The Spanish services have been investigating since Monday the data leak of about 70,000 members of the security apparatus of Morocco and consider "true" the documents in this first phase of analysis, according to an exclusive publication by El Confidencial. The information affects personnel from the General Directorate of National Security (DGSN), the Moroccan Police, and the General Directorate of Territorial Surveillance (DGST), responsible for domestic intelligence.
The documentation, disseminated by the group of Jabaroot hackers through a public Telegram channel, contains names, identification numbers, recruitment dates, and, in some cases, ranks and banking data. Its publication now allows Spanish services to cross-check those identities with the information they already have and verify if any of them are linked to previous operations, contacts, or investigations.
Not all names correspond to intelligence agents. The list includes thousands of members of the DGSN, so only a part would belong to the DGST. It is precisely those identities that are of greater interest to the Spanish services, especially if any of those officials have maintained professional or operational contacts with Spain.
Spain tries to identify members of Moroccan intelligence
The investigation is still in an initial phase. The Spanish services are first working on authenticating the documents and identifying the people appearing in them, a process that becomes complicated when it comes to agents who may have used different names in their relations with foreign services.
"It serves us mainly to know if there may be any infiltrated agent in our services as a source, translator or, in a very, very hypothetical case, as a colleague [agent]," explains a source from a Spanish security agency to El Confidencial.
The cross-referencing of names with photographs and other data would allow verifying if any of them were already known in Spain under another identity or had participated in operations in which Spanish services intervened.
The leak may also serve to review relationships maintained so far with certain sources or collaborators. If one of the published identities had been used by Morocco in intelligence or counterintelligence operations, its exposure would force a reconsideration of those contacts.
Entries in Spain, hotels or vehicle rentals
Once the persons of interest have been identified, the Spanish security forces can check if there are records of their movements in Spain or if their names appear in previous police actions.
El Confidencial points out that the identified agents could be subject to indications that allow knowing their entries and exits from the country. Their identities could also be cross-referenced with the records available to the security forces, such as those related to hotel establishments or vehicle rentals.
Any investigation that required measures subject to judicial authorization would have to previously have the necessary indications and legal requirements.
The scope of the leak will therefore depend on how many of the identities can be verified and how many have connections of interest to Spain.
The problem for Morocco goes beyond the names
The publication of thousands of identities also raises a question within the Moroccan services themselves: how Jabaroot managed to access that information.
The documents could come from an intrusion into the computer systems or from a leak from within. El Confidencial indicates that the consulted sources believe that the database is slightly outdated, although that does not eliminate the risk posed by the exposure of its members.
If the origin was a cyber attack, Rabat will have to determine which systems were compromised and if the authors were able to access more documentation that has not yet been made public. An internal leak would pose a different problem, as it would imply that someone with access to sensitive information was able to extract it and deliver it to the group.
The question also extends to the material that has not been published. The dissemination of this database does not allow knowing if Jabaroot obtained other files or if any information may have reached third parties before appearing publicly on Telegram.
Jabaroot links the leak to the Ceuta crisis
The group disseminated the documents on Monday and presented the operation as retaliation against Morocco for the massive entries recorded in Ceuta at the end of July.
Jabaroot maintains that among the names are agents who would have worked in Europe and accuses them of participating in espionage operations, installing listening devices, and bribery. These claims come from the group itself and have not been independently verified.
The appearance of a person in the documents does not alone determine what functions they performed or whether they participated in operations outside of Morocco. That is one of the issues that the services analyzing the documentation will have to clarify.
El Confidencial identifies a dozen agents
The newspaper itself has cross-referenced the files with publicly available information and claims to have independently identified at least a dozen agents included in the lists.
Among them are, according to El Confidencial, heads of sensitive areas of the DGST, such as the director of human resources, the deputy director of counterintelligence, or the head of the Research Cell.
Some identifications have also been made based on the testimony of people who had direct contact with members of the Moroccan services. Journalist Omar Radi, imprisoned in Morocco in 2019 and released after receiving a pardon in 2024, has pointed out among the leaked names agents of the Judicial Police who participated in his interrogations.
The possibility of associating names with photographs, destinations, and functions allows for the reconstruction of part of a structure that usually remains outside public scrutiny.
Morocco had already suffered other leaks
The Moroccan services had faced other episodes of exposure of sensitive information in recent years, although not with the volume of data known this week.
In September 2025, Mohamed VI dismissed General Mostafa Rabil, then head of the General Directorate of Information Systems Security, after a succession of leaks and attacks against the country's agencies.
There is also a precedent of greater scope. In 2014, hundreds of documents and emails related to Moroccan diplomacy and foreign intelligence appeared on the internet.
The difference this time is in the content of the files: the documentation allows naming thousands of members of the security forces and, among them, members of the internal intelligence.
Silence in the main Moroccan media
The leak had been circulating for almost 48 hours when El Confidencial published its investigation without the main newspapers and television stations in Morocco having reported on it.
Some Moroccan media have since begun to question its scope. Médias24 claims that a significant portion of the names corresponds to members of the Police and suggests that Jabaroot may have gathered information from previously compromised databases.
While the exact origin of the files is determined, Spanish services continue to analyze their content to identify which names actually belong to Moroccan intelligence and which may be of interest to Spain.