• 5 mins read
  • Published

Amnesty links Spain's Pegasus attacks to Morocco's intelligence service

Bruce Maddy Maghreb politics and identity contributor Maghreb Insider

Post by Bruce Maddy

Amnesty links Spain's Pegasus attacks to Morocco's intelligence service Maghreb Insider © maghrebinsider.com
Amnesty links Spain's Pegasus attacks to Morocco's intelligence service © maghrebinsider.com

Amnesty says an iMessage account linked to Morocco's Pegasus system was used in the 2021 attacks on Spain's defence and interior ministers. It names the DGST as the end user behind operations against Moroccan and foreign targets, but does not identify an individual perpetrator.

Amnesty's report centers on an email address: linakeller2203@gmail.com. Investigators linked it to Pegasus attacks on French activist Claude Mangin and exiled Moroccan journalist Hicham Mansouri.

In a report published on 1 October 2026, Amnesty said the iMessage account was associated with Morocco's Pegasus client. It was also used in the 2021 breaches of Spain's defence minister, Margarita Robles, and interior minister, Fernando Grande-Marlaska. Amnesty describes the evidence as strong support for attributing the wider campaign to Moroccan intelligence services. Its assessment is not a court finding. No individual operator is named.

The report identifies Morocco's Directorate General for Territorial Surveillance (DGST), the country's internal intelligence service, as the end user behind Pegasus operations. Amnesty says its documented cases span 2017 to 2021, with possible use continuing later. Amnesty's report calls on Morocco to stop spying on activists and journalists and to open an independent investigation into the DGST. Amnesty says Moroccan authorities have previously denied using spyware against critics.

In Spanish judicial records, the same account appears as the Apple account used in zero-click attacks on Robles and Grande-Marlaska. That match matters.

NSO Group set up separate infrastructure for each customer, including dedicated email addresses, Apple IDs, domains and servers. Amnesty says it has not observed a specific attacker account or infection domain shared across customers. Here, the repeated account acts as a technical fingerprint linking the devices to one operator. It does not show who controlled that operator.

France's national cybersecurity agency, ANSSI, identified the same cluster of Apple accounts on targeted phones, according to Amnesty. The findings were sent to Spain through a European Investigation Order. The link crossed borders.

Amnesty does not make the same direct, account-based link to Prime Minister Pedro Sánchez. His phone was also infected in May 2021, but Spanish judicial filings do not identify the iMessage account used in that breach.

Relations between Madrid and Rabat had worsened sharply. Spain admitted Polisario Front leader Brahim Ghali for medical treatment in April 2021. Thousands of migrants crossed into Ceuta from Morocco on 17 and 18 May.

Sánchez's phone was compromised on 19 and 31 May. The attacks extracted 2.6 gigabytes and 130 megabytes of data. Robles was targeted in June, and nine megabytes were taken. Grande-Marlaska's phone was breached twice that month. One attack extracted more than six gigabytes.

The Pegasus allegations are separate from claims about the treatment of migrants at the border. Reuters reported on 30 September 2026 that Amnesty had documented 22 cases of torture and abuse by military personnel in Ceuta. Spain ordered an inquiry. Those allegations concern different events and do not establish anything about the Pegasus infections.

The case also has a regional dimension. Technical evidence, government positions and judicial findings need to be kept distinct. Morocco's MAP and Algeria's APS are national news agencies that report on regional affairs. Their public reporting cannot replace forensic examination of devices or findings by a court.

That distinction matters for civil society and diplomatic trust. The cross-border case is politically sensitive, particularly because of Sahrawi rights and relations between Morocco and Spain.

Amnesty's 126-page report, We Start with the Verdict: Inside Morocco's Surveillance Machine, draws on NSO materials disclosed in litigation brought by WhatsApp and Meta, leaked records, forensic audits and testimony from a former DGST operative. Amnesty says it identified nearly 13,000 unique numbers selected by the Moroccan client. It also matched 103 phone numbers to potential targets, including 65 civil society members and 22 journalists.

Being on a target list does not by itself prove that a phone was infected, Amnesty cautions. Forensic examination is needed to confirm a compromise.

The report describes a wider surveillance system, not just spyware use. Amnesty says Pegasus was combined with non-digital methods, including tailing and wiretapping. Its documented surveillance record crosses borders and includes activists, journalists and politicians in France and Spain. A separate analysis examines the wider regional stakes, including the debate over Western Sahara's green economy.

Spain's Audiencia Nacional provisionally shelved its investigation again on 22 January. Judge José Luis Calama said Israel's failure to answer requests for legal assistance prevented investigators from attributing the acts to a specific person. The case was closed in July 2023, then reopened in April 2024 after evidence arrived from France.

Amnesty's findings make the attribution to Morocco more specific. They have not named a perpetrator or resolved the Spanish case. The conclusion remains narrower: infrastructure built to isolate spyware clients can leave technical traces that help link a cross-border attack to a state intelligence operator. The identity and legal responsibility of any individual remain unresolved.

Related Briefs