Morocco Investment Ministry Data Claim Includes 150,000 Folders and Records on 50,000 Investors
A threat actor using the handle "anisans2" claims to be selling a dataset purportedly from Morocco's Ministry of Investment (MICEPP) containing more than 150,000 folders, records on over 50,000 investors and 400+ GB of material. The claim is unverified and could expose administrative, authorization and national ID–related data if authentic.

Morocco's Ministry of Investment, Convergence and Evaluation of Public Policies (MICEPP) is the subject of a claim by an actor using the handle "anisans2" who says they are selling a dataset that includes more than 150,000 folders, records relating to over 50,000 investors and in excess of 400 GB of material. The actor advertises samples and says the material contains administrative documents, authorization records and national ID–related data relating to Moroccan companies, public institutions and individuals, and is offering the full dataset for sale either in whole or in parts.
"More than 150,000 folders, records relating to more than 50,000 investors, administrative and national ID‑related material, a dataset exceeding 400 GB," the listing claims, with samples and sale terms shown in a supplied screenshot.
Context and details
The listing identifies the targeted organization as Morocco's Ministry of Investment, Convergence and Evaluation of Public Policies (MICEPP) and uses the actor handle "anisans2." Contact channels visible in the listing include a Telegram channel, @pka291channel, and a Telegram backup link referenced as t[.]me/pka291backup. The actor states the dataset contains administrative and authorization documents, national ID‑related material, and investor information tied to Moroccan companies and public institutions.
Claims in the listing include:
- More than 150,000 folders extracted
- Data concerning more than 50,000 investors
- Administrative and authorization documents included
- National ID‑related data included
- Dataset exceeding 400 GB in size
- Samples advertised; full dataset offered for sale; seller accepts offers and will sell in parts
The material presented in the screenshot documents the seller's assertions and sale terms, but the dataset, its provenance, the actor's possession of the complete material, and the stated volumes have not been independently verified. The screenshot alone does not disclose the acquisition method, nor does it provide sufficient underlying content to confirm the named organizations or to determine how records are distributed across the claimed dataset.
Potential impact and response
If authentic, the claimed files could expose administrative documents, authorization records and national ID‑related information tied to Moroccan companies, public institutions and individuals. The post itself notes possible consequences: such data might enable identity fraud, targeted phishing, impersonation, business‑email compromise or intelligence gathering against organizations represented in the dataset.
At present, the status of the claim remains unverified. The actor advertises sample documents and invites offers for purchase; the listing indicates the dataset can be bought in parts. No Tox ID, session ID, malware hash, attacker‑controlled domain or IP address is visible in the supplied capture, and no definitive proof of unauthorized access to MICEPP systems has been provided in the materials shown.
Outlook: Authorities and affected organizations would need to confirm whether the files are genuine, identify any breach vector, assess the scope of exposed data and notify impacted individuals or entities. Meanwhile, the presence of contact channels such as Telegram’s @pka291channel suggests the seller is prepared to transact, underscoring the importance of rapid verification and incident response should the claim prove accurate.
Stay in the loop
Join our weekly newsletter and get the latest MENA startup news, funding rounds, and insights delivered straight to your inbox.