The hacker group Jabaroot, which has once again come into focus due to the leak of information related to the security services of Morocco and their accusations about the migratory crisis of Ceuta, had previously been involved in another attack against a Moroccan institution months earlier. The National Cybersecurity Institute (INCIBE) documented in April 2025 a leak attributed to the group against the National Treasury of the Social Security of Morocco.
According to INCIBE, Jabaroot published on April 8, 2025 confidential data extracted from the Moroccan CNSS. The leaked information set included more than 53,000 files with records of nearly half a million companies and close to two million employees.
The documents contained, among other data, information about company affiliation, worker identification numbers, salaries, and contact details. INCIBE also noted that most of that data appeared to have been exposed in clear text on compromised servers.
INCIBE collected the political motivation attributed to the attack
The Spanish agency explained that, according to statements made by the threat actor itself, the leak of the Moroccan Social Security was due to a political motivation. Jabaroot presented the attack as retaliation for a previous incident against the X account of the Algerian Press Service.
That attack had been attributed by Jabaroot to actors linked to Morocco and the account was renamed "Sahara Marocain," in reference to the dispute between Morocco and Algeria over Western Sahara. Subsequently, the account was suspended.
After announcing the leak of the CNSS, Jabaroot also disseminated additional content on Telegram, including a screenshot that supposedly showed an attack against the website of the Moroccan Ministry of Labor. The group claimed that this action was part of a broader campaign in response to other incidents attributed to Moroccan hackers against Algerian institutions.
The current leak places Jabaroot back at the center of the case
The new appearance of the group occurs after Jabaroot disseminated data of members of the security services of Morocco and claimed to have a database with information on about 70,000 records. The group now links its activity to the migratory crisis in Ceuta and accuses those responsible in the Moroccan security leadership of having participated in the planning of the massive entry recorded on July 30.
Among the information attributed to Jabaroot are names and personal data of members of the General Directorate of Territorial Supervision (DGST), the Moroccan internal intelligence service, and of the General Directorate of National Security (DGSN), the country's police.
The exact dimension of this new leak requires caution. Available information indicates that Jabaroot has disclosed names and birth dates of some members of the Moroccan services and claims to have another database with around 70,000 records. There is no independent official confirmation that all those records correspond to intelligence agents or police officers.
The accusations about the massive entry in Ceuta
The organization directly points to Abdellatif Hammouchi, head of the DGST and the DGSN, and to Fouad Ali el Himma, one of the main advisors to King Mohamed VI, for their alleged role in the events in Ceuta.
According to messages attributed to the group, both would have participated in the planning of the operation that led to the massive entry of migrants into the autonomous city. These accusations come from the very group responsible for the leak and have not been independently verified.
Jabaroot also claims to have documentation that it has not yet made public and has announced that it could reveal the names of those who, according to its version, "orchestrated and coordinated the plan for Ceuta." The group also claims to have orders directed to agents who moved to Fnideq, the Moroccan town of Castillejos located next to the Ceuta border, before and during the events of July 30.