Marrakech – More than 18.5 million Moroccan accounts have been breached since 2004, placing the country 60th globally in terms of total breached accounts.
According to a report by Surfshark, this represents approximately 0.1% of global data breaches. The breach rate in Morocco is on the rise, with a concerning 125% increase in the second quarter of 2025 compared to the first quarter.
The total number of breaches in Morocco this decade stands at 8,655,015, with 22,621 breaches per 100,000 people. Among the most significant breaches affecting Moroccan users were the 3.3 billion unique email list by Addka (impacting 1,793,702 Moroccan accounts), Wattpad (695,475 accounts), and Aptoide (158,324 accounts).
Within North Africa, Morocco ranks behind Egypt (ranked 50th globally with 25.9 million breached accounts) but ahead of Algeria (ranked 67th with 11.5 million breaches), Tunisia (ranked 83rd with 6.5 million breaches), and Libya (ranked 143rd with 1.2 million breaches).
This positions Morocco as having the second-highest number of breached accounts in the North African region according to the Surfshark data.
Globally, the total number of breached accounts since 2004 has reached an alarming 23.1 billion. Of these, approximately 7.7 billion have unique email addresses.
Surfshark points out that many people use the same email for different accounts when registering online, meaning a single email can be breached several times in separate incidents.
On average worldwide, a single email address is breached around 3 times, with 94 unique email addresses breached for every 100 people, and 281 accounts breached per 100 people.
Morocco’s cyber risk environment tightened in 2025 after a run of high-profile account and data breaches. In April, the National Social Security Fund (CNSS) suffered a major leak; independent analysis indicates more than one million records and 50,000+ PDF documents containing payroll and identity data were exfiltrated and posted online.
A June scare around the land registry was later rebutted by Morocco’s cyber authority: DGSSI’s investigation found the leaked dataset came exclusively from the notaries’ tawtik.ma platform, and that ANCFCC systems were not breached.
Amid these mounting vulnerabilities, Kaspersky’s 2025 data (presented at GITEX Africa 2025) ranks Morocco among Africa’s top targets: third for web-based threats with 12.6 million attack attempts in 2024.
The report also shows a continent-wide rise in spyware (+14%), password-stealers (+26%), and on-device threats (+4%) – all of which directly elevate the risk of account takeovers.
Authorities and industry have moved to harden defenses, from incident containment and advisories to new capacity-building. The government formalized a national Cybersecurity Innovation Center (CIC) in the Official Bulletin and launched it with Mohammed V University to drive research, training, and coordinated response – part of wider upgrades to state digital infrastructure.
On the technical front, attackers have actively abused supply-chain style weaknesses – most notably an unauthenticated admin-creation flaw affecting 100,000+ WordPress sites (SureTriggers/OttoKit), a vector that enables silent account compromises when sites aren’t promptly patched.
In practical terms, the situation is improving but remains high-risk: organizations and users that enforce MFA, keep software and plugins patched, deploy EDR/backup routines, and monitor for credential theft stand a far better chance of avoiding the kind of mass account breaches seen this year.
Read also: Moroccan Police Officer Files Complaint Against Jabaroot’s False Allegations








