leak
Potential
transport
MarsaMaroc: database sample with full names and emails shared
MarsaMaroc
CompanyMarsaMaroc
Country
Sectortransport
Breach date2025-07-01
People affected100,000
Data typesNot disclosed
<p>On 01 July 2025, darkMods claims to have leaked data belonging to <strong>MarsaMaroc</strong> on a hacking forum. The claimed data includes full names, email addresses. A limited sample was published to support the claim.</p>
<h2>What the source reveals</h2>
<p>nom: BENNANIM prenom: Youssef email: [email protected] nom: BENJELLOUN prenom: Said email: [email protected] nom: BENCHAIB prenom: Imane email: [email protected] nom: KABBAJ prenom: Moncef email: [email protected] nom: ZIANI prenom: Mounia email: [email protected] nom: LOULID prenom: Mustapha email: [email protected] nom: NAH prenom: Toufik email: [email protected] nom: FAIDI prenom: Mohamed email: [email protected] nom: ELMALLEM prenom: Abderazak email: [email protected] nom: BOULAJOUL prenom: Aimad email: [email protected] nom: ouhmiz prenom:</p>
<h2>Risks</h2>
<ul>
<li>Targeted phishing campaigns using compromised email addresses to distribute malware or harvest credentials from employees and customers</li>
<li>Identity theft and impersonation using exposed personal identification documents and biometric data</li>
<li>Unauthorised access to sensitive organisational data that could be used for follow-on attacks</li>
<li>Competitive intelligence loss if proprietary business information or trade secrets were exposed</li>
<li>Reputational damage and erosion of customer, citizen, or stakeholder trust in the affected organisation</li>
<li>Legal liability and regulatory fines under applicable data protection frameworks</li>
</ul>
<h2>What remains unknown</h2>
<ul>
<li>the total volume of data compromised and whether it includes additional categories beyond those disclosed</li>
<li>the method by which the data was obtained - whether through a direct database compromise, an insecure API, or a third-party breach</li>
<li>whether the data has been sold or distributed to additional parties beyond the forum post</li>
</ul>
<h2>Conclusion</h2>
<p>While the claim has not been independently verified, the potential exposure of data from MarsaMaroc warrants attention. Organisations in the transport sector should treat this incident as a reminder to audit access controls, monitor for anomalous data exfiltration, and ensure incident response plans address data publication scenarios. Affected individuals should change passwords and remain vigilant against phishing attempts.</p>