Ministère de l'Inclusion économique, de la Petite Entreprise, de l'Emploi et des Compétences
Incident posture
Linked entities
- Victim
- Ministère de l'Inclusion économique, de la Petite Entreprise, de l'Emploi et des Compétences
- Threat actors
- 1 actor
- Sources
- 1 source
Timeline
Summary
The Moroccan Ministry of Inclusion Economic, Small Enterprise, Employment and Skills was targeted by a cyberattack claimed by the Algerian hacktivist group JabaRoot DZ, which struck the ministry's informational web portal. The ministry confirmed the incident through an official statement, characterizing the impact as minor and indicating that no sensitive data was exposed. Because the affected site was strictly informational and hosted only publicly accessible content, officials stated there was no risk of compromise to personal records or professional databases. The ministry also publicly disavowed fraudulent documents circulating online that were falsely attributed to its services, clarifying that such materials fell outside its area of responsibility.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On Monday, April 1, 2025, the Moroccan Ministry of Economic Inclusion, Small Enterprise, Employment and Skills (MIEPEEC) confirmed through an official communiqué that it had been the target of a cyberattack claimed by a group identifying itself as JabaRoot DZ, described in media reporting as Algerian hackers. The attack was directed at a digital portal operated by MIEPEEC, and the ministry moved to publicly disclose the incident the same day. According to the ministry's statement, the affected platform was primarily an informational website rather than a transactional or data-processing system. The attack was characterised by the ministry as having no major consequences, and the administration took the opportunity to clarify the precise nature and scope of what had been compromised in order to address public concern.
In its official communication, MIEPEEC emphasised that the targeted site hosted only publicly available, freely accessible information, and that it did not contain any database of a professional character. The ministry stated explicitly that all information published on the platform was public and openly accessible, and that the site held no sensitive professional databases. Based on these technical characteristics, the administration concluded that there was no risk of compromise to personal data files or to any sensitive database. The attack was therefore framed by the ministry as an incident limited in impact, confined to a non-critical, outward-facing informational resource that did not process or store confidential information. This assessment formed the central element of the ministry's public response and was intended to reassure both citizens and partner institutions about the absence of significant data exposure.
Beyond addressing the technical nature of the affected portal, MIEPEEC also sought to distance itself from various documents that had begun circulating online, which were being falsely attributed to the ministry's services. The ministry stated clearly that the documents in circulation did not fall within the scope of its responsibilities, and it issued a public statement to that effect. This component of the response aimed to contain the reputational and informational fallout that often follows such incidents, where leaked or fabricated materials may be attributed to the compromised institution in order to amplify the perceived impact of the attack. By formally disavowing any connection to these documents, the ministry attempted to clearly delineate the boundaries of the actual compromise.
The claim of responsibility by JabaRoot DZ was reported through media coverage of the incident, and the group was described as an Algerian entity. The attack was presented in the reporting as being politically or geographically motivated, given the identification of the threat actor and the regional context. However, the ministry's own communications focused not on the attribution or the motivations of the attackers, but rather on the practical consequences of the intrusion and the nature of the systems affected. Throughout the public reporting on the incident, there was no indication that the attack had resulted in service outages affecting critical government functions, nor any evidence that internal ministry systems beyond the public-facing portal had been accessed or disrupted. The incident was ultimately presented as an attack on an outward-facing informational resource, the consequences of which were characterised as minimal by the affected institution itself.
Sources
Sources available to members: 1 source.