Forgotten Dairies

The Spy List That Could Set Europe Ablaze -By Fransiscus Nanga Roka

The most dangerous weapon in Jabaroot may not be the stolen data. It is the uncertainty of that, because in hybrid warfare, doubt becomes a bullet itself.

Published

on

It may not need to be completely real for a spreadsheet to turn into a geopolitical weapon. All it needs is enough truth to put people in potential danger, just the right amount of fiction to confuse governments and such a level of vagueness as to make every denial look dubious.

The first reference, dated 24 August 2026, shows that Jabaroot claimed to have identified over 70,000 personnel associated with Morocco’s nation police and the national police of the DGST for domestic intelligence. The data allegedly included names, dates of birth, national ID numbers, banking information and details about their ranks and recruitment. They even included Abdellatif Hammouchi, the chief of both security institutions. (middleeasteye. net)

The who remains contested. Since 2025, the Arabic-influenced name Jabaroot—denoting dominance or power has been used against Moroccan institutions. At the time, it took credit for the CNSS social-security breach which had relatively little in terms of hardcore data to take away: just salary records of around two million workers. The group claims that that attack was a response to purported Moroccan cyberoperations against Algeria, but its affiliation has never been independently verified. (resecurity. com)

It makes for plausible but not proven Algerian involvement due to Rabat’s regional rivalry with Algiers. Another bombshell theory, detailed after an inquiry to Le Monde, focuses on five ex-Moroccan security officials living in post war Europe. If this is true, then we have gone from foreign cyberwarfare to an internal bedbugroar guided by insiders. Yet attributing state responsibility at this time would be irresponsible, until forensic evidence links them to the crime.

The why is openly political. And Jabaroot packaged the leak about the migration crisis in Ceuta as a kind of “gift” to Spain and Europe. The hackers claim that Moroccan intelligence is using migration as a tool to pressure Madrid, an accusation Morocco has denied and which Spanish Prime Minister Pedro Sánchez said so far lacks evidence. Despite that, recently declassified Spanish intelligence described a lack of pro-active measures by Moroccan border forces on July 30 during which over 70,000 people attempted to leave for Ceuta. (reuters. com)

Advertisement

The how is even less certain. Neither system for DGSN or DGST has been hacked, Morocco says According to authorities, the files were compiled from old payroll, insurance and social-security records then altered to appear like an active intelligence directory. Moroccan authorities too have invoked corpses, recruitment data predating 2020, issues of verb and fact and even ghost ranks.

The leak is much more serious than that weakness however. According to European analysts, many names appear to be real — albeit worn out. Even a payroll database that is compromised can still expose employment relationships, familial relationships and financial identifiers. Even the most stale information has an alarming ability to identify targets, facilitate coercion or provide a roadmap for operational networks targeted by hostile intelligence services, criminal organizations or violent extremists.

It is not mindless acceptance and it is not automatic rejection.

Morocco must open a fully independent forensic investigation with reputable European and African support, publicly disclose cryptographic proof of all compromised systems and inform every identifiable target at risk. Just because it says classified networks are secure does not address if some vulnerable insurers, payroll processors or health institutions have created an indirect map of the security state.

Spain, Morocco and Algeria should create an emergency cyber-deconfliction mechanism to preserve evidence, share technical indicators and ensure that settlements of unverified attribution does not escalate to retaliation. Europol will coordinate assessments of the risk for exposed persons living or working in Europe.

Advertisement

So, telegram and similar platforms should be made to retain relevant accounts (with voluntary sign-up) and corresponding metadata suitable for legal investigation; while journalists too have slice of responsibility — as they should redact personal identifiers (where appropriate) in such documents but also explicitly state what verified records versus claims by hackers are.

Third, Morocco should think of third-party data as within its national-security perimeter. It does not help to airgap an intelligence network if insurers and payroll contractors hold enough processing integrity to reconstruct the institution beyond it.

The most dangerous weapon in Jabaroot may not be the stolen data. It is the uncertainty of that, because in hybrid warfare, doubt becomes a bullet itself.

Fransiscus Nanga Roka

Faculty of Law University 17 August 1945 Surabaya and managing Partner Law Firm Victorious Indonesia

Advertisement

Leave a Reply

Your email address will not be published. Required fields are marked *

Exit mobile version