ransomware
Credible
Morocco (MA)
telecom
Maroc Telecom (IAM) listed by the APT73 ransomware group
Maroc Telecom (IAM)
CompanyMaroc Telecom (IAM)
Domainiam.ma
CountryMorocco (MA)
Sectortelecom
Breach date2026-04-27
People affected1,000,000
Ransomware groupapt73
Data typessubscriber data, internal records, operational data
Overview
The APT73 ransomware group has listed Maroc Telecom (IAM), Morocco's leading telecommunications operator, on its leak site. The listing appeared on 27 April 2026.
What was published
The group claims to have accessed the operator's systems and copied data. The potential contents of any exfiltration would depend on which systems were reached, ranging from internal administrative records to operational data.
Risks for affected individuals
- Subscriber records, if exposed, enable phishing and fraud.
- Internal operational data could reveal network details.
- Employees' information may be included.
What remains unknown
- Whether subscriber data is included.
- The volume of data exfiltrated.
- The response status of the operator.
What affected people should do
Subscribers should be alert to phishing messages and monitor account activity. Maroc Telecom should review affected systems, notify regulators and customers if subscriber data is involved, and communicate transparently about the incident.

Sources
- http://basherq53eniermxovo3bkduw5qqq5bkqcml3qictfmamgvmzovykyqd.onion/page_company.php?id=143