Rabat : Le ministre de l'Intérieur tient deux réunions avec les dirigeants des partis politiques sur les prochaines élections législatives    Le gouvernement et les centrales syndicales s'affrontent autour du «triptyque maudit» des retraites    Un message publié par le journal britannique The Guardian : La souveraineté du Maroc sur le Sahara bénéficie d'un large soutien international et populaire... et les Britanniques réaffirment leur position historique    Affaire Achraf Hakimi : Le Club des avocats au Maroc pointe des «défaillances procédurales graves»    Maroc : Jusqu'à 44°, averses orageuses, grêle et rafales de vent jusqu'à vendredi    Comment les grandes ONG internationales entretiennent une grande conspiration du silence dans le cas Sansal, doublée d'une complaisance envers le régime algérien    Ports marocains : le trafic commercial progresse de 11,6 % au premier semestre 2025    Les fertilisants phosphatés animent les échanges économiques entre le Maroc et le Bangladesh, deux alliés indéfectibles    Maroc-Palestine : Aide humanitaire pour Gaza en denrées alimentaires et médicaments    Fête du Trône: Dans un message à S.M. le Roi, le Président Trump réaffirme la reconnaissance par les Etats-Unis de la souveraineté marocaine sur le Sahara    Le Raja scelle un partenariat avec Ports4Impact pour lancer la société sportive Raja S.A.    Football : Le Raja passe de l'association à l'entreprise    «La souveraineté du Maroc sur le Sahara occidental est largement reconnue» : quand la propagande de l'officine FiSahara contre le film de Christopher Nolan s'évanouit    Le Maroc accueille les 19-22 août un grand atelier panafricain sur la gestion des ressources sécuritaires en présence de dix-huit pays    Fête du Trône : Trump réaffirme le soutien des Etats-Unis à la souveraineté marocaine sur le Sahara    Sous le parrainage de la Chine... Une organisation internationale pour l'intelligence artificielle en cours de création à Shanghai    Marrakech : Un chauffeur de taxi arrêté en pleine nuit pour trafic de drogue — scène digne d'un polar urbain    En hommage à l'art et à la fraternité maghrébine : Le Syndicat Professionnels Marocain des Créateurs de la Chanson Marocaine célèbrent la fête du trône en Tunisie    Diaspo #400 : De Paris à Sydney, Jamal Gzem met en image les histoires humaines    Famine à Gaza : des Marocains en grève de la faim contre le silence international    La Turquie a commencé à fournir du gaz azerbaïdjanais à la Syrie    Festival des Plages Maroc Télécom : Réussite de l'Edition Spéciale Fête du Trône    Japon: Juillet 2025, le plus chaud jamais enregistré depuis 1898    BAD: Six millions d'euros pour le développement d'une centrale solaire au Burkina Faso    Thaïlande : la tempête Wipha fait six morts    CHAN 2024 : Une victoire face à l'Angola, «cruciale pour la suite de la compétition» (Tarik Sektioui)    L'avocate d'Achraf Hakimi souligne des incohérences dans le récit de la plaignante    Afro Basket U16 / Coup d'envoi des éliminatoires régionales ce samedi : Maroc vs Tunisie (f) et Maroc vs Algérie (g)    Le Maroc réaffirme son engagement pour les zones humides et déjoue une tentative de politisation de la Convention Ramsar    El Jadida: Vivement, la réhabilitation de l'hopital Provincial Mohammed V    L'Humeur : David Hallyday et les clebs marocains    CHAN 2024 : Coup d'envoi ce samedi à Dar Es-Salaam    Exportations céréalières : le Kazakhstan livre 12,4 millions de tonnes dont 60 000 au Maroc    Le Maroc triple ses importations de bœuf en provenance de l'Union européenne    MAGAZINE : Ozzy Osbourne, les ténèbres à bras ouverts    Fuites de documents d'urbanisme : Des fonctionnaires accusés de collusion avec des spéculateurs    CHAN 2024 : Les cinq stades qui accueilleront la compétition    Le temps qu'il fera ce samedi 2 août 2025    Les températures attendues ce samedi 2 août 2025    Les indicateurs hebdomadaires de BAM en 5 points clés    Omar Benmoussa prend les rênes de Mobiblanc    Le Maroc, allié de longue date et partenaire "essentiel" des Etats-Unis (Sénateurs US)    Wafabail: Mise à jour annuelle du dossier relatif au programme d'émission de bons de sociétés de financement    Espagne : Des élus du PP irritent les alliés du Polisario    Casablanca accueille la 1ère édition du festival AYTA D'BLADI    «Vallée des vaches» : Le Maroc documente des gravures bovines inédites à Tiznit    Disparition : Hassan Ouakrim, doyen de la culture marocaine aux Etats-Unis, n'est plus    Cinéma : "Calle Malaga", de Maryam Touzani, en sélection officielle à Venise et Toronto    







Merci d'avoir signalé!
Cette image sera automatiquement bloquée après qu'elle soit signalée par plusieurs personnes.



What Morocco's largest data leak says about public cybersecurity [Interview]
Publié dans Yabiladi le 15 - 04 - 2025

Last week, Morocco fell victim to a major data breach after two of its public institutions were targeted in cyberattacks claimed by an Algerian hacking group. The incident has raised serious questions about the country's cybersecurity policies and the strategies in place to protect personal data and public institutions. Moroccan entrepreneur and consultant Youssef El Maddarsi, CEO of Naoris Consulting, offers insight. He leads initiatives at the crossroads of decentralized cybersecurity, blockchain, AI, and digital trust infrastructure.
Could you provide an overview of the cyberattacks on Morocco's Employment Ministry and CNSS? What methods did the attackers likely use to gain access to these systems?
The recent cyberattacks on Morocco's National Social Security Fund (CNSS) and the Ministry of Economic Inclusion have been described by analysts as the most significant data breach in the country's history.
According to analyses by The Record and the cybersecurity firm Resecurity, the attacks, believed to have been carried out by the Algerian hacker group JabaRoot DZ, likely exploited a zero-day vulnerability in a third-party Oracle-based system, which enabled them to infiltrate the network without detection.
Once inside, they reportedly bypassed internal security protocols and accessed large volumes of unencrypted data. Rather than deploying ransomware or demanding payment, the attackers appear to have quietly exfiltrated the data and later published it on Telegram. The absence of financial demands, combined with the strategic nature of the leak, has led some experts to suggest a political motive—although attribution in such cases should always be treated with caution pending official confirmation.
CNSS had warnings about its weak cybersecurity. Now that 2 million people's salary info got leaked, how could they have prevented this?
What makes this breach especially concerning is that it was not the first. In 2020, a previous incident exposed the personal data of over 3.5 million users due to an unsecured access point. Despite that earlier warning, several vulnerabilities persisted—particularly around access control, encryption practices, and third-party system oversight.
This incident underscores the urgent need to modernize and strengthen cybersecurity measures across Morocco's critical digital infrastructure. With well-established best practices—such as end-to-end encryption, zero-trust architecture, timely patching, and real-time threat detection—the risks could have been significantly reduced. Like in many public systems worldwide, this breach highlights the importance of elevating cybersecurity from a purely technical domain to a matter of strategic national importance.
These cyberattacks have been claimed by Algerian hackers, representing a continuation of mutual cyberattacks between Algerian and Moroccan hacker groups. How would you describe this cyber warfare?
These recent incidents did not occur in isolation—they form part of an increasingly visible pattern of mutual cyber operations between non-state actors in Algeria and Morocco. What we are witnessing is a form of undeclared, asymmetric cyber conflict, where hacker groups aligned with national narratives carry out attacks that reflect broader geopolitical tensions.
This tit-for-tat dynamic has clearly intensified over the past few years. What began as symbolic acts—such as website defacements—has evolved into high-impact data breaches affecting millions of citizens. If this cycle of escalation continues unchecked, we may eventually see attacks targeting critical infrastructure: power grids, financial systems, telecommunications, or transport networks.
While these are often framed as actions by unofficial groups, the strategic consequences are real. It underscores the urgent need for regional cyber diplomacy, stronger cross-border digital norms, and national-level cyber resilience to prevent these operations from triggering broader instability.
What are your immediate recommendations to address this situation swiftly and effectively?
The breach must be treated as both a national security risk and a wake-up call for long-overdue reform. In the immediate term, authorities should act on several urgent fronts.
1- They must contain the damage by monitoring where the leaked data is spreading and working with platforms to restrict its circulation. The National Commission for Personal Data Protection (CNDP) has already cautioned against unauthorized use—this message must be enforced.
2- Morocco's public institutions need to conduct a full security audit of critical systems; particularly where third-party software is involved. Patching known vulnerabilities, strengthening authentication protocols, and deploying continuous threat detection systems are immediate priorities.
3- Cyber awareness across all government IT personnel must be significantly upgraded. Social engineering and phishing remain the most common points of entry for attackers. Training, red teaming, and policy enforcement must all be intensified.
4- Authorities should consider engaging with international cybersecurity experts to help fortify the country's digital infrastructure and ensure best-in-class practices are implemented without delay.
5- This escalating pattern of cyber retaliation between non-state actors in the region calls for the establishment of regional diplomatic frameworks around cyber norms and shared digital resilience. Without coordinated response mechanisms, the risks of disruption and escalation will only grow.
How do these cyberattacks impact public trust in government institutions, particularly concerning data protection and digital services?
This breach has had a significant impact on public trust. When an institution like CNSS—responsible for pensions, health coverage, and social benefits—is compromised so extensively, it casts doubt on the security of all digital public services. Citizens are understandably concerned about identity theft, fraud, and how their most sensitive information is being managed.
But this goes beyond one breach. It exposes a systemic issue: centralization. When security depends on a single point of failure, the entire infrastructure becomes fragile. Once that single door is forced open, everything behind it is exposed. This is precisely what happened.
To rebuild trust, Morocco must go beyond short-term fixes. The country needs to rethink the foundation of its cybersecurity approach. Decentralized cybersecurity architectures replace centralized bottlenecks with a mesh of interconnected nodes that validate, isolate, and respond to threats autonomously.
Had such a system been in place, the impact would have been drastically reduced. Compromised systems could have been automatically quarantined, sensitive data would have remained encrypted and unreadable, and essential services could have continued operating securely even under attack.
This isn't theoretical. In real-world use, decentralized cybersecurity models have already blocked billions of threats, detecting and neutralizing anomalies before they cause harm. They create self-healing, sovereign digital ecosystems that become more resilient with every attempted breach.


Cliquez ici pour lire l'article depuis sa source.