ransomware
Credible
Morocco (MA)
government
HACA (High Authority for Audiovisual Communication) listed by the APT73 ransomware group
HACA
CompanyHACA
Domainhaca.ma
CountryMorocco (MA)
Sectorgovernment
Breach date2026-04-27
People affected500,000
Ransomware groupapt73
Data typesregulatory records, internal documents, employee data
Overview
The APT73 ransomware group has listed HACA, Morocco's High Authority for Audiovisual Communication, on its leak site. The authority regulates the audiovisual sector in Morocco. The listing appeared on 27 April 2026.
What was published
The group claims to have accessed the authority's systems and copied data. As a regulator, the institution holds licensing records, internal administrative documents and employee information, which are the likely contents of any exfiltration.
Risks for affected individuals
- Media operators may have licensing data exposed.
- Employees' records could be misused.
- Internal regulatory documents are sensitive.
What remains unknown
- The volume of data exfiltrated.
- Whether the release is scheduled.
- The attack vector used.
What affected people should do
The authority should coordinate with Moroccan cybersecurity authorities, review affected systems, and inform staff. Regulated media operators should watch for suspicious communications referencing the authority.

Sources
- http://basherq53eniermxovo3bkduw5qqq5bkqcml3qictfmamgvmzovykyqd.onion/page_company.php?id=136