INTELLIGENCE
ZERO|TOLERANCE
Intelligence Advisory
HIGH PRIMARY SOURCE

OFPPT Morocco's Vocational Training Office Confirms 100,000 Records Exposed, Actor Claims 400,000

Apr 14, 2026 · 100,000 confirmed vs 400,000 claimed · CNI numbers exposed · HIGH

Publication Date
2026-04-14
Category
Data Breaches
Author
K. Ellabban
Organization
Zero|Tolerance Security Research

Morocco's Office de la Formation Professionnelle et de la Promotion du Travail (OFPPT), the public establishment that runs the country's vocational training network, identified a personal data security incident on its MyWay career orientation platform on April 12, 2026. Two days later, on April 14, 2026, OFPPT published a press release confirming that a CSV file of roughly 19 MB had been exposed on the dark web containing records on close to 100,000 young people.

The exposed fields include first and last names, telephone numbers, email addresses and CNI numbers, the national identity card number that every Moroccan adult carries and that cannot be reissued on request.

The figure OFPPT confirmed is not the figure the seller advertised. A threat actor using the alias anisanas2 listed an OFPPT database for sale, published a free 100,000-record sample as proof, and claimed to hold more than 400,000 records in total. OFPPT's communiqué addresses only what it could see. The gap between the two numbers is the central unresolved question of this incident, and it is not a rounding difference.

Executive Summary

KEY FACTS

  • WhatPersonal data from the MyWay career orientation platform was published on the dark web as a CSV file of approximately 19 MB.
  • WhoOFPPT, Morocco's national vocational training establishment. OFPPT states close to 100,000 affected individuals, of whom roughly 70% are prospective applicants and 30% potential trainees.
  • HowOFPPT attributes the incident to "l'usage frauduleux d'un compte légitime identifié (compte potentiellement piraté)", the fraudulent use of an identified legitimate account, potentially hacked, with no indication at this stage of a technical compromise of the orientation system.
  • DataFirst and last names, telephone numbers, email addresses, and CNI national identity card numbers. OFPPT states that no documents or supporting identity papers were exposed.
  • ActorAn individual using the alias anisanas2. No formal technical attribution has been issued by OFPPT, the CNDP, or Morocco's DGSSI.
  • Impact100,000 individuals confirmed by the victim, more than 400,000 records claimed by the seller. Exposure of CNI numbers is permanent because the identifier is not rotatable.
Incident Overview

WHAT HAPPENED

OFPPT dates identification of the incident to April 12, 2026. Reporting in the Moroccan press places the appearance of the data on the night of April 11 to April 12, 2026. OFPPT published its communiqué on April 14, 2026, stating that the incident originated at the MyWay platform and did not affect the rest of its information systems, and that an investigation was underway by its internal IT directorate in collaboration with the competent authorities and mobilised external technical expertise.

The affected population is specific. OFPPT says all affected users had used the new MyWay orientation platform to access information about the training system and to sit a professional interests test ahead of enrolment, creating their own accounts and entering their own details. Only two public functions of the platform were involved: "s'identifier", which handles account creation, and "apprendre à me connaître", which delivers the interests test.

OFPPT states that the other components of the orientation system, including training pathways, professional project records and grade transcripts, were not affected.

The communiqué contains two defensive framings that deserve to be read carefully. The first is a data quality argument: OFPPT notes that some of the data is inaccurate or incomplete as entered by users themselves. The second is a scope limitation: OFPPT writes that it is "exclusivement et uniquement" this data concerning 100,000 users that has been exposed "à date", meaning as of the date of writing. That final qualifier is doing real work. It confirms what OFPPT had observed by April 14, 2026, and it does not foreclose a larger set.

The most consequential disclosure in the communiqué is one OFPPT volunteered. It states that the incident occurred against a background of earlier reports concerning dark web exposure risk, following which OFPPT had launched an emergency remediation plan for cyber vulnerabilities in February 2026. That plan included accelerating existing security work through external expertise and initiating procurement for data classification and data loss prevention tooling, which the communiqué marks "(en cours)", in progress.

OFPPT had roughly two months of warning and an active emergency plan when the data reached the dark web.

THE 100,000 VERSUS 400,000 QUESTION

The seller and the victim describe different objects, and both descriptions can be true at once.

The actor published a 100,000-record sample and claimed a full database of more than 400,000 records. That structure is standard commercial practice on data markets: release a fraction to establish that the goods are real, withhold the remainder as the thing being sold. A sample is evidence of possession, not a statement of inventory.

The sequence is what makes OFPPT's number legible. The sample was published on April 12, 2026. OFPPT identified the incident on April 12, 2026, and its count of close to 100,000 matches the size of that published sample. An organisation that learns of a breach from the public dump is, at the outset, measuring the dump. OFPPT's own framing is consistent with this: the figure is qualified "à date", and the communiqué describes the investigation as continuing in order to confirm the origin and measure the effective impact.

ZERO|TOLERANCE therefore assesses that OFPPT's figure is best read as a count of what surfaced publicly rather than as a measurement of what was taken, and that the seller's 400,000 claim is unverified in both directions. Nothing in the public record establishes an upper bound. OFPPT has not published platform-side extraction logs, which is the only evidence that would settle it. Readers should treat 100,000 as a confirmed floor, not as a total, and should not treat the absence of confirmation for 400,000 as a refutation of it.

A four times gap between a victim's confirmed number and a seller's claimed number most often reflects this asymmetry: the victim can count only what surfaced, the seller has an incentive to inflate, and neither has produced evidence about the remainder.

A second divergence runs alongside the first, and it points the other way. OFPPT's communiqué is the only origin in this reporting for the fact that CNI national identity numbers were in the file. Several Moroccan outlets print the CNI detail, but each relays the communiqué rather than the data. The actor-derived coverage, meaning the reporting built from the listing and the sample rather than from OFPPT, lists names, phone numbers, email addresses, enrolment details, fields of study and diploma levels across more than 500 training centres, and contains no mention of CNI numbers at all.

The victim disclosed a more sensitive data class than the seller advertised, which is not the usual direction of travel and lends weight to the CNI confirmation. The academic and administrative fields described in actor-derived reporting are correspondingly unconfirmed by OFPPT.

Attribution

THREAT ACTOR

The listing is attributed to an individual operating under the alias anisanas2, who advertised the OFPPT database for sale and released the 100,000-record sample. No formal technical attribution has been issued. Neither OFPPT nor the Direction Générale de la Sécurité des Systèmes d'Information (DGSSI), Morocco's national information systems security authority, has publicly named or confirmed an actor.

There is no indication in any retrieved source of an established criminal brand, a ransomware affiliate, or a state nexus, and the profile is consistent with financially motivated data brokerage rather than a targeted intrusion campaign.

The incident lands in a sequence. In April 2025 Morocco's Caisse Nationale de Sécurité Sociale was breached in an incident reported to have exposed data on around two million workers and roughly 500,000 companies, which an actor using the name Jabaroot DZ claimed. Moroccan commentary following the OFPPT disclosure questioned whether institutional security has kept pace with the speed of public sector digitisation.

Impact Assessment

WHAT WAS EXPOSED

Confirmed by OFPPT:

  • First and last names
  • Telephone numbers
  • Email addresses
  • CNI national identity card numbers
  • Segmentation of affected users as roughly 70% prospective applicants and 30% potential trainees

Explicitly excluded by OFPPT:

  • Identity documents and supporting papers, which OFPPT states were not exposed
  • Training pathway records, professional project data and grade transcripts

Claimed in actor-derived reporting but not confirmed by OFPPT:

  • Enrolment details and administrative records
  • Academic tracks and fields of study, including IT, mechanics, tourism, construction and electricity
  • Diploma levels
  • Coverage spanning more than 500 vocational training centres

The CNI number is the field that matters most and the one that cannot be undone. Password resets, email changes and new phone numbers are all available to an affected individual. A national identity card number is not. It is a permanent identifier used across Moroccan administrative and financial procedures, which means the combination of full name, phone number, email address and CNI number in a single row has an operational value to identity fraud that does not decay when OFPPT finishes its remediation.

The affected population makes this worse rather than better: these are young people at the point of entering vocational training, many of them at the start of their financial lives, with no prior history of fraud monitoring.

Root Cause Analysis

TECHNICAL FAILURE CHAIN

1
Account compromise upstream of the platform.

OFPPT's stated scenario is fraudulent use of a legitimate account that was potentially hacked. The communiqué does not state how that account was compromised, and no phishing campaign, credential stuffing wave or password leak has been confirmed by OFPPT.

2
No authorisation boundary between one account and 100,000 records.

This is the failure OFPPT's framing obscures. Whether or not the platform was technically compromised, a single legitimate account was able to reach the personal records of approximately 100,000 other users. An account on a self-registration career orientation platform has no legitimate business reading other people's CNI numbers. The exposure volume is evidence of a missing authorisation boundary regardless of how the credentials were obtained.

3
No effective rate limiting or volume threshold.

Extracting on the order of 100,000 records through an application interface is a high volume operation. Nothing in the retrieved record indicates that a request volume ceiling, throttle or automated cut-off interrupted it.

4
No anomaly detection on account behaviour.

OFPPT identified the incident on April 12, 2026, which press reporting places at or after the point the data surfaced publicly. The retrieved record contains no indication that the extraction was detected while it was happening, which points to absent behavioural monitoring on authenticated sessions.

5
Data loss prevention procured but not deployed.

OFPPT states that its data classification and DLP work was initiated in February 2026 and marked "(en cours)". The control specifically suited to detecting bulk personal data leaving a platform was in procurement while the data was being taken.

6
Prior warnings did not translate into compensating controls.

OFPPT acknowledges earlier signals about dark web exposure risk and an emergency plan opened in February 2026. Two months later the outcome those signals warned about occurred. The gap between recognising the risk and having controls in place was not bridged by any interim measure that stopped this extraction.

Detection

INDICATORS OF COMPROMISE

NO TECHNICAL INDICATORS OF COMPROMISE HAVE BEEN PUBLISHED BY OFPPT, THE CNDP, OR DGSSI. NO FILE HASHES, IP ADDRESSES, DOMAINS, MALWARE FAMILIES OR CVE IDENTIFIERS ARE ASSOCIATED WITH THIS INCIDENT IN ANY RETRIEVED SOURCE. THE FOLLOWING ARE IDENTIFIERS RATHER THAN DETECTION ARTEFACTS
THREAT ACTOR
  • Aliasanisanas2
AFFECTED SYSTEM
  • PlatformMyWay career orientation platform, OFPPT
  • Exposed functions"s'identifier" (account creation) and "apprendre à me connaître" (professional interests test)
LEAKED ARTEFACT
  • FormatCSV, approximately 19 MB
  • Contentdata relating to approximately 100,000 individuals per OFPPT
EXPOSURE TIMELINE
  • Data reported on the dark webnight of April 11 to April 12, 2026
  • Incident identified by OFPPTApril 12, 2026
  • Public communiqué: April 14, 2026
  • Emergency remediation plan openedFebruary 2026
Compliance Impact

REGULATORY EXPOSURE

Two separate Moroccan statutes govern this incident, and conflating them produces the wrong answer. Law 05-20 on cybersecurity imposes the duty to report the incident to the state. Law 09-08 on personal data protection imposes the duty to have secured the data in the first place. They have different regulators, different enforcement routes and different penalties.

Incident reporting: Law n° 05-20 on cybersecurity, promulgated July 25, 2020 and published in Bulletin Officiel N° 6906, with implementing decree n° 2-21-406 of July 15, 2021.

  • Law 05-20, Article 1 - The law applies to the information systems of state administrations, territorial collectivities, "les établissements et entreprises publics et toute autre personne morale de droit public", which it designates throughout as "entité". OFPPT is a public establishment and is therefore an entité within the meaning of the statute.
  • Law 05-20, Article 8 - "Chaque entité doit, dès qu'elle prend connaissance d'un incident affectant la sécurité ou le fonctionnement de ses systèmes d'information, le déclarer à l'autorité nationale." Every entity must declare an incident affecting the security or functioning of its information systems to the national authority as soon as it becomes aware of it. The national authority is the DGSSI. This duty is mandatory and immediate, and it attaches on awareness, which for OFPPT was April 12, 2026.
  • Law 05-20, Article 50 - Failure to comply with the incident declaration obligations of Articles 8, 30 and 33 carries a fine of 100,000 to 200,000 dirhams, without prejudice to more serious criminal penalties under other legislation.
  • Law 05-20, Articles 48 and 52 - Infractions are established by sworn agents of the national authority through procès-verbaux transmitted to the public prosecutor. On repeat offence, penalties are doubled.

The distinction matters for liability. Notification to the state was not a choice. What OFPPT retained discretion over was the public communiqué of April 14, 2026 and any direct notice to the affected individuals. The communiqué's reference to working "en collaboration avec les autorités compétentes" is consistent with a declaration having been made, but it does not name DGSSI and does not confirm the timing.

Data protection: Law n° 09-08, promulgated by Dahir n° 1-09-15 of February 18, 2009 and published in Bulletin Officiel N° 5714, enforced by the Commission Nationale de contrôle de la protection des Données à caractère Personnel (CNDP). The law remains in force in 2026.

  • Law 09-08, Article 2 - Applies to any controller established on Moroccan territory. Public establishments are not exempt; the only carve-outs are national defence, internal and external state security, and defined crime prevention processing. OFPPT is squarely in scope.
  • Law 09-08, Article 23(1)The controller must implement appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, accidental loss, alteration, and unauthorised disclosure or access, at a level of security appropriate to the risk presented by the processing and the nature of the data. Extraction of 100,000 records containing CNI numbers by a single account engages this obligation directly.
  • Law 09-08, Article 58 - Processing personal data without implementing the security measures required by Articles 23 and 24 carries three months to one year of imprisonment and a fine of 20,000 to 200,000 dirhams, or one of those two penalties.
  • Law 09-08, Article 61 - Any controller, processor or person charged with processing personal data who, "même par négligence", even by negligence, causes or facilitates the abusive or fraudulent use of the data processed, or communicates it to unauthorised third parties, faces three months to one year of imprisonment and a fine of 20,000 to 200,000 dirhams. OFPPT's own communiqué characterises the incident as "usage frauduleux", the precise language this article addresses, and the negligence limb does not require that the controller intended the outcome.
  • Law 09-08, Article 64 - Where the offender is a legal person, fines are doubled and the court may additionally order partial confiscation of assets or closure of the establishment where the offence was committed. If Article 64 reaches a public establishment, which is untested in Morocco and unsettled in Moroccan doctrine, the ceiling on the criminal fine under Articles 58 or 61 becomes 400,000 dirhams, approximately 42,800 US dollars at 9.35 dirhams to the dollar on August 3, 2026.
  • That ceiling is not the total exposure. Four liabilities sit outside it. Law 05-20 Article 50 adds 100,000 to 200,000 dirhams for any failure to declare. Law 09-08 Article 65 doubles the chapter's sanctions on recidivism. Article 53 penalises refusal of access, rectification or opposition rights at 20,000 to 200,000 dirhams expressly "par infraction", which is the one provision that scales with a population of 100,000 data subjects. And civil liability runs alongside the criminal track: Article 52 opens "sans préjudice de la responsabilité civile à l'égard des personnes ayant subi des dommages du fait de l'infraction", and while that clause attaches to the Article 52 offence, it reflects that criminal fines under this statute do not absorb damages claims. With roughly 100,000 potential claimants, civil exposure is the larger number.
  • No breach notification duty under Law 09-08. The full text contains no obligation to notify the CNDP or affected individuals of a personal data breach. There is no equivalent of GDPR Articles 33 and 34 and no 72 hour clock. This is verified against the complete statute, and it explains an otherwise striking feature of OFPPT's communiqué: it makes no reference to the CNDP at all. Morocco therefore splits what GDPR unifies. The state must be told under the cybersecurity statute; the data protection regulator and the affected citizens need not be.
  • CNDP enforcement powers. Under Article 28 the CNDP may receive and investigate complaints, order the publication of corrections, and refer matters to the procureur du Roi for prosecution. Under Article 51 it may withdraw a declaration receipt or authorisation. Monetary penalties under Law 09-08 are criminal and run through the courts rather than through a regulator's decision, so financial enforcement is slower and less certain than a GDPR reader would assume. Non-monetary enforcement is not. Article 30 gives the CNDP direct coercive power without a court, including "le pouvoir d'ordonner le verrouillage, l'effacement ou la destruction de données et celui d'interdire provisoirement ou définitivement, le traitement", the power to order the blocking, erasure or destruction of data and to prohibit processing provisionally or permanently. A CNDP order to suspend MyWay processing would not require a prosecution.
  • International instruments. The CNDP identifies Convention 108 and Convention 108+ among the frameworks it implements. No evidence was retrieved that EU residents' data was involved, so no GDPR exposure is asserted here.
Analytical Limitations

INTELLIGENCE GAPS

?
The true size of the dataset is unresolved.

OFPPT confirms close to 100,000 and the seller claims more than 400,000. Only the sample has been examined publicly. Resolution requires either the actor publishing the full set or OFPPT disclosing platform-side extraction logs.

?
How the legitimate account was compromised is unknown.

OFPPT says the account was potentially hacked but names no vector. SearchInform describes phishing or an employee password leak; that claim is uncorroborated elsewhere and OFPPT asserts neither.

?
Whose account it was is undisclosed.

The communiqué does not say whether the account belonged to a staff member, an administrator, a partner or an ordinary self-registered user. The distinction governs how much of the failure is credential hygiene and how much is authorisation design.

?
The extraction window is undisclosed.

No source establishes when access began, how long it continued, or how it was ultimately identified. Without a dwell time, the effectiveness of OFPPT's monitoring cannot be assessed.

?
Whether OFPPT declared the incident to DGSSI, and when, is unconfirmed.

The declaration was mandatory under Law 05-20 Article 8 from the moment OFPPT became aware on April 12, 2026. The communiqué refers only to "les autorités compétentes" without naming the authority or the date. Nothing retrieved confirms compliance, and nothing retrieved suggests non-compliance.

?
Whether the CNDP has engaged is unknown.

No CNDP statement was retrieved, no Article 30 order has been reported, and Law 09-08 imposes no notification duty that would have compelled OFPPT to approach the regulator.

?
Whether affected individuals were notified individually is unknown.

The communiqué contains no commitment to contact the roughly 100,000 people concerned, and no notification programme was described in any retrieved source.

?
The additional academic and administrative fields are unverified.

Enrolment details, fields of study, diploma levels and the 500-plus training centre figure appear only in actor-derived reporting and are not confirmed by OFPPT.

?
OFPPT's claim of no technical compromise is untested externally.

The assertion that the orientation system itself was not compromised rests on OFPPT's own preliminary analysis, which the communiqué acknowledges is ongoing. No independent forensic finding has been published.

Assessment

ZERO|TOLERANCE Advisory

1
Treat "a legitimate account was misused" as a finding about authorisation, not an exoneration.

The question that matters is not how the credentials were obtained but why one account could read approximately 100,000 other people's identity numbers. Enforce per-record ownership checks on every read path in self-service platforms, so that an authenticated session can retrieve the record it owns and nothing else, and audit those checks independently of the authentication layer.

2
Impose volume ceilings on authenticated sessions and alert before the ceiling, not after.

Define a defensible daily record retrieval limit per account for any platform holding national identity numbers, block at the limit, and generate an alert at a fraction of it. A single account reaching four or five figures of record retrievals is an incident by definition, whatever the credentials look like.

3
Do not let DLP sit in procurement while a known risk is live.

OFPPT identified dark web exposure risk and opened an emergency plan in February 2026, and the data classification and DLP deployment was still marked in progress in April. Where tooling has a procurement lead time, deploy interim compensating controls on day one: egress volume monitoring, database query auditing on personal data tables, and manual review of bulk export activity.

4
Separate identity numbers from contact data at rest.

CNI numbers should not sit in the same row as name, phone and email in an application-accessible table. Tokenise the identifier, hold the mapping in a separate store with its own access control, and ensure that a compromise of the application tier yields rows that are not directly usable for identity fraud.

5
Know which clock is legal and which is discretionary.

For any Moroccan entité, declaring an incident to DGSSI under Law 05-20 Article 8 is mandatory and starts on awareness, not on confirmation, and non-declaration is separately fineable at 100,000 to 200,000 dirhams. Notice to affected individuals is what Moroccan law leaves to the controller. Build the DGSSI declaration into the incident runbook as a legal trigger, then treat individual notice as the decision it actually is, and make it: a person whose CNI number appeared in the file cannot rotate that identifier and needs to know to watch for its misuse indefinitely.

6
Publish a scope update when the investigation closes, and address the 400,000 claim directly.

OFPPT's figure is qualified "à date" and its investigation is ongoing. A follow-up communiqué that either confirms the original count against extraction logs or revises it will do more for institutional credibility than silence, and it is the only way the four times discrepancy gets resolved on the record.

References

SOURCES

OFPPT, "Incident de Cybersécurité au sein de l'OFPPT : Éclairage", press release, April 14, 2026, https://www.ofppt.ma/fr/communiques-de-presse/incident-de-cybersecurite-de-lofppt%C2%A0eclairage and https://www.ofppt.ma/sites/default/files/documents/COMMUNIQUE%20DE%20PRESSE%20-%20Incident%20Cybersecurite_0.pdf Loi n° 09-08 relative à la protection des personnes physiques à l'égard du traitement des données à caractère personnel, Dahir n° 1-09-15 of February 18, 2009, Bulletin Officiel N° 5714, https://www.cndp.ma/images/lois/Loi-09-08-Fr.pdf Loi n° 05-20 relative à la cybersécurité, July 25, 2020, Bulletin Officiel N° 6906, official DGSSI text, https://www.dgssi.gov.ma/sites/default/files/legislative/brochure/2023-03/loi%2005-20.pdf Décret n° 2-21-406 du 15 juillet 2021 pris pour l'application de la loi n° 05-20 relative à la cybersécurité, https://www.dgssi.gov.ma/sites/default/files/legislative/brochure/2023-07/Decret%202-21-406.pdf Commission Nationale de contrôle de la protection des Données à caractère Personnel (CNDP), https://www.cndp.ma/ Morocco World News, "Alleged Cyberattack on OFPPT Sparks Alarm Over 400,000 Leaked Student Records", April 13, 2026, published the day before OFPPT's communiqué and based on the actor listing rather than the victim statement, https://www.moroccoworldnews.com/2026/04/286826/alleged-cyberattack-on-ofppt-sparks-alarm-over-400000-leaked-student-records/ SearchInform, "Morocco Student Data Leak: OFPPT 400K Records Breach", April 15, 2026, a data loss prevention vendor reporting on an incident in which DLP tooling was in procurement, https://searchinform.com/blog/2026/04/15/morocco-student-data-leak-ofppt-400k-records-breach/ 7News Morocco, "Morocco cybersecurity maturity questioned after massive OFPPT data breach", https://en.7news.ma/morocco-cybersecurity-maturity-questioned-after-massive-ofppt-data-breach-claims-400000-records-exposed/ Medias24, "Fuite de données à l'OFPPT : près de 100.000 utilisateurs de la plateforme MyWay concernés", April 14, 2026, https://medias24.com/2026/04/14/fuite-de-donnees-a-lofppt-pres-de-100-000-utilisateurs-de-la-plateforme-myway-concernes-1659635/ TelQuel, "Fuite de données à l'OFPPT : les informations de 100.000 jeunes exposées sur le dark web", April 14, 2026, https://telquel.ma/instant-t/2026/04/14/fuite-de-donnees-a-lofppt-les-informations-de-100-000-jeunes-exposees-sur-le-dark-web_1984188/ Le360, "Cyberattaque à l'OFPPT: près de 100.000 profils exposés via la plateforme My Way", April 14, 2026, https://fr.le360.ma/societe/cyberattaque-a-lofppt-pres-de-100000-profils-exposes-via-la-plateforme-my-way_BZOYHKYO6VE5JIGOAZC225V5CA/ L'Economiste, "Fuite de données : l'OFPPT active des mesures correctives", https://www.leconomiste.com/flash-infos/fuite-de-donnees-lofppt-active-des-mesures-correctives/