SATURDAY, OCTOBER 10, 2026|No. 18148
Technology · Cybersecurity · Morocco

Morocco Faces Wave of Cyberattacks Amid Rapid Digitalization

A series of cyberattacks targeting Moroccan institutions highlights the security gaps that accompany the country's rapid digital transformation, experts say.

Morocco's rapid digitalization has exposed vulnerabilities, as seen in recent cyberattacks on government databases.
Morocco's rapid digitalization has exposed vulnerabilities, as seen in recent cyberattacks on government databases.
1 sources
Pipeline ingest
3 reads
Positive / Neutral / Negative
1 countries
Related coverage

Cyberattacks targeting Morocco: the paradox of digitalization without security maturity (Opinion)

The wave of cyberattacks targeting Moroccan institutions, platforms and data does not contradict the Kingdom's digital transformation. It reveals its new threshold of requirement. As public services, registers, procedures and infrastructures become digital, their protection becomes a condition of trust, continuity and sovereignty. Artificial intelligence now adds an additional rupture: it makes the attack accessible to inexperienced profiles and multiplies the power of seasoned actors. Cybersecurity can therefore no longer be treated as an IT subject. It becomes a public policy of resilience.

A few dozen months ago, during a meeting with the head of a public institution, the question of cyberattacks was insistently raised. Other organizations had already been targeted. Had his institution taken the lead? The answer was categorical: significant investments had been made, the systems existed, the risk seemed under control. What he did not know, at that very moment, was that terabytes of his institution's data were being silently siphoned off. He was not entirely wrong: his own system held up. But one of his subcontractors, vulnerable, had opened access to his entire architecture. An institution can strengthen its own systems and still remain exposed by a subcontractor, a poorly maintained component, a third-party access, a human flaw or an insufficiently compartmentalized architecture. In cyberspace, the strength of an actor depends on the least prepared link in its ecosystem.

It is this reality that gives the recent attacks their scope. They do not say that Morocco has remained idle. They show that a country that rapidly digitizes its services mechanically increases the strategic value of its data. The Kingdom has taken a step in digitalization. It must now take the same step in protection, governance and resilience.

A succession of attacks that changes scale

The recent sequence opens in April 2025. A group of hackers calling themselves Jabaroot publishes on Telegram nearly two million personal data attributed to the National Social Security Fund. The claimed volumes also mention several hundred thousand companies. As always in this type of affair, the figures from claims must be handled with caution until they are established by official or independent expertise. The public effect, however, is immediate: social data becomes a pressure tool.

In June 2025, the National Agency for Land Conservation, Cadastre and Cartography (ANCFCC) is in turn cited in leak claims, with more than 4 terabytes of data presented as exfiltrated. The nature of the documents mentioned changes the gravity of the episode. Certificates of ownership, deeds of sale, notarized contracts or patrimonial elements do not have the same status as an ordinary administrative database. They affect legal security, land trust and sometimes the economic privacy of the individuals concerned.

Other attacks or disclosures then targeted infrastructures such as the websites of the Ministry of Economic Inclusion, Small Business, Employment and Skills, as well as social organizations. In January 2026, during the 2025 Africa Cup of Nations, the Royal Moroccan Football Federation is targeted. Then, in March and April 2026, the National Fund for Social Welfare Organizations (CNOPS) is in turn cited among the organizations hit, with several million members potentially affected.

At the same time, a separate wave hits the National Commission for the Control of the Protection of Personal Data (CNDP), the site of ENCG Kenitra and the AI Movement platform of UM6P. More recently, deeds of sale involving public figures and businessmen, powers of attorney and notarized contracts from the Tawtik platform, administered by the ANCFCC in conjunction with the National Council of the Order of Notaries, are leaked on the dark web. On May 18, 2026, more than 690,000 lines attributed to the civil status platform Watiqa.ma are disseminated on Telegram.

This chronology is not a simple addition of incidents. It shows a change of scale. The targets are varied, but the mechanism is common: the technical attack becomes an attack on trust. It targets not only a server. It affects the continuity of service, the reputation of an institution, the safety of citizens and the perception of the public capacity to protect what has been digitized.

The paradox of a solid framework and uneven resilience

The first lesson lies in a paradox. Morocco has a recognized institutional and regulatory framework. According to the cybersecurity index of the International Telecommunication Union, the Kingdom scores 97.5 out of 100 in 2024, one of the best in the world. It is also cited as a regional leader in Africa and ranked 34th globally in the Global Cybersecurity Index. These results are not decorative. They reflect real efforts: national strategy, legal framework, specialized structures, central role of the National Directorate for the Security of Information Systems (DGSSI), presence of maCERT and the rise of governance mechanisms. But a framework is not enough to absorb an attack. Compliance measures the existence of rules, institutions and mechanisms. Resilience is verified in reaction times, quality of backups, compartmentalization of databases, continuous supervision, crisis communication and the ability to restore a service without aggravating the risk. That is where the heart of the matter lies.

Morocco does not suffer from a lack of digital maturity. It faces the classic challenge of countries that digitize quickly: the attack surface sometimes grows faster than protective reflexes. Each platform put online, each digitized register, each interconnected base creates an efficiency gain. They also create a new strategic object. Public data is no longer just a management tool. It becomes a resource of power. This resource can be sold, fragmented, enriched, cross-referenced, used for phishing, impersonation, extortion, fraud or propaganda. Hacked data is rarely disclosed all at once. It sometimes circulates in closed spaces, is resold on the dark web in untraceable cryptocurrencies, then reappears at the moment when its dissemination produces the greatest media or political effect. When a hostile actor seeks to destabilize a state, it doses the revelations to maintain a lasting climate of suspicion. The public leak is often only the visible part of a much older compromise.

Weaknesses that feed each other

The diagnosis does not lie in a simple accusation. It rests on weaknesses that reinforce each other. The most visible concerns old, heterogeneous or insufficiently maintained systems. Experts regularly point to phishing as the preferred entry vector. Emails imitating clients, suppliers or official services lead an employee or civil servant to open a trapped attachment or click on a link, triggering a ransomware or an intrusion. In some cases, a critical vulnerability in a third-party provider, such as Oracle, whose authentication flaw had been reported in March 2025, has also been considered among the technical hypotheses. This point must remain formulated as a hypothesis as long as no official attribution establishes it.

The subcontracting chain prolongs this exposure. In the case of the CNDP, the incident was associated with an outdated plugin on the site, a basic maintenance flaw. More broadly, each entrusted access, each open interface, each technical account and each component installed at a subcontractor becomes a point of vigilance. Digital transformation requires integrators, hosts, maintainers, cloud providers and external developers. This outsourcing is normal. It becomes vulnerable when it is not framed by strict contractual requirements, regular audits, effective logging, incident notification and fine-grained access control.

Yet the gap between regulation and operational reality precisely maintains this risk. The UIT score of 97.5 out of 100 testifies to a serious commitment. It also reminds that an index measures a framework, not always the daily robustness of each application. The real test lies in patches applied on time, tested backups, segmented databases, revised rights, processed alerts and repeated crisis procedures. An untested backup is not a protection. It is a promise.

Massive outsourcing adds its own part to the picture. According to the 2025 Barometer of AUSIM, 64% of Moroccan companies outsource their cybersecurity. This orientation can be effective when based on qualified providers and demanding contracts. It becomes risky if it creates delegation without control, if third-party accesses are not inventoried, if responsibilities are not clarified or if incidents are not reported quickly.

Finally, artificial intelligence modifies the very economy of cyberattack. Phishing campaigns can now be written in very credible French, Arabic or English. Scripts can be generated, adapted or improved faster. Target reconnaissance can be automated. Voice or video deepfakes open new forms of identity theft. For beginner profiles, AI lowers the barrier to entry. For experienced groups, it acts as a power multiplier. The threat becomes not only more frequent. It becomes industrial.

Cybersecurity becomes a governance culture

Cybersecurity has long been seen as a domain reserved for IT departments. This reading is no longer sufficient. Security concerns the lawyer who validates a subcontracting contract, the business manager who requests a new access, the agent who receives a suspicious email, the director who allocates a budget, the communicator who must inform without minimizing or panicking, and the leader who assumes the continuity of a public service. The Director General of the DGSSI insisted, during GITEX Africa 2026, on challenges that go beyond the technical framework to directly touch sovereignty. Cybersecurity is no longer an operating cost. It becomes a condition of operational sovereignty, because it decides a country's ability to protect its data, its services, its citizens and its major events.

The DGSSI, placed under the Administration of National Defense, has historically a demanding security culture and plays a central role in the protection of sensitive information systems. Recent changes in its status must be understood in this logic: strengthening the attractiveness of the institution, broadening the national pool of expertise and integrating more specialized profiles from diverse backgrounds, without opposing military and civilian skills. The issue is not to suggest that skills are lacking. It is to recognize that the demand for cybersecurity grows everywhere in the world faster than available pools. Profiles in audit, forensics, incident response, cryptography, cloud security, application security, data governance or industrial protection are sought by all states and all large companies. For Morocco, consolidating these skills becomes a strategic imperative.

This consolidation cannot rely solely on the state. It requires a complete sector: initial training, continuing education, university laboratories, engineering schools, specialized startups, qualified providers, security operations centers, audit capabilities, international partnerships and a culture of cyber hygiene in administrations and companies.

Specialized young companies have a role to play here. Some face barriers to entry in public and private markets: insufficient seniority, lack of volume references, unreached engineer thresholds. Yet their main strength lies precisely in mastery of the state of the art and in permanent updating, because each day brings its share of new threats. The question is not to reduce security requirements, but to find mechanisms to frame these emerging skills and gradually integrate them into public and private procurement when they are technically sound.

Thinking about the geopolitical dimension without haste

The recent attacks cannot be isolated from the strategic context in which they appear. The claim against the CNSS came after the reaffirmation by the United States of Moroccan sovereignty over the Sahara. That against the ANCFCC occurred the day after British support for the Moroccan autonomy plan. This concomitance raises legitimate questions. It does not, by itself, constitute proof of a sponsor. Serious analysis must hold two requirements together: not ignore the possible geopolitical dimension, but not transform a correlation into certainty. Cyberspace blurs responsibilities. Criminal groups, influence relays, opportunistic actors, hacktivists and sometimes hostile powers can cross paths without leaving a simple signature.

What can be said with caution is that some campaigns mix computer hacking and politically targeted communication. Stolen data is sometimes accompanied by accusations, threats of new leaks or narratives of moralization. The objective is no longer just to steal. It may be to discredit decision-makers, to demonstrate an alleged incapacity of the state, to create a climate of mistrust or to maintain suspicion in public opinion. The exposure of real estate assets or semblances of conflicts of interest weakens the legitimacy of public actors, regardless of the veracity of the leaked documents.

It is here that data becomes a narrative weapon. A deed of sale, a pay slip, a power of attorney, a social record or a compromised identifier can be taken out of context, combined with other elements, then projected into the public space to produce a political effect. The veracity of a document is not enough to establish the veracity of the narrative that accompanies it. The real risk lies in this superposition of data, suspicion and virality.

What needs to be secured now

In the short term, the priority is to reduce the attack surface. This involves auditing third-party accesses and cloud providers, reviewing technical accounts, systematically enabling multi-factor authentication on critical systems, hardening exposed interfaces, compartmentalizing sensitive databases and rigorously applying security patches. No plugin, component or exposed service should remain in production without documented maintenance follow-up.

However, reducing the attack surface is not enough if the restoration capacity remains theoretical. An organization must know where its data is, how it is backed up, at what frequency, in what form, with what level of encryption and within what timeframes it can be restored. Restoration exercises must become regular practices, not exceptional operations triggered after the crisis.

Crisis communication completes this system. Many organizations worsen the situation by minimizing too quickly, speaking too late or using formulations that will be contradicted by new publications. Several institutions have claimed that only public data was exposed, only to be caught up shortly after by the disclosure of private documents. This inconsistency in communication aggravates the perception of powerlessness as much as the attack itself. Cyber crisis communication must be prepared in advance, tested and calibrated to inform without weakening.

In the medium term, the effective application of Law 05-20, the National Directive on the Security of Information Systems and audit mechanisms must become more homogeneous. External providers must be subject to precise contractual requirements: logging, incident notification, regular tests, security clauses, reversibility, encryption, localization or control of data when the level of sensitivity requires it. Mandatory audits by qualified PASSI providers and systematic notification of incidents to maCERT must become structuring reflexes.

It is also necessary to strengthen incident response teams. The maCERT plays an essential national role, but the most exposed sectors would benefit from having specialized capabilities: health, finance, land, education, local authorities, sports, transport, energy and major events. Cybersecurity becomes more effective when it descends closer to the professions. In the long term, the National Cybersecurity Strategy 2030 must be an opportunity to treat cyber defense as a component of national sovereignty. Governance, skills, legal framework, international cooperation, local innovation and citizen awareness are not separate components. They form a single architecture of trust.

The whole world faces the same test

International comparison relativizes the Moroccan case without excusing it. Major powers suffer the same challenges. In France, the data leak associated with France Travail potentially affected 43 million people. The Family Allowance Fund was also compromised in 2024. In 2026, the French ANSSI was still handling 218 incidents affecting local authorities, representing 14% of national reports. The United States, the United Kingdom, Germany, Australia or Japan face repeated attacks against their hospitals, administrations, universities, strategic companies and local communities. Cyber risk accompanies the digitization of services. The more a country digitizes, the more digital value it creates, and the more attractive this value becomes for cybercriminals, influence groups and hostile actors.

Morocco also pays the price for its advances. According to the Allianz Global Insurance 2025 report, it is among the 23 countries most exposed to cyber threats, with a singular position in the Maghreb-MENA space. This data must be read with caution, according to the report's methodology, but it confirms a trend: exposure increases with the importance taken by digital services, administrative data and connected infrastructures. The difference between countries often lies less in the absence of attacks than in the depth of means, the culture of notification, the speed of reaction, the quality of communication and the ability to learn after an incident. In the most mature systems, the attack is not always avoidable. What is expected is early detection, damage limitation, rapid restoration, controlled transparency and documented correction of flaws.

The cost of inaction exceeds that of prevention

Robust cybersecurity requires resources. On a global average, the share of IT budget allocated to cybersecurity is estimated at around 5.6%. Experts often recommend a range of at least 5 to 10% of the IT budget, depending on the criticality of activities. For Morocco, several orders of magnitude allow measuring the effort to be accomplished. At the central public level, sensitive ministries and agencies would each need an annual budget adapted to their criticality. The suggested orders of magnitude range from 20 to 80 million MAD per sensitive entity, i.e., a national range of 2 to 4 billion MAD per year for the central administration. These amounts should not be read as a uniform expenditure, but as a level of effort compatible with the growing criticality of systems.

An exceptional upgrade investment could cover a national SOC (Security Operations Center), the overhaul of aging architectures, mass training, audit of the entire fleet, modernization of backups, hardening of accesses and incident response capabilities. A credible plan could require an investment of 15 to 25 billion MAD over four years, i.e., 1.5 to 2.5 billion dollars, compared to the 150 billion euros invested in public cybersecurity by the European Union in its 2021-2027 plan.

The cost of non-action is higher. For comparison, losses related to cybercrime in Africa jumped from 192 million dollars in 2024 to 484 million in 2025, the number of victims having more than doubled. This figure is probably underestimated, because several entities, particularly in the banking and insurance sectors, victims of ransomware, prefer to pay to recover their data and keep the incident quiet rather than compromise their reputation. The cost of inaction always exceeds that of prevention, in a ratio of at least one to five.

Understanding the modus operandi without dramatizing it

Phishing remains one of the most commonly used techniques. A message imitates a supplier, a client, an administrative service or a colleague, then pushes the victim to click on a link, open an attachment or enter their credentials. Once access is obtained, the attacker can progress in the system, search for data, create new accesses or prepare exfiltration.

Attacks through the subcontracting chain are also feared. They consist of reaching an organization via a subcontractor, a shared tool, a maintenance interface or a third-party component. Persistent attacks, often qualified as APT when sophisticated, rely on discreet and long infiltration. The presence of data dating from 2021 to 2023 in some leaks of 2025 may suggest patient infiltration for years before any disclosure, or reuse of old data, without alone allowing a conclusion.

Credential stuffing exploits credentials already compromised elsewhere and reused on multiple services. Sniffing allows discreet interception of network traffic over long periods, passively collecting sensitive data without arousing suspicion. SEO poisoning manipulates the referencing of a legitimate site to inject fraudulent content or redirect visitors. In the case of the CNDP, the injection of Japanese characters into results referenced by Google was associated with this type of practice exploiting poorly maintained CMS.

The operational chain often follows the same three-step pattern. First, silent collection: infiltration through a third-party flaw, theft of credentials or interception tool. Data accumulates for months or years without being detected. Then, strategic publication: files appear on an obscure dark web forum, then are amplified on Telegram to maximize viral dissemination. Finally, political narration: technical data is dressed up with a narrative of moralization, denunciation or intimidation. The damage then becomes immaterial as much as technical.

The quantification of damage must integrate this dimension. Claimed figures mention approximately two million employees and 500,000 companies for the CNSS, nearly three million members for the CNOPS, four terabytes for the ANCFCC, 5,000 magistrates and 35,000 agents for the Ministry of Justice, as well as 2.1 million compromised identifiers around the 2025 Africa Cup of Nations. These figures must be verified, but their political and media effect exists from their dissemination.

The 2030 World Cup as a full-scale test

If the recent attacks have served as a warning, the 2030 World Cup will constitute a full-scale test. Global sport has become a digital infrastructure. Ticketing, accreditations, stadium security, transport, hospitality, broadcasting, mobile applications, media access, payment systems and connected objects form a complex ecosystem. The co-organization by Morocco, Spain and Portugal will place this reality at the heart of the event.

The Russian precedent of 2018, marked by more than 25 million cyberattacks against World Cup-related infrastructures, reminds that major competitions attract cybercriminals, hacktivists and sometimes more sophisticated actors. The 2025 Africa Cup of Nations has already shown that sports environments can be targeted, notably through the theft or exposure of more than 2.1 million identifiers, availability attacks, fake sites and phishing campaigns.

The specific risks for 2030 are identifiable. Digital ticketing will be a priority target. For the World Cup in Qatar, fully digital ticketing multiplied the risk of fraudulent sites, phishing pages and fake reseller accounts, leading to massive theft of personal and banking data. Morocco would benefit from imposing a dynamic QR code system changing every thirty seconds, as Qatar did.

The connected infrastructures of stadiums call for the same vigilance. Giant screens, air conditioning, access systems, cameras, sensors and industrial automation can open the way to intrusions if not mapped, isolated and supervised. Hackers could sabotage screens, cut air conditioning or render tickets unusable. Applications and APIs, now at the heart of digital interactions in sports, also concentrate risks. Without adapted protection, they become preferred entry points.

The geopolitical hacktivist threat must be anticipated. Kaspersky draws strategic lessons from the 2025 Africa Cup of Nations: Morocco must strengthen its local preventive measures, adapt its infrastructures against DDoS attacks and put in place response plans to react quickly to any emerging threat. The trilateral attack surface adds an unprecedented dimension. The 2030 World Cup will create a network of cross-border interconnections between three countries. Each bilateral or common interface, whether for accreditations, ticketing, broadcasting or fan services, will become an additional vulnerability point.

Artificial intelligence will multiply these risks. The rise of deepfakes and fictitious digital identities weakens verification systems, with international estimates suggesting a nearly 200% increase in artificial identifiers used to bypass identity checks. False security instructions, fake voices, fake accreditations or manipulated content could circulate quickly during the tournament, generating operational disinformation in real time. Morocco has the time needed to prepare for this deadline. But useful time is that which begins before the emergency. Intrusion tests, crisis exercises, audits of providers, restoration procedures, disinformation scenarios, communication plans and international cooperation must be thought of now.

Digital maturity must become resilience maturity

Morocco suffers from the classic syndrome of digital maturity without security maturity: rapidly digitized systems, solid regulation on paper, but still fragmentary operational application, insufficient budgets and a security culture under construction. The recent cyberattacks have been the brutal revealer of this reality. This reality should not, however, be read as a denial of Morocco's digital transformation. It is its maturity test. The Kingdom has accelerated the digitization of many services and built a recognized institutional framework. The next step is to advance security, data governance, operational resilience and cyber culture at the same pace as digital usage.

In a world where data flows, where providers interconnect, where attacks professionalize and where artificial intelligence lowers the cost of offense, cybersecurity can no longer be added after the fact. It must be thought from the design of services, integrated into contracts, carried by general management, tested by technical teams and understood by users. Digital trust is not decreed. It is built in architectures, procedures, skills, controlled transparency and the ability to learn from each incident. The good news is that the diagnosis is now made and the reforms undertaken are moving in the right direction. What is expected is that they be applied with the rigor and speed that the deadline demands.

Terminological markers

• API. Interface allowing two applications to communicate and exchange data. In sports or administrations, APIs manage ticketing, accreditations and real-time broadcasting. Poorly secured, they become entry points for attackers.

• APT. Persistent attack conducted by a highly qualified actor, often state-sponsored, who discreetly infiltrates a system and remains hidden for months or years before any disclosure.

• CAPEX. Investment expenditure intended to acquire or modernize durable assets, here cybersecurity infrastructures, software or equipment.

• Credential stuffing. Technique of automatically testing couples of identifiers and passwords stolen from other leaks and resold on the dark web. It exploits the bad habit of reusing the same passwords on multiple services.

• Cryptocurrency. Decentralized digital currency based on cryptography. Used by cybercriminals to receive ransoms or settle transactions on the dark web, due to the difficulty of tracing flows.

• CSIRT. Specialized team responsible for detecting, analyzing and responding to cybersecurity incidents.

• Dark web. Part of the Internet accessible only via special software, not indexed by standard search engines. Preferred market for selling stolen data and hacking tools.

• Deepfake. Audiovisual content falsified by artificial intelligence to imitate a real person. In the context of a global event, deepfakes can be used to broadcast false security instructions or fabricate scandals in real time.

• DDoS. Attack aimed at saturating a server or network with a massive flow of simultaneous requests, causing its unavailability.

• IoT. Set of physical objects connected to the Internet: sensors, cameras, air conditioning systems, screens. In stadiums, each sensor represents a potential entry point.

• maCERT. Moroccan national computer incident response team, under the authority of the DGSSI.

• MFA. Multi-factor authentication, requiring at least two distinct factors to prove identity. Significantly reduces the risk of compromise in case of credential theft.

• PASSI. Information systems security audit provider qualified by the DGSSI, authorized to conduct audits on sensitive systems.

• Phishing. Fraudulent message imitating a trusted entity to induce the victim to disclose credentials or open a malicious attachment. Numero uno entry vector for cyberattacks.

• Plugin. Complementary software module installed on an application or website. If not updated, it can contain exploitable vulnerabilities.

• Ransomware. Malicious software that encrypts data and demands payment of a ransom, often in cryptocurrency, to decrypt them.

• SEO poisoning. Malicious manipulation of a legitimate site's referencing to inject fraudulent content or redirect visitors to trapped pages.

• Sniffing. Discreet interception of network traffic allowing passive collection of credentials and sensitive data over long periods, without arousing suspicion.

• SOC. Security Operations Center, operating 24/7, monitoring systems in real time and coordinating incident response.

PAN's pipeline reviewed approximately 1 open sources for this article. No human editor reviewed this article before publication.

Related Reads

Show on timeline →

Earlier on PAN

More in Technology →