ransomware Credible Morocco (MA) government

Institut Royal des Etudes Strategiques (IRES) listed by the APT73 ransomware group

Institut Royal des Etudes Strategiques (IRES)

📅 27 April 2026
CompanyInstitut Royal des Etudes Strategiques (IRES)
Domainires.ma
CountryMorocco (MA)
Sectorgovernment
Breach date2026-04-27
People affected500,000
Ransomware groupapt73
Data typesresearch records, internal documents, employee data

Overview

The APT73 ransomware group has listed the Institut Royal des Études Stratégiques (IRES), a state-owned analytical centre in Morocco, on its leak site. The listing appeared on 27 April 2026.

What was published

The group claims to have accessed the institute's systems and copied data. As a strategic research body, the institution holds research documentation, internal correspondence and administrative records, which are the likely contents of any exfiltration.

Risks for affected individuals

  • Research material may be sensitive.
  • Employees' personal data could be exposed.
  • Internal documents may be used for disinformation.

What remains unknown

  • The volume of data exfiltrated.
  • Whether the release is scheduled.
  • The level of access achieved.

What affected people should do

The institute should coordinate with Moroccan cybersecurity authorities and review affected systems. Staff should be alert to phishing referencing the institution.

IRES leak listing

Sources

  • http://basherq53eniermxovo3bkduw5qqq5bkqcml3qictfmamgvmzovykyqd.onion/page_company.php?id=144