Listen to this Post
A Dangerous Claim Emerges From the Dark Web
A highly sensitive claim circulating on an underground cybercrime forum has raised concerns about the possible exposure of Moroccan intelligence and security personnel. A threat actor operating under the alias “Jabaroot” reportedly claims to possess a database containing approximately 70,000 records linked to Moroccan intelligence and security organizations.
The claim was highlighted on August 24, 2026, by Dark Web Intelligence and is being promoted under the banner OP_CEUTA, an apparent hacktivist operation with geopolitical overtones. The alleged dataset reportedly references personnel associated with Morocco’s General Directorate for Territorial Surveillance (DGST) and General Directorate of National Security (DGSN).
At this stage, however, the most important distinction is between a claim and a confirmed breach. The available material does not independently prove that 70,000 intelligence officers were exposed, that the database originated from DGST or DGSN systems, or even that every record belongs to an intelligence or security employee.
That uncertainty does not make the allegation unimportant. If even a portion of the database were authentic and current, the consequences could extend far beyond ordinary personal-data exposure.
What the Threat Actor Claims
According to the underground forum post described by Dark Web Intelligence, the actor claims to have obtained what is characterized as a “full database” containing information allegedly associated with Moroccan intelligence personnel.
The claimed figure of approximately 70,000 records immediately makes the allegation significant. But the number itself should not be interpreted as proof that 70,000 intelligence officers have been identified.
Large databases can contain duplicates, historical records, administrative personnel, contractors, retired employees, unrelated individuals, or information gathered from multiple public and private sources.
Therefore, the real question is not simply whether a database containing 70,000 records exists. The more important questions are where it came from, when it was created, what information it contains, and whether the information can be independently authenticated.
DGST and DGSN References Increase the Sensitivity
The allegation specifically mentions Morocco’s General Directorate for Territorial Surveillance (DGST) and General Directorate of National Security (DGSN).
References to these organizations make the claim considerably more sensitive because information connected to intelligence and national-security personnel can have consequences that differ dramatically from a conventional commercial data breach.
An ordinary leaked customer database may expose names, email addresses, telephone numbers, or purchasing histories. A genuine intelligence-personnel database could potentially expose identities, professional relationships, operational associations, locations, or other information that could assist surveillance, intimidation, targeting, or counterintelligence activity.
That is precisely why the authenticity and provenance of the alleged dataset require extraordinary scrutiny.
The OP_CEUTA Connection
The operation is being promoted under the OP_CEUTA banner, adding another layer to the story.
The reference to Ceuta is particularly notable because the Spanish autonomous city is located on the North African coast and has long been associated with political, territorial, and geopolitical tensions involving Morocco and Spain.
The use of a politically charged operation name may indicate that the alleged disclosure is intended not merely as a criminal monetization opportunity, but as part of an ideological or geopolitical campaign.
However, branding alone cannot establish the identity, nationality, political affiliation, or motivations of the person behind the account.
Who Is Jabaroot?
The actor reportedly uses the alias “Jabaroot,” while the forum account promoting the material is identified as “JBT2026.”
According to the information accompanying the original claim, the account was created in April 2026 and has published multiple posts.
Online commentary has attempted to associate Jabaroot with Algeria, with some users referring to the actor as “Jabaroot DZ.” Other comments go further by alleging connections to Algerian intelligence services.
Those allegations remain unverified.
Attribution in cyber operations is notoriously difficult. A threat actor can deliberately adopt another country’s identity, use infrastructure located elsewhere, operate through compromised systems, or cultivate a misleading persona to create geopolitical confusion.
Consequently, the nationality or institutional affiliation of Jabaroot should not be treated as established simply because anonymous accounts or commentary claim it.
A Screenshot Is Not Proof of a Breach
One of the most important details in the original report is also one of the easiest to overlook: the available screenshot does not independently establish the authenticity of the alleged database.
A screenshot can demonstrate that someone posted a claim.
It cannot, by itself, prove that the underlying records are legitimate.
It also cannot establish that the records were stolen directly from DGST or DGSN infrastructure.
This distinction is essential for responsible cybersecurity reporting.
The Difference Between a Data Leak and a Data Breach
A database appearing online does not automatically mean the organization named in the post was hacked.
Data can reach underground markets through numerous routes.
It may have been stolen during a direct network intrusion. It could have originated from a contractor, supplier, government partner, exposed cloud storage system, compromised employee account, insider, third-party application, or previously leaked dataset.
It could also be fabricated or assembled from older information.
For that reason, investigators need to establish provenance before identifying a particular government organization as the source of the compromise.
Why 70,000 Records Could Be Misleading
The headline figure of 70,000 records sounds definitive, but record counts often conceal important details.
A database with 70,000 entries might contain only a fraction of genuinely unique individuals. Records may be duplicated across different systems or represent historical snapshots of the same person.
Some entries could also refer to administrative employees or individuals who have no intelligence responsibilities whatsoever.
The dataset could even combine information from unrelated sources.
Consequently, researchers should avoid translating “70,000 records” directly into “70,000 intelligence officers.”
What Information Would Matter Most?
The sensitivity of the alleged leak depends heavily on the fields contained within the database.
Names alone would already create privacy concerns, but additional information could dramatically increase the risk.
Potentially sensitive fields could include employment identifiers, government credentials, telephone numbers, addresses, family information, photographs, organizational roles, internal identification numbers, email addresses, security clearances, locations, or employment histories.
Even apparently harmless metadata can become dangerous when combined with information from other datasets.
The Counterintelligence Risk
If authentic information about intelligence personnel has been exposed, the incident could become a counterintelligence problem rather than merely a cybersecurity breach.
Identifying personnel connected to intelligence and security institutions could help hostile actors map organizational structures.
Even partial information could potentially be combined with social-media profiles, corporate records, property databases, previous leaks, travel information, and other open-source intelligence.
The value of such information may therefore increase over time as separate datasets are correlated.
The Personal-Safety Dimension
The alleged exposure also raises personal-security concerns.
Security personnel whose identities become public could potentially face harassment, intimidation, surveillance, or targeted social-engineering attempts.
Family members could also become indirectly exposed if personal information is sufficiently detailed.
This is one reason researchers should avoid unnecessarily republishing alleged identities while an investigation is still underway.
Responsible threat intelligence should focus on understanding the incident without amplifying potentially harmful personal information.
Could This Be an Old Database?
Another possibility investigators must consider is that the alleged database may not be recent.
Threat actors frequently advertise older datasets as new material because historical data can still appear valuable.
A database from several years ago may contain people who have changed positions, left government employment, moved locations, or had their information updated.
Determining the freshness of the alleged records is therefore as important as determining their authenticity.
Could the Dataset Have Come From a Third Party?
A compromise involving government personnel does not necessarily mean government infrastructure was directly breached.
Third-party systems can hold enormous amounts of sensitive information.
Recruitment platforms, payroll providers, identity-management systems, contractors, telecommunications providers, government suppliers, cloud services, and external portals may all contain employee information.
If the alleged database proves authentic, investigators should examine the entire supply chain rather than focusing exclusively on DGST or DGSN networks.
The Insider Threat Cannot Be Ignored
Another possible scenario is an insider compromise.
An employee or contractor with legitimate access could potentially copy information without exploiting a sophisticated vulnerability.
That would create a very different investigation from an external ransomware or intrusion campaign.
Investigators would need to examine access logs, database queries, unusual downloads, authentication events, privilege changes, endpoint activity, and account behavior.
Attribution would then depend heavily on forensic evidence rather than the threat actor’s public narrative.
The Possibility of Fabrication
Fabrication must also remain on the table.
Threat actors sometimes create convincing-looking samples to attract attention, damage an organization’s reputation, pressure a victim, gain followers, or increase the perceived value of future releases.
A small number of genuine records can also be mixed with fabricated entries to make a false database appear authentic.
For that reason, independent sampling and verification are essential.
What Researchers Should Validate
The first investigative priority should be dataset provenance.
Researchers should determine whether sample records correspond to real individuals, whether the information is internally consistent, whether timestamps indicate recent collection, and whether unique identifiers match independent sources.
The second priority should be identifying whether the alleged data has appeared elsewhere.
Comparing samples against historical breach datasets can help determine whether the material is genuinely new or simply repackaged.
Infrastructure Tracking Could Reveal More
Investigators should also monitor the infrastructure associated with Jabaroot and the JBT2026 account.
Changes in usernames, cryptocurrency addresses, file-hosting services, domains, messaging accounts, forum identities, and previously used infrastructure can sometimes reveal connections between apparently separate campaigns.
However, infrastructure overlap should be treated carefully because cybercriminals can share hosting services or deliberately reuse infrastructure to mislead investigators.
The Geopolitical Angle
The OP_CEUTA branding gives the allegation a potentially geopolitical dimension.
Cyber operations linked to territorial disputes or political conflicts can serve several purposes at once: propaganda, intimidation, intelligence gathering, reputational damage, or disruption.
The operation could be genuinely ideological.
It could also be financially motivated but wrapped in political branding.
Or the geopolitical narrative itself could be part of an attribution strategy designed to make investigators suspect a particular country.
Without forensic evidence, none of these explanations should be treated as conclusive.
Deep Analysis: Why This Claim Matters
The Number Is Less Important Than the Provenance
The figure of 70,000 records is attention-grabbing, but provenance is the real story. Investigators need to know how the information was obtained and whether it originated from a protected Moroccan government system.
Intelligence Data Has a Different Threat Profile
A leak involving intelligence personnel can have consequences beyond identity theft. Information can potentially be used for surveillance, recruitment attempts, intimidation, or operational targeting.
Metadata Can Become Intelligence
Even fields that appear mundane can reveal organizational structures when analyzed collectively. Job titles, departments, locations, timestamps, and reporting relationships can expose patterns.
Cross-Dataset Correlation Raises the Risk
Attackers rarely depend on one database. A leaked government dataset can become substantially more valuable when combined with older breaches, social-media information, public records, and commercially available intelligence.
Attribution Is Especially Difficult
The apparent use of Algerian branding or references does not establish that the actor is Algerian. Cyber personas are easy to manipulate.
False Flags Are a Real Possibility
Threat actors can intentionally create narratives pointing toward another country or organization. Investigators should therefore separate technical attribution from political speculation.
The
The reported creation of the JBT2026 account in April 2026 provides a starting point for behavioral analysis. Previous posts could reveal whether this is an established operation or a newly constructed identity.
Historical Activity Could Establish Credibility
Researchers should examine whether previous Jabaroot claims were independently validated. A record of accurate disclosures would not prove this claim, but it could help assess the actor’s credibility.
Sample Data Should Be Tested
If samples become available, researchers should verify selected fields against independent sources while avoiding unnecessary publication of personal information.
Duplicate Detection Is Essential
A database containing tens of thousands of records may contain repeated entries. Counting unique individuals rather than raw rows would produce a more meaningful assessment.
Freshness Can Change the Entire Story
A decade-old dataset and a database collected last month represent very different security events, even if they contain the same number of records.
Government Compromise Is Not Yet Established
The claim should not be described as a confirmed DGST or DGSN breach unless technical evidence connects the database to those organizations.
Third Parties Need Investigation
Government contractors and external service providers can sometimes possess sensitive employee information. Investigators should examine these possibilities.
Insider Access Should Be Considered
A legitimate user accessing large amounts of information could potentially create the same final dataset as an external attacker.
Cloud Exposure Is Another Possibility
Misconfigured storage, exposed databases, stolen cloud credentials, and compromised identity systems can all result in large-scale data exposure without a traditional malware infection.
Credential Reuse Could Expand the Damage
If the alleged dataset contains authentication-related information, attackers could potentially use it for phishing or account-takeover campaigns.
Social Engineering Could Become the Next Threat
Once attackers know the identities and organizational roles of security personnel, convincing impersonation attempts become easier.
Targeted Phishing Becomes More Credible
Detailed employee information can help attackers construct highly convincing messages that appear to come from colleagues, government departments, or trusted partners.
Family Information Would Increase Risk
If personal or family details are included, the threat could extend beyond employees to relatives and close contacts.
Operational Security Could Be Affected
If current personnel, assignments, or organizational relationships are exposed, the information could potentially undermine operational security.
Retired Personnel Could Still Matter
Historical employee records may reveal organizational relationships and career histories even if the individuals are no longer serving.
Database Structure Can Reveal Its Origin
Technical details such as table names, field naming conventions, internal identifiers, timestamps, and database schemas can sometimes provide clues about the source.
File Metadata Can Also Help
Creation dates, export formats, software fingerprints, and other metadata may help investigators determine how a dataset was generated.
The Threat
Claims of possessing a “full database” are common in underground forums and should be treated as marketing language until technical evidence supports them.
Forum Reputation Is Not Proof
An
Public Attention Can Benefit Attackers
High-profile coverage can increase the perceived value of a dataset and potentially encourage buyers or additional participants.
Researchers Should Avoid Amplification
Publishing unverified personal information can create additional harm without improving the investigation.
Authorities Would Need Technical Evidence
A genuine investigation would likely require server logs, authentication records, endpoint telemetry, database activity, network evidence, and potentially evidence from compromised infrastructure.
A Leak Could Have Multiple Sources
The same information may exist across several systems. Finding the data online does not automatically reveal which system was compromised.
The Incident Could Become a Supply-Chain Investigation
If a contractor or service provider is identified as the source, the consequences could extend to other organizations using the same platform.
Political Claims Require Extra Caution
Attributing the activity to Algeria, Morocco, or any government without forensic evidence risks turning a cyber investigation into unsupported geopolitical speculation.
Jabaroot’s Future Releases May Be Important
Additional samples, files, or claims could provide investigators with more evidence about the dataset and the operation.
A Partial Leak Could Still Be Serious
Even if the 70,000-record figure is exaggerated, a smaller authentic dataset involving security personnel could still represent a significant security incident.
Authenticity Should Be Treated as a Spectrum
The dataset could be completely genuine, partially genuine, outdated, recycled, fabricated, or a combination of real and false information.
Independent Verification Is the Turning Point
The story changes fundamentally if independent researchers confirm unique, recent, non-public information that can only reasonably originate from a protected source.
The Biggest Risk Is Premature Certainty
At this stage, the strongest conclusion is not that Morocco suffered a confirmed breach. The strongest conclusion is that a threat actor has made an unusually serious claim that warrants investigation.
What Organizations Can Learn
Government organizations and security agencies should assume that personnel information can become a high-value target and should minimize unnecessary exposure, strengthen identity controls, monitor unusual database access, and segment sensitive systems.
What Security Teams Should Monitor
Defenders should watch for unusual authentication activity, bulk database queries, privilege escalation, unexpected exports, compromised employee accounts, suspicious cloud activity, and phishing campaigns targeting personnel.
What the Public Should Understand
The presence of a claim on an underground forum does not make the claim true. Cybersecurity reporting must distinguish between allegations, evidence, and confirmed incidents.
The Broader Lesson
The alleged Jabaroot database highlights a growing reality of modern cyber conflict: information about people can sometimes be more strategically valuable than information about machines.
What Undercode Says:
The Claim Is Serious, But It Is Still a Claim
The alleged exposure of 70,000 Moroccan intelligence and security personnel would be an exceptionally serious incident if verified. But responsible reporting requires a clear separation between what has been claimed and what has been demonstrated.
The Most Important Missing Evidence Is Provenance
The central unanswered question is where the alleged database came from. Without provenance, it is impossible to confidently connect the material to DGST, DGSN, or any other Moroccan government infrastructure.
Seventy Thousand Records Should Not Be Translated Into Seventy Thousand Officers
The number could represent database rows rather than unique people. It could include duplicates, historical information, administrative staff, contractors, or unrelated records.
The Political Narrative Is Not Enough
The OP_CEUTA branding may suggest ideological motivation, but branding does not prove the actor’s political affiliation or nationality.
Claims About Algeria Require Independent Evidence
Online commenters have attempted to identify Jabaroot as Algerian and even suggested intelligence-service involvement. Those claims should remain unverified unless supported by credible technical or intelligence evidence.
Attribution Should Follow Evidence
A responsible investigation would examine infrastructure, operational behavior, malware, account history, cryptocurrency activity, technical fingerprints, and other evidence before making attribution claims.
The Potential Human Impact Is Enormous
If current security personnel are genuinely exposed, the danger could involve targeted harassment, surveillance, impersonation, social engineering, and physical-security concerns.
The Dataset Could Be More Valuable Than Its Headline Suggests
Even a smaller authentic dataset could reveal relationships between departments and personnel. Such information can become more valuable when combined with other datasets.
The Supply Chain Deserves Attention
Investigators should not assume that a government network itself was breached. Contractors, cloud platforms, recruitment systems, identity providers, and other third parties may hold sensitive information.
An Insider Scenario Cannot Be Excluded
A malicious or compromised insider could potentially obtain large quantities of information without exploiting an external vulnerability.
Recycled Data Is Another Major Possibility
Underground actors frequently reuse historical data. Establishing the age of the records will therefore be critical.
The
Additional releases, samples, technical documentation, or proof-of-access material could either strengthen or weaken the credibility of the current claim.
Researchers Should Verify Without Spreading Personal Data
Verification can be performed through controlled sampling and independent checks without publishing sensitive identities or information unnecessarily.
The Screenshot Proves Very Little
The existence of a forum post proves that someone made the allegation. It does not prove that the underlying database exists or came from the organization being named.
This Could Be a Propaganda Operation
A politically themed cyber persona may be seeking publicity, intimidation, or geopolitical influence rather than simply selling stolen information.
It Could Also Be a Genuine Breach
The possibility of authenticity should not be dismissed simply because the claim is politically framed. Both possibilities must be investigated.
The Correct Position Is Uncertainty
At present, the evidence supports describing this as an alleged database exposure, not a confirmed breach of Moroccan intelligence infrastructure.
The Investigation Should Focus on Technical Evidence
Network telemetry, database logs, access records, cloud activity, authentication data, and endpoint evidence would be considerably more valuable than social-media speculation.
The Real Story May Evolve Quickly
If credible samples emerge, the assessment could change rapidly. Conversely, if samples fail verification or are found to be recycled, the claim could lose much of its credibility.
Cybersecurity Reporting Has a Responsibility
Publishing an unverified allegation as fact can cause unnecessary panic and potentially amplify the threat actor’s objectives.
The 70,000 Figure Needs Independent Validation
The number should be treated as an allegation until researchers can establish the number of unique, relevant, authentic records.
Sensitive Personnel Require Special Protection
Security organizations should assume that employee data can be targeted for intelligence purposes and should protect personnel information accordingly.
The Broader Threat Is Information Fusion
Attackers increasingly combine information from different sources. A single database may become dangerous when correlated with other leaked and publicly available information.
The Claim Demonstrates Why Identity Security Matters
Organizations often focus heavily on protecting infrastructure while underestimating the intelligence value of employee information.
The Political Context Makes Verification Even More Important
Because Morocco-Algeria relations are politically sensitive, unsupported attribution could have consequences beyond cybersecurity.
A False Flag Could Be Deliberate
An attacker may deliberately create evidence pointing toward another actor to generate confusion or political tension.
A Genuine Attribution Would Require Multiple Signals
No single username, language pattern, IP address, or forum statement should be considered sufficient attribution.
The Account History Is Worth Investigating
The JBT2026
The Threat Should Be Monitored
Even without confirmation, the claim deserves continued monitoring because subsequent releases may reveal whether the actor actually possesses meaningful data.
The Most Dangerous Scenario Is Authentic and Current Data
If the dataset contains current, non-public information about active security personnel, the consequences could be substantially more serious than an ordinary personal-data breach.
A Smaller Authentic Leak Would Still Matter
Even if only a few thousand records prove genuine, the incident could remain strategically significant because of the type of individuals allegedly involved.
The Claim Should Not Be Ignored
Unverified does not mean irrelevant. It means the available evidence is insufficient to make a definitive conclusion.
The Claim Should Not Be Overstated
Equally, an underground forum post should not become a confirmed government breach simply because the headline is dramatic.
Verification Is the Key Next Step
Independent researchers, affected organizations, and authorities should focus on validating samples, determining provenance, establishing freshness, and identifying the actual access path.
The Bottom Line
Jabaroot’s alleged 70,000-record Moroccan intelligence database is a serious and potentially consequential claim, but there is currently insufficient evidence in the supplied material to confirm the alleged breach or identify the actor’s true affiliation.
✅ Claim status: The available information supports reporting that Jabaroot claimed to possess approximately 70,000 records associated with Moroccan intelligence and security personnel; it does not independently confirm the database's authenticity.
✅ Organizations named: The allegation specifically references Morocco’s DGST and DGSN, but the supplied material does not establish that either organization was directly compromised.
❌ Attribution: Claims that Jabaroot is Algerian or connected to Algerian intelligence services remain unverified and should not be presented as established fact without independent evidence.
Prediction
(-1) The claim will likely generate additional geopolitical and cybersecurity speculation before its authenticity is established. The OP_CEUTA branding and online discussion create conditions for rapid attribution claims, particularly involving Morocco and Algeria.
(-1) If authentic, the most immediate danger could shift from data theft to targeted intelligence gathering. Detailed information about security personnel could enable phishing, impersonation, surveillance, and social-engineering campaigns.
(+1) Independent verification will likely become possible if the actor releases additional samples. A larger sample containing unique, recent, non-public information would provide researchers with stronger evidence for assessing provenance.
(+1) Security researchers are likely to focus increasingly on the actor’s infrastructure and historical activity. Previous claims, account behavior, file-hosting patterns, and technical indicators could help establish whether Jabaroot is a credible threat actor or a newly constructed persona.
(-1) If the dataset is old or recycled, the headline figure may prove substantially more misleading than it initially appears. Historical records can be repackaged as new breaches, particularly when the threat actor wants maximum attention.
(+1) The incident will likely reinforce the importance of protecting government personnel databases as intelligence assets. Even without confirmation of this particular claim, the alleged operation demonstrates how employee information can become strategically valuable in politically motivated cyber campaigns.
▶️ Related Video (76% Match):
🕵️📝Let’s dive deep and fact‑check.
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
References:
Reported By: x.com
Extra Source Hub (Possible Sources for article):
https://www.quora.com
Wikipedia
OpenAi & Undercode AI
Image Source:
Unsplash
Undercode AI DI v2
🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]
📢 Follow UndercodeNews & Stay Tuned:
𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon | 📺Youtube




