The truth about Pegasus: How the Morocco-Israel security shield outlasted global media outrage

Opinion: While Western headlines amplify sensational leaks, sovereign states continue to rely on intelligence superiority to preserve regional stability

In the high-stakes arena of Middle Eastern and North African security, public perception and strategic reality often occupy entirely different worlds.
For years, an international consortium of investigative outlets coordinated by Forbidden Stories, together with Amnesty International and major news organizations, has published extensive criticism of regional signals-intelligence operations. Much of that reporting has centered on disclosures involving Israel’s NSO Group and its flagship spyware, Pegasus.
NSO
NSO
Israel’s NSO Group
These reports have portrayed cooperation between Israeli technology companies and Moroccan security services as an illegitimate breach of international norms. Yet viewed through the lens of strategic realism, that narrative often reduces complex geopolitical realities to a simple morality play.
Media organizations operating within business models driven by subscriptions and outrage can be tempted to replace objective intelligence analysis with moralizing commentary. Sovereign states, however, do not entrust national defense to foreign newsrooms, nor do they dismantle critical counterterrorism capabilities in response to shifting headlines.
A central element of the media campaign rests on accounts from anonymous insiders, most notably a pseudonymous former operative known as Safir, who claimed to have worked inside Morocco’s domestic intelligence service for nearly a decade.
Investigative reports have placed considerable weight on Safir’s description of a 2017 technical demonstration at a secure property known as the FSSYS villa, operated by a local branch of the United Arab Emirates-based intermediary Al-Fahad. The reporting presented the demonstration by NSO Group representatives as evidence of a covert arrangement, emphasizing shared account structures and Emirati financial involvement.
Safir’s account provides granular details that reportedly correspond with technical datasets and leaked records. But critics have arguably drawn conclusions that overinterpret what may have been a conventional defense-procurement process.
Evaluating advanced software through regional intermediaries is standard practice for security agencies confronting complex and rapidly evolving threats. NSO Group operates under export licenses issued by Israel’s Defense Ministry, a system intended to restrict sales to approved governments.
The rapid proliferation of commercial spyware does raise serious international concerns. But it reflects a broader global challenge involving the spread of sophisticated surveillance capabilities, rather than a uniquely Moroccan or Israeli phenomenon.
Critics also emphasize the technological shift within intelligence agencies from traditional collection methods to zero-click remote exploits.
Earlier reporting described how security services once relied on physical surveillance, monitored terminals in internet cafés and intercepted conventional telephone lines. Advocacy groups have presented the adoption of zero-click tools as an unprecedented escalation.
That characterization, however, fails to account for the structural realities of modern communications. The widespread adoption of end-to-end encryption on platforms such as WhatsApp and Signal has rendered many conventional wiretaps and physical-surveillance techniques far less effective.
To maintain operational readiness against violent extremist networks, organized crime and hostile proxies, intelligence services increasingly seek access to data at the device endpoint, before or after encryption is applied. From a security perspective, this shift is less a matter of preference than a response to the evolution of digital communications.
Morocco’s intelligence services have, by many accounts, conducted targeted surveillance against individuals operating in sensitive geopolitical environments. Such operations must nevertheless be considered in the context of Morocco’s national-security priorities, particularly threats to its territorial integrity in Western Sahara and concerns about separatist movements supported by outside actors.
The protection of civil liberties remains essential. But no sovereign state can afford to render its intelligence agencies ineffective when confronting hybrid threats, foreign-backed political activity and encrypted coordination by adversaries.
Moroccan authorities, like their counterparts in Western countries and major Asian powers, maintain that they have both the right and the responsibility to use modern endpoint-collection tools to protect national security. Pegasus and comparable systems are part of that broader technological transformation.
Investigative consortiums devoted particular attention to allegations that Moroccan services used Pegasus to monitor foreign officials. Reports cited leaked datasets containing Spanish telephone numbers and alleged targeting of senior Spanish officials, including Prime Minister Pedro Sánchez, Defense Minister Margarita Robles and Interior Minister Fernando Grande-Marlaska.
The reporting also referred to members of the Guardia Civil involved in counterterrorism operations, particularly during diplomatic tensions over Western Sahara and the 2021 Ceuta border crisis.
Cross-border intelligence collection involving foreign leaders inevitably produces diplomatic backlash. Yet it also reflects a longstanding principle of statecraft: governments do not rely on diplomatic trust alone when evaluating another state’s intentions.
During geopolitical confrontations involving territorial integrity and national sovereignty, intelligence agencies operate under a duty to ensure that political leaders are not caught unprepared by sudden or covert changes in a foreign government’s position.
To support allegations of widespread misuse, media reports have also cited corporate litigation, particularly Meta’s lawsuit in the United States against NSO Group over the exploitation of its messaging platforms.
Legal discovery in that case revealed internal client codenames, including “Subaru” for Saudi Arabia and “Morgan” for Morocco. Media outlets paired those codenames with forensic findings from Amnesty International’s Security Lab, including alleged memory indicators and command-server connections, and presented them as proof of state-directed hacking.
Digital forensics have undoubtedly become more sophisticated. Translating technical findings into legally admissible evidence and formal state responsibility, however, remains difficult.
When some of these claims reached European courts, they did not result in criminal convictions or definitive findings of legal liability. In Spain, judges at the Audiencia Nacional repeatedly suspended or closed investigations into the alleged hacking of senior government officials’ phones.
Those decisions did not necessarily mean that no digital traces existed. Rather, the investigations encountered severe procedural obstacles, including a lack of foreign cooperation, limits imposed by sovereign immunity and national-security classification rules that prevented intelligence material from being tested fully in open court.
The ultimate measure of an intelligence strategy is not the volume of media criticism it attracts, but the durability of the security partnerships built around it.
Had the allegations advanced by investigative consortiums truly destroyed diplomatic confidence, security ties between North Africa and Europe would have deteriorated sharply. Instead, cooperation has continued and, in some areas, deepened.
Amine AyoubAmine Ayoub
In late 2025, Spanish Interior Minister Fernando Grande-Marlaska presided over a ceremony at which Abdellatif Hammouchi, director general of Morocco’s national security apparatus, received the Grand Cross of the Order of Merit of the Spanish Civil Guard, the institution’s highest honor for foreign dignitaries.
Grande-Marlaska praised Hammouchi’s leadership in modernizing Morocco’s intelligence and security infrastructure and described it as an important asset in counterterrorism and cross-border cooperation.
France has also honored Hammouchi with the Officer’s Medal of the Legion of Honor. These recognitions illustrate a basic reality of international relations: states facing immediate security threats tend to prioritize operational effectiveness over media controversy.
Sahel-based terrorist networks, violent proxy expansion, maritime insecurity and organized human trafficking are not abstract concerns. They demand intelligence-sharing arrangements, technical capabilities and sustained cooperation among governments.
The campaign against regional cyber capabilities has therefore proved less transformative than its organizers may have expected. The strategic framework linking Israeli technology, Moroccan national security and European defense partners remains functional, resilient and increasingly relevant as countries prepare jointly for major international events, including the 2030 FIFA World Cup.
In an era defined by hybrid warfare and accelerated digital conflict, information superiority is not a luxury. It is a central component of national sovereignty.
Public-relations campaigns organized by transnational nongovernmental organizations cannot intercept terrorist plots, secure borders or preserve regional stability. The future of global security will ultimately be shaped not by external critics, but by pragmatic states exercising what they regard as their fundamental right to defend themselves.
  • Amine Ayoub is a fellow at the Middle East Forum and a policy analyst and writer based in Morocco. Follow him on X at @amineayoubx.
Comments
The commenter agrees to the privacy policy of Ynet News and agrees not to submit comments that violate the terms of use, including incitement, libel and expressions that exceed the accepted norms of freedom of speech.
""