Editorial Product: SafeExpat WATCHING

Executive Summary

A former officer of Morocco’s domestic intelligence service has provided a detailed account of how the country allegedly acquired and deployed Pegasus spyware against selected targets.

The testimony is supported by additional intelligence sources, documents and previous forensic investigations. It strengthens the evidence connecting Moroccan security structures to highly targeted mobile surveillance despite longstanding official denials.

The development is most relevant to journalists, human rights personnel, diplomats, foreign officials, NGOs and individuals working on politically sensitive issues. It does not indicate a generalized cyber threat to ordinary visitors.

No evidence reviewed by the investigative consortium indicates continued Pegasus-linked surveillance by Morocco after late 2021.

Signal

An investigation published on 16 July 2026 by an international consortium coordinated by Forbidden Stories has presented new testimony from a former officer of Morocco’s Direction Générale de la Surveillance du Territoire, or DGST.

The source, identified under the pseudonym “Safir,” reportedly worked within the service for almost a decade. He described the operational use of Pegasus against a Moroccan journalist and explained how the spyware could provide access to messages, calls, photographs and other information stored on a targeted phone.

According to the investigation, Moroccan intelligence structures sought to avoid a direct procurement trail by obtaining access to Pegasus through a private intermediary. A second intelligence source reportedly confirmed this procurement method, although the intermediary’s role in selecting or compromising individual targets remains unclear.

The investigation also draws on leaked material, targeting records, judicial documents, technical analysis and testimony from two additional former Moroccan intelligence personnel. The reporting indicates that Moroccan services began using Pegasus in 2017 and deployed it against selected domestic and foreign targets until approximately late 2021.

Morocco has consistently denied using Pegasus. Neither the Moroccan authorities nor NSO Group reportedly responded to the latest consortium’s requests for comment.

Assessment

The principal change is not the identification of an entirely new surveillance threat. Technical investigations had already documented Pegasus-related targeting involving Moroccan journalists, activists and human rights defenders.

The new element is insider testimony describing how the system was allegedly introduced, procured, tested and used inside Morocco’s intelligence architecture. This reduces some of the uncertainty surrounding earlier technical findings and strengthens the attribution of historical Pegasus activity to Moroccan state structures.

Previous forensic work by Amnesty International identified NSO-linked attacks against journalist Omar Radi between January 2019 and January 2020. Amnesty later confirmed Pegasus traces on devices belonging to Western Saharan human rights defender Aminatou Haidar, including evidence of infection in October and November 2021.

For internationally mobile organizations, the most relevant implication is that exposure is determined primarily by a person’s profile, access and relationships—not simply by nationality.

Personnel working with opposition figures, investigative journalists, diplomatic missions, human rights organizations, security institutions or sensitive commercial and political information may face a higher level of targeted digital scrutiny than ordinary expatriates or tourists.

The disclosures should not be interpreted as proof that Pegasus is currently being deployed in Morocco. The consortium reported finding no evidence of Pegasus-assisted surveillance connected to Morocco after late 2021. Other surveillance capabilities, however, may remain available and cannot be assessed from the Pegasus evidence alone.

Exposed Groups

The groups most likely to require additional digital-security awareness include:

  • Journalists reporting on Moroccan politics, corruption, security institutions or Western Sahara.
  • Human rights defenders, civil-society organizations and their local partners.
  • Diplomats, embassy personnel and visiting government delegations.
  • Foreign law-enforcement, defence and intelligence personnel cooperating with Moroccan counterparts.
  • NGO employees handling politically sensitive cases or confidential source information.
  • Lawyers representing activists, journalists or politically exposed individuals.
  • Researchers and academics working on governance, security or territorial disputes.
  • Business executives involved in sensitive negotiations, regulated industries or government-facing projects.
  • Family members and close associates of high-interest individuals.
  • Global mobility and corporate-security teams responsible for high-profile travelers.

Routine leisure travelers and most conventional business visitors are unlikely to represent priority targets unless their work, contacts or access create a specific intelligence interest.

Operational Impact

The most credible operational impact is the potential compromise of sensitive communications rather than widespread disruption to telecommunications or public services.

A successful mercenary-spyware infection could expose messages, photographs, contact lists, location information, emails and confidential documents. Pegasus has also been designed to activate a device’s microphone or camera, potentially turning a personal phone into a surveillance platform.

For affected organizations, this could create:

  • Loss of source confidentiality.
  • Exposure of local partners or vulnerable contacts.
  • Compromise of meeting schedules and travel movements.
  • Disclosure of diplomatic, legal or commercial negotiations.
  • Increased physical-surveillance risk following digital identification.
  • Reputational damage if confidential communications become public.
  • Legal and data-protection consequences for employers.
  • Reduced trust between international personnel and local counterparts.

The incident also demonstrates the limitations of relying solely on encrypted messaging. Encryption protects communications in transit but cannot protect information once the device itself has been compromised.

Likelihood

Moderate

Further political, judicial and media scrutiny is likely following the publication of detailed insider testimony and supporting documentation.

The likelihood of an immediate, identifiable Pegasus campaign is lower because the investigation found no evidence of Morocco-linked Pegasus activity after late 2021. However, targeted digital monitoring using Pegasus, another commercial platform or less sophisticated surveillance methods cannot be excluded.

The threat should therefore be treated as profile-specific rather than universal.

Time Horizon

30 days

The immediate monitoring period should focus on Morocco’s official response, any additional evidence released by the investigative consortium, reactions from European governments and possible legal or parliamentary follow-up.

Organizations with exposed personnel should use this period to review travel-device policies, identify sensitive travelers and reassess how confidential information is handled during visits to Morocco.

The underlying surveillance exposure extends beyond the 30-day horizon and should remain part of longer-term country-risk planning.

For individuals

Keep operating systems, messaging applications and browsers fully updated. Security patches remain one of the most important protections against known mobile-device vulnerabilities.

High-risk Apple users should evaluate Lockdown Mode, which restricts certain device functions to reduce the attack surface available to sophisticated mercenary spyware. High-risk Android and Google users should consider Google’s Advanced Protection features and stronger account authentication.

Do not carry unnecessary archives, contact databases or confidential documents on a travel phone.

Separate personal, professional and sensitive communications. Individuals with elevated exposure should consider using a dedicated travel device containing only the minimum required information.

Avoid connecting sensitive devices to unfamiliar computers, charging stations, accessories or locally supplied hardware.

Treat unexpected account warnings, device-security notifications and state-sponsored attacker alerts as operational incidents rather than routine spam.

Do not erase, reset or replace a potentially compromised device before obtaining specialist advice. Premature action may destroy forensic evidence.

For organizations

Conduct profile-based assessments before travel. The traveler’s role, access, contacts and subject matter should determine the security posture.

Provide high-risk personnel with configured travel devices rather than allowing sensitive corporate phones to enter the operating environment unchanged.

Remove access to unnecessary cloud folders, historical emails and internal systems before departure.

Use hardware security keys or passkeys for critical accounts and ensure recovery procedures do not depend solely on the traveler’s mobile number.

Establish a clear reporting route for security alerts, unexplained device behaviour, suspicious messages or possible physical surveillance.

Review whether meetings involving sensitive sources or strategic information should take place with personal electronic devices present.

Ensure corporate-security, legal and data-protection teams have an agreed process for preserving and examining potentially compromised devices.

Where credible targeting is suspected, seek assistance from qualified digital-forensics specialists. Amnesty International’s Security Lab maintains resources for consensual forensic examination, including the Mobile Verification Toolkit.

Watch Indicators

Monitor the following developments:

  • A formal response from the Moroccan government or DGST.
  • Additional whistleblower testimony or supporting documents.
  • New forensic findings involving devices used after 2021.
  • Security notifications issued by Apple, Google or other technology providers.
  • Statements from NSO Group concerning Morocco or intermediary procurement arrangements.
  • French, Spanish, European Union or other parliamentary investigations.
  • Reopening or expansion of existing judicial proceedings.
  • Diplomatic guidance concerning electronic devices carried into Morocco.
  • Reports of targeting involving foreign officials, NGO personnel or international companies.
  • Evidence that alternative commercial spyware platforms are being used.
  • Unusual detentions, questioning or device inspections involving journalists and civil-society personnel.
  • Embassy or organizational advisories recommending enhanced digital precautions.

Confidence Level

Medium

Confidence is high that the latest investigation materially strengthens the evidence of historical Moroccan use of Pegasus. The account is supported by multiple former intelligence sources, documentary material, previously leaked targeting data and earlier forensic examinations.

Confidence is lower regarding the present operational environment. No Morocco-linked Pegasus activity was identified after late 2021, and the available evidence does not establish whether comparable tools are currently being used.

The assessment therefore distinguishes between a strongly supported historical attribution and an uncertain current capability.

SafeExpat Assessment

The disclosures reinforce Morocco’s relevance as a targeted digital-surveillance environment for individuals whose work, contacts or institutional access may attract state interest.

This is not evidence of a generalized threat to expatriates or travelers. It is a reminder that high-value personnel operating across diplomatic, journalistic, security and human rights networks should assume that their mobile devices may represent an intelligence collection opportunity.

For organizations, the appropriate response is not alarm or disengagement. It is disciplined travel-device management, profile-based risk assessment and rapid access to specialist forensic support when credible indicators appear.