FIELD NOTES
A personal record of travel, networks and small failures
TRAVEL NOTE

After Morocco’s Salary Leak, I Wanted a VPN That Didn’t Ask Who I Was

The message arrived while I was waiting for a train in Casablanca: “Your salary declaration requires verification. Confirm your bank details before 18:00.” It included my employer’s name and a salary figure close enough to mine to make my stomach tighten. I blamed the MaCNSS app, opened the notification link and stopped when the page asked for my national ID number, bank details and password.

I closed the page without entering anything.

Then I opened my bank app.

It stayed on the loading screen.

The station’s mobile signal was weak, and the café Wi-Fi required a phone number before it would connect. Normally, I would have waited until I reached home. That afternoon, waiting felt irresponsible.

I needed to know whether the message was merely using leaked information to frighten me or whether someone had already reached one of my accounts.

The difference mattered more than catching the next train.

The short answer

That afternoon, the VPN that fit Morocco’s salary-leak anxiety was not the one that promised to remember more about me. It was the one that let me check my bank, payroll and social-security accounts without asking who I was first.

The message knew enough to feel real

In April 2025, Morocco’s National Social Security Fund confirmed that its systems had been targeted and that data had been leaked. The agency said it was still assessing the incident and warned that some files circulating online appeared inaccurate, incomplete or falsified. (Cnss)

That uncertainty did not make the breach harmless.

Reporting on the incident described more than 54,000 stolen files connected to nearly two million people. The exposed information reportedly included names, national identification numbers, employers, contact details, bank information and salary declarations. (Therecord)

A scammer did not need every field to be correct.

They needed enough accurate details to make the next request feel familiar.

That was what the message on my phone had done. It did not begin with a mysterious prize or an unknown invoice. It used my employer and salary to create urgency around an account I genuinely used.

The longer-term danger was obvious: once salary and identity data circulate, they can keep making fraudulent messages more convincing long after the original breach leaves the news. (Reddit)

I no longer trusted the link.

But I still needed to check the accounts it mentioned, and that meant finding a safer way online.

I needed the real services, not the link

I joined the café Wi-Fi and typed my bank’s address manually rather than returning to the message.

The login page opened, but I hesitated before entering anything. The network belonged to a busy café inside a station. Dozens of unfamiliar phones and laptops were connected around me.

A VPN could not remove my salary from a leaked file or decide whether the message was genuine.

Its immediate job was simpler: give me a protected route to the legitimate bank, email and social-security services while I checked them myself.

I opened the established VPN provider already installed on my phone.

It was a reasonable first choice. The company had years of public history, a polished application, many reviews and servers across a long list of countries.

The app had signed me out after an update.

It asked for my email address and password.

I stared at the fields.

The email address was one of the details reportedly exposed in the breach. I used a unique VPN password, but the request still felt poorly matched to the moment. I was trying to reduce the number of systems connecting my identity, email address, payment history and device.

The first security tool I opened wanted me to rebuild that connection before it would protect anything.

I signed in anyway.

An email verification code followed. I switched to my inbox, copied it and returned to the VPN app.

The code had expired.

I requested another.

By the time the connection finally opened, I had entered an email address, password and temporary code merely to protect the process of checking whether my other identities were already being abused.

The provider worked.

The problem was that it asked me to identify myself before it became useful.

The wrong account was asking for more information

The VPN connected automatically through Spain, and the bank app opened.

I ignored the message link, used the bank’s saved app and reviewed the account directly. There was no unfamiliar transfer, new beneficiary or password-reset request.

That should have made me relax.

Instead, I moved to my email and found three new messages titled CNSS Verification, Salary Declaration Update and Urgent Bank Confirmation.

They had arrived within two days.

The breach had changed the quality of the bait. The messages did not need to break into the bank themselves. They could use information I recognised to persuade me to surrender whatever details were still missing.

A strong password would not help if I typed it into a convincing imitation. Passkeys offered a cleaner defence because they worked with the legitimate service rather than asking me to type a reusable secret into a page. (Nist)

I enabled one on my email account and reviewed the bank’s security settings.

Then the station Wi-Fi dropped briefly.

The VPN disconnected and returned to its login screen.

I still had access to a large server map and advanced controls, but only after repeating part of the identity process that had bothered me in the first place.

For an ordinary trip, that might have been a small inconvenience.

After a breach connecting names, emails, salaries and financial details, it felt like the central issue.

I did not need more features attached to another conventional identity account.

I wanted the security tool to know less about me.


The free shortcut wanted the wrong access

A free browser extension appeared near the top of the app-store results.

It promised immediate protection without a subscription. I installed it, then read the permissions.

The extension wanted access to the pages I visited and the data handled inside the browser.

That failed the test I now cared about.

It protected one browser, while my bank, email and MaCNSS apps remained outside it. I would still need another solution for the rest of the phone, and I had no reason to add a broadly permissioned extension while investigating a message designed to collect personal information.

I removed it.

That brief detour clarified the decision.

I did not need the fastest app to install.

I needed one that could protect the phone without first requiring another email address, password or identity-bearing account.

The VPN started before I gave it my name

I opened the smaller app I had saved before the trip.

Basic use did not begin with an account form. It did not ask me to enter the email address already circulating in breach files or create another password I might later need to recover.

I selected the public-Wi-Fi preset.

The connection opened.

That was all.

I returned to the bank app through its saved icon, authenticated with the phone and reviewed the account again. There were no new beneficiaries, card changes or transfers.

Next, I opened my email from its official app, changed the password and signed out older sessions I no longer recognised.

Finally, I opened MaCNSS directly rather than following the message link. My genuine account contained no request to reconfirm my bank details and no notice matching the deadline in the text.

The message had manufactured urgency from leaked information.

The accounts themselves were intact.

For the first time since the notification arrived, I knew what had happened rather than merely fearing what might have happened.

I could not see the internal fraud-detection rules used by the bank, MaCNSS or the email provider. I could verify the result: the suspicious request existed only in the message, while the legitimate accounts showed no matching action.

The smaller app had given me a protected route without asking me to build another conventional identity profile first.

That difference became more valuable with every account I checked.

The laptop joined without another login trail

I still needed to inspect the payroll portal used by my employer. Its mobile layout hid the recent-login history, so I opened my laptop at the café table.

With the established provider, the next step would have been another installation, another account login and possibly another email verification.

The smaller service displayed a verification code instead.

I entered the code on the laptop, connected and opened the payroll portal from my saved bookmark.

No email address.

No password reset.

No second account-recovery trail.

The portal showed my last successful login and no unexpected change to the bank account used for salary payments. I downloaded the latest payslip and compared it with the figure in the suspicious message.

The scam had used an older declared amount.

That small error finally broke the spell.

The message had felt powerful because it knew something private. It did not know enough to survive a careful check through the real service.

I reported it to my employer’s IT contact and deleted it.

Then I warned my parents. A fake request containing a real employer, salary or identification detail could look much more convincing than the ordinary scams they were used to ignoring.

Collecting less was the feature that mattered

The smaller service has fewer locations, fewer independent ratings and a shorter public history than the established provider I tried first. That is its clearest limitation.

But location count was not the comparison that mattered at the station.

The established provider protected my traffic only after asking me to authenticate through another account tied to an email address and subscription. The free extension installed quickly, but covered the wrong part of the device and requested broad browser access. The smaller app protected the phone first, then let the laptop join through a code without collecting another set of ordinary login credentials.

The salary leak had already connected my name, employer, income, contact information and financial life in ways I never approved.

I could not reverse that from a café table.

I could decide whether the next security tool needed to add one more identity record to the pile.

That afternoon, the VPN that fit Morocco’s salary-leak anxiety was not the one that promised to remember more about me. It was the one that let me check my bank, payroll and social-security accounts without asking who I was first.

Questions this experience may leave you with

What was actually causing the problem?

That afternoon, the VPN that fit Morocco’s salary-leak anxiety was not the one that promised to remember more about me. It was the one that let me check my bank, payroll and social-security accounts without asking who I was first.

Why did the obvious fixes fail?

Instead, I moved to my email and found three new messages titled CNSS Verification , Salary Declaration Update and Urgent Bank Confirmation .

What should you check first?

The first security tool I opened wanted me to rebuild that connection before it would protect anything.

What finally changed the result?

Finally, I opened MaCNSS directly rather than following the message link. My genuine account contained no request to reconfirm my bank details and no notice matching the deadline in the text.

What is worth remembering?

The salary leak had already connected my name, employer, income, contact information and financial life in ways I never approved.