What is Jabaroot, the mysterious group of hackers that threatens to reveal Morocco's secrets about Ceuta

The name appeared in April 2025 after a massive leak from the Moroccan Social Security. Its authors presented themselves as "Algerian patriots," but more than a year later it is still unknown who is really behind Jabaroot or if all the publications signed with that name come from the same group.

6 minutes

fotonoticia 20260710122904 1920
Add DEMÓCRATA to Google

Published

Last updated

6 minutes

Jabaroot has become one of the most enigmatic actors in the digital war surrounding Morocco. The name has now returned to the forefront after those operating under this identity have disseminated information about the Moroccan security apparatus and linked their latest publications to the Ceuta crisis, accompanying them with serious accusations against officials of the kingdom that, for the moment, have not been independently proven.

Presenting it simply as a "group of Algerian hackers" does, however, assume a mystery that remains open. The leaders of the first major operation of Jabaroot defined themselves as "Algerian patriots" and justified their actions as a response to Morocco, but the identity, composition, and location of their members have never been publicly accredited.

The uncertainty has increased over time. The original channel used by Jabaroot on Telegram disappeared and subsequently new accounts using the same name emerged. The messages also changed in tone and language. Therefore, there is also no certainty that those currently publishing under the Jabaroot brand are the same people who carried out the cyberattack that shook Morocco in April 2025.

What Jabaroot means and when it appeared

"Jabaroot" is an Arabic word that can be translated as "power," "might," or "domination". The first identity that gained notoriety used the name "JabaRoot DZ," incorporating the letters "DZ," an international code associated with Algeria. Later on, some publications began to appear simply signed as Jabaroot.

The group publicly burst onto the scene on April 8, 2025, when it claimed an operation against Moroccan institutions and a huge amount of information from the National Social Security Fund of Morocco (CNSS) began to be disseminated. The institution itself acknowledged having suffered attacks against its systems and Morocco opened an investigation into what happened.

Jabaroot presented that action as retaliation for alleged Moroccan attacks against Algerian institutions. From the beginning, therefore, the collective built its identity around the political rivalry between Algeria and Morocco, although that ideological statement does not constitute proof of who technically executed the attack.

The attack that exposed the data of millions of Moroccans

The operation against Social Security was what turned Jabaroot into a known name. The leak affected information corresponding to approximately two million workers and around 500,000 companies, with tens of thousands of documents that included salary, professional, and personal data.

The impact was especially strong because among the documentation appeared data related to important businessmen and people close to the Royal House. The publication allowed for the knowledge of salaries and other private information that until then remained within the Moroccan administrative systems and provoked a significant debate about the security of public databases in the country.

The existence of a breach was acknowledged, but that does not mean that every disclosed document can be automatically considered authentic. The CNSS itself warned at the time that part of the files circulating were inaccurate, incomplete, or could have been manipulated, a caution that continues to be relevant for assessing the subsequent publications attributed to Jabaroot.

From the cadastre and Justice to the security services of Morocco

After the April attack, new leaks related to other Moroccan agencies and personalities began to appear under the identity Jabaroot. Among the targets were the Property Conservation, structures related to Justice, and later, members of the security apparatus and the royal palaces.

The publications also began to acquire an increasingly political character. Jabaroot disseminated documents about properties and assets attributed to high-ranking Moroccan officials and later information about alleged members of the security services. In August 2025, the revelations reached people linked to the General Directorate of Territorial Surveillance (DGST), the powerful Moroccan domestic intelligence service.

Precisely the nature of some of those documents fueled doubts about the origin of the information. Le Monde pointed out that certain leaks seemed to come from internal material of the Moroccan apparatus itself, a circumstance that opened a second hypothesis about Jabaroot different from the exclusively Algerian explanation.

The rivalry between Morocco and Algeria behind Jabaroot

The operations attributed to Jabaroot cannot be understood outside of the profound confrontation between Morocco and Algeria. Both countries broke diplomatic relations in 2021 and maintain opposing positions on strategic issues, especially regarding Western Sahara.

Rabat defends its sovereignty over the territory and proposes a regime of autonomy under Moroccan sovereignty, while Algeria supports the Polisario Front. This rivalry has also moved to cyberspace, where actors presenting themselves as patriotic from both countries have carried out attacks, leaks, and retaliation campaigns.

Jabaroot has positioned its messages within that confrontation. The first major leak was presented as a response to actions against Algeria, and other subsequent operations have also incorporated political claims. The fact that its messages favor Algerian positions, however, does not allow us to conclude that the group depends on the Algerian state, something for which there is no conclusive public technical attribution.

The mystery: who is really behind Jabaroot?

The disappearance of the first Telegram channel further complicated any attempt at attribution. Other channels with the name Jabaroot then emerged, and actors linked to the pro-Algerian hacker ecosystem promoted some of those new accounts. But no continuity has been accredited among all of them.

Le Monde even detected differences between the different stages. The first messages were written exclusively in English, while later publications incorporated Arabic and French and adopted a considerably more political discourse. In the world of Maghreb hacktivism, changes of identity, impersonations, and the reuse of known names are common.

That is why there is another hypothesis that is even more delicate. The French newspaper reported on speculations about a possible settling of accounts within the Moroccan security apparatus itself, in a context of rivalries between the DGST, dedicated to internal affairs, and the DGED, responsible for external espionage. The theory of former members of the services established in Europe has also circulated. None of these hypotheses have been proven, and there is no public technical evidence that allows attributing them to Jabaroot.

Why Jabaroot has reappeared now due to the Ceuta crisis

The brand Jabaroot becomes relevant again in August 2026 after its latest publications have directly introduced Spain and Ceuta into its narrative against the Moroccan security apparatus.

Those currently using this identity attribute responsibilities to high-ranking Moroccan security officials regarding the recent migratory pressure on Ceuta and claim to have sensitive information about the structures that participated in it. They have also presented their data leaks of members of the security services as retaliation against those officials.

Here it is essential to separate the existence of documents from the interpretation that Jabaroot makes of them. There is currently no independent proof that demonstrates that the group's accusations about the organization of events in Ceuta are true. These are claims made by those who currently control its channels and need external corroboration before they can be presented as facts.

What we know about Jabaroot and what remains unproven

There are several sufficiently documented elements. An identity called JabaRoot DZ appeared publicly in April 2025; it presented itself as formed by "Algerian patriots"; claimed responsibility for the attack coinciding with a real breach in Moroccan Social Security; and subsequently, documents related to other institutions and members of the kingdom's security apparatus have been disseminated under the name Jabaroot.

What remains unproven is equally important. We do not know the identity of its members, we do not know if they receive instructions from any State, and it is also not accredited that all leaks signed as Jabaroot since 2025 come from the original authors. Suspicions about a Moroccan internal operation are hypotheses, not conclusions.

The same caution must be applied to Ceuta. That Jabaroot has previously demonstrated access to sensitive information increases the interest of its publications, but an authentic leak does not automatically make the accompanying political narrative true. The accusations against Moroccan officials and the Ceuta crisis must be supported by verifiable documents or independent investigations before they can be considered accredited.