cited by Demócrata notes that the DGST provides “precise intelligence information” to dismantle jihadist cells and neutralize “highly dangerous terrorist plans” on Moroccan territory, with coordinated operations in cities such as Casablanca, Agadir, or Tetouan.

Based on these documents and known operations, its main functions can be summarized as follows:

  • Prevention and repression of internal terrorism: the DGST promotes investigations that allow identifying cells linked to the Islamic State, arresting their members, and seizing explosives, bladed weapons, and propaganda material. The described operations include phases of surveillance, risk analysis, and coordination with police forces.
  • Fight against radicalization and violent extremism: official statements emphasize that the DGST monitors social networks and digital spaces where nasheeds, manuals, or instructions to manufacture explosive devices are disseminated, and helps identify “jihadist influencers” operating both in Morocco and abroad.
  • Intelligence support to police and justice: in several cases, the Central Judicial Investigations Office (BCIJ) indicates that arrests were based on data provided by the DGST, positioning this general directorate as the main intelligence provider for criminal investigations on terrorism and organized crime.
  • Organized crime and drug trafficking: a statement about dismantling an international hashish trafficking network near Casablanca notes that the operation was planned based on information from the DGST, which allowed locating beaches, boats, engines, and money linked to the organization.
  • International security cooperation: notes from the Spanish Ministry of the Interior highlight the “close collaboration” with the DGST in antiterrorist operations carried out in Spain, implying information exchange, monitoring of common targets, and operational coordination.
  • Use of technological surveillance capabilities: an investigation published by Demócrata on the Pegasus case explains, based on the testimony of a former DGST member, how the agency would have incorporated the spyware into its operations and reserved it for targets considered high value ( Demócrata analysis on Pegasus ).

Overall, the DGST acts as an internal state security service: it collects and analyzes information, conducts physical and digital surveillance, feeds the police and judicial apparatus, and coordinates the operational response against terrorist threats and criminal networks.

DGED: intelligence and operations abroad

The General Directorate for Studies and Documentation (DGED) appears more indirectly in the consulted documentation. Demócrata mentions it as one of the Moroccan intelligence services involved in debates about the role of certain media actors, specifying that there is no judicial ruling that personally identifies some individuals as DGED agents ( Demócrata piece on the alleged CNI report ).

Based on that coverage and journalistic analyses of the Moroccan security system, the DGED is positioned as the other major pillar of the intelligence apparatus, complementary to the DGST. The functions attributed to it in open sources can be summarized as follows, always cautiously because Rabat does not publish a detailed catalog:

  • Strategic intelligence on the exterior: collection and analysis of political, security, and economic information relevant to Moroccan foreign policy and the calibration of its international influence, for example in the debate on Western Sahara.
  • Monitoring key actors and scenarios abroad: media such as Demócrata document that Morocco cultivates an intense presence in Washington through lobbying contracts registered with the U.S. Department of Justice ( investigation on Moroccan lobbying ); the DGED appears in this context as one of the services that feed this strategy with information and analysis.
  • Sensitive operations and protection of interests abroad: although sources do not detail specific missions, as an intelligence service linked to the royal palace it is associated with tasks of protecting Morocco's strategic interests in other countries and multilateral forums.

Compared to the DGST, public information about the DGED is much scarcer and more fragmented. What the consulted sources do reflect is that it is part of the overall Moroccan intelligence apparatus, with emphasis on the external dimension and the international projection of the kingdom's agenda.

In summary, the DGST concentrates intelligence and operational action within Moroccan territory against terrorism and organized crime, while the DGED is located in the field of strategic intelligence and external influence, with a high degree of institutional opacity and few official references about the details of its competencies.

What international laws regulate cybersecurity and data protection in cases of cross-border leaks like those carried out by Jabaroot?

Cases of cross-border leaks like those carried out by the hacker group Jabaroot operate at the intersection of several regulatory layers: data protection, cybersecurity, and international criminal cooperation. There is no “single global law,” but rather a mosaic of overlapping instruments that operate depending on who the victim is, where the attacked company is located, and from which country the attackers act.

1. General Data Protection Regulation (GDPR) and its development

The Regulation (EU) 2016/679, GDPR, is today the central reference when the leak affects data of persons in the EU. It applies to any organization processing data of residents in the Union, regardless of where it is established, and broadly defines “personal data security breaches” as incidents causing destruction, loss, alteration, or unauthorized disclosure of personal data (AEPD, sanctioning resolutions such as this one).

For cross-border leaks, the GDPR articulates:

  • Obligation to notify breaches to the supervisory authority and, where applicable, to the affected individuals.
  • A system of cooperation among national authorities in cross-border cases: a “lead authority” leads the investigation but must coordinate with others (the European Council and Parliament have approved a new specific law to speed up these cross-border claims: regulation on cross-border complaints ).
  • Strict rules for international data transfers: adequacy decisions, standard contractual clauses, binding corporate rules, etc. (see CNIL guides on transfers: impact assessment guide for transfers ).

Additionally, the EU has adopted a new regulation to improve cross-border enforcement of the GDPR, which standardizes requirements and cooperation deadlines among data protection authorities ( Council-Parliament political agreement ).

2. NIS2 Directive and cybersecurity regulation

Regarding cybersecurity of essential networks and services, the European pillar is the Directive (EU) 2022/2555, NIS2. It obliges a wide range of “essential” and “important” entities (energy, transport, banking, health, digital providers, etc.) to:

  • Apply risk management measures and technical and organizational controls.
  • Notify significant incidents to competent authorities within very short deadlines (between 24 and 72 hours, as explained in analyses like this one ).
  • Assume responsibilities at the management level for serious cybersecurity failures.

NIS2 is not a criminal law, but it sets the minimum standard of cyber resilience and incident notification for critical operators, complementing the GDPR when the incident involves personal data.

3. International data protection conventions

Outside the exclusively community framework, two Council of Europe instruments stand out:

  • The Convention 108 and its Protocol 108+, the first binding international treaty on data protection, also open to non-European countries. It establishes principles of lawfulness, minimization, security, and rules for cross-border data transfers.
  • A network of supervisory authorities that can cooperate in investigations and sanctions for processing or leaks with an international dimension, in line with what is reflected in decisions of various national authorities and guidelines from the European Data Protection Board ( guidelines on transfers to third-country authorities ).

4. Cybercrime and access to evidence: Budapest and the new UN treaty

When the leak results from a cyberattack — as in the case of Jabaroot —, the criminal sphere comes into play:

  • The Budapest Convention on Cybercrime of the Council of Europe, with dozens of state parties, harmonizes computer crimes (illegal access, interception, system damage, etc.) and facilitates cross-border cooperation and obtaining electronic evidence.
  • The new UN treaty against cybercrime, signed by 65 countries in Hanoi ( Hanoi treaty ), strengthens this framework: it criminalizes various forms of cybercrime, creates a 24/7 cooperation network, and regulates the exchange of electronic evidence.

These two instruments are key to investigating groups like Jabaroot when they attack from one country infrastructures or persons located in another.

5. Cross-border data flows and sectoral agreements

To this core are added numerous agreements that condition how data are protected in international flows:

  • EU adequacy decisions and bilateral agreements (for example, with Brazil or Singapore) that allow creating “free and secure data” areas, provided the partner country has a protection level comparable to the GDPR ( EU-Brazil ; EU-Singapore ).
  • PNR agreements with third countries (USA, Australia, UK, Norway, Iceland, Switzerland) that set strict rules for the exchange of air passenger data, limiting uses and retention periods ( PNR agreements ).
  • Multilateral initiatives on data flows and digital trade, often inspired by OECD principles, seeking to reconcile international transfers with privacy guarantees.

6. Practical application to cases like Jabaroot

In a cross-border leak scenario like Jabaroot's, the regulatory fit is usually as follows:

  • If there are affected individuals in the EU or companies established in the EU, the GDPR is activated (data protection, breach notification, sanctions) and, if the entity is essential, also NIS2 (risk management and incidents).
  • To criminally prosecute the attackers and request proceedings in other countries, the Budapest Convention and, progressively, the UN treaty against cybercrime are used.
  • Data agreements (adequacy, PNR, digital trade) and Convention 108+ frame how those data can circulate between jurisdictions and what safeguards must be applied even after the leak.

Play

Test your knowledge with FREN!

How much do you know about this topic? Answer the following 3 questions.

On what date did Jabaroot publicly claim its first major operation against Moroccan institutions?

Question 1 of 3

How many workers were affected by the Moroccan Social Security data leak attributed to Jabaroot?

Question 2 of 3

What factor has complicated the clear attribution of Jabaroot's identity and actions?

Question 3 of 3

Hola, soy Fren. ¿Cómo te ayudo?