Concur News
  • Home
  • India
  • Startup
  • Regulation
  • Interview
  • Press Release
  • Login
September 17, 2025
No Result
View All Result
Concur News

Home » Historic Moroccan Data Breach Leaks Private Information of Millions

Historic Moroccan Data Breach Leaks Private Information of Millions

April 12, 2025
in Africa
Reading Time: 3 mins read
Historic Moroccan Data Breach Leaks Private Information of Millions
Share on LinkedinShare on Whatsapp

Earlier this month, a historic Moroccan cybersecurity breach shook the nation, marking the most severe digital attack in its history. The target was the Caisse Nationale de Sécurité Sociale (CNSS), Morocco’s key agency for managing social benefits for private-sector workers. The breach exposed sensitive personal information of nearly 2 million individuals and data from around 40,000 businesses covering close to 4 million employees.

CNSS, founded in 1961, handles everything from healthcare and pensions to unemployment, maternity, and disability benefits. Because of this, it stores a huge amount of sensitive data on Moroccan citizens and businesses.

This breach raised alarms across the country, especially as Morocco adopts more digital services. The incident revealed serious issues in data protection, government crisis communication, and public transparency. So far, officials haven’t informed many victims, leaving them vulnerable and damaging trust in government systems.

Consent Foundation

The hacker, known as “Jabaroot,” leaked the stolen data on a Dark Web forum in PDF and CSV formats. They made no attempt to sell it, suggesting political or espionage motives over financial gain. Resecurity, a cybersecurity firm, called it a politically motivated cyber-attack. They named it Morocco’s most serious breach due to the data’s scale and sensitivity.

The leak revealed names, ID numbers, passport details, phone numbers, emails, salaries, and banking data. It also exposed internal files and employee records from major businesses and government departments.

The breach affected staff from the Finance, Health, Food Safety, and SME departments. Resecurity warned scammers may use the leaked data for identity theft, financial fraud, and phishing scams.

The hacker suggested this attack was revenge for Moroccan hackers targeting an Algerian state news agency. This follows a pattern of cyber hostilities between Moroccan and Algerian digital groups.

The files included salary data of top officials and accused them of hiding the breach’s true scale. One leaked archive dated November 29, 2024, raised suspicion of an earlier, unreported breach.

Resecurity verified the data’s authenticity by cross-checking it with clients and internal sources. Yet, CNSS and regulators haven’t officially informed affected individuals or provided protection steps.

This silence sparked public concern over privacy, accountability, and consumer rights. Experts fear scammers may already be using the data to impersonate citizens or run phishing attacks.

The leak affects not just Moroccans, but also foreign workers and businesses in Morocco. Experts say this could strain international trade and diplomatic relations.

Morocco’s data authority, CNDP, acknowledged the breach and called the data’s use illegal. Despite this, the government has taken little legal or regulatory action so far.

Resecurity is helping police investigate. They suspect a state-backed cyber group may be involved. These groups often hide behind hacktivist motives to avoid detection and blame.

This breach shows signs of deep political intent and organized digital espionage. Two years ago, CNSS had already warned the public about scammers posing as staff. They promised legal action then—a promise that now feels more urgent than ever.

Also read: India Plans to Replace Old SIM Cards Over Security Concerns After Chinese Chip Discovery

Related Posts

FIFA Flags Risks in NSE’s Mutual Fund Platform: Data Security & Operational Concerns
India

FIFA Flags Risks in NSE’s Mutual Fund Platform: Data Security & Operational Concerns

September 8, 2025
Affordability Meets Privacy Risks in ChatGPT Go
India

Affordability Meets Privacy Risks in ChatGPT Go

September 3, 2025
Data Protection Law Amendment to RTI Act Strikes Balance with Privacy Rights: Ashwini Vaishnaw
Global

Data Protection Law Amendment to RTI Act Strikes Balance with Privacy Rights: Ashwini Vaishnaw

September 1, 2025
Raghuveer
Interview

Interview with Dr. Raghuveer Kaur, DPO at Cateina Technologies, on DPDPA, GRC, and Building Scalable Privacy Frameworks

August 29, 2025

RECOMMENDED NEWS

biometric data

Microsoft Teams Collects Students’ Biometric Data for Weeks, NSW Education Unaware

4 months ago
Meta Whistleblower

Meta Whistleblower Claims Company Prioritized Profit Over Children’s Safety in Horizon Worlds

5 months ago
FIFA Flags Risks in NSE’s Mutual Fund Platform: Data Security & Operational Concerns

FIFA Flags Risks in NSE’s Mutual Fund Platform: Data Security & Operational Concerns

1 week ago
insurance company

Is it Harassment or a Privacy Violation? Insurance Company Demands Home Photos and Google Location for Claim Approval

5 months ago

BROWSE BY TOPICS

AI AI in education AI Privacy banks Children privacy Compliance Consent consent managers Cross-Border Cybercrime Cyber security Data Data breach Data leak Data privacy data privacy in education Data Protection Data security Data Violation Digital DPDP DPDPA DPDP Act EU Fines GDPR google Hack Hacked Industry Interview Law Meity penalty Personal data Press Release Privacy privacy rights RBI SPAM Tech giants Technology TRAI Training Trending

701, The Capital, BKC(E), Mumbai, India

Follow us on social media:

Categories

Categories Layout
  • Africa
  • America
  • India
  • Asia
  • Europe
  • Japan
  • Business
  • Events
  • Regulation
  • Law
  • News
  • Privacy
  • Startup
  • Technology
Categories Layout
  • Apps
  • Cybercrime
  • Data
  • Data Breach
  • Data Privacy
  • Data Protection
  • Digital
  • FBI
  • Investment
  • Law
  • Privacy
  • Tech Giants
  • DPDP
  • DPDPA

Harmonize Data Compliance

Footer with Animated Button
Effortlessly align your data compliance with Concur, ensuring seamless integration and robust adherence to regulatory standards.
BOOK A DEMO
  • About
  • Advertise
  • Careers
  • Home
  • Demo

© 2025 Concur - consent manager

Welcome Back!

OR

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • News
  • Business

© 2025 Concur - consent manager