French Government Tchap Messenger Breach Exposes 73,000 Public Sector Accounts
The French government disclosed a breach of its Tchap encrypted messaging platform that affects over 73,000 public sector employees. Attackers compromised a user account and scraped data from public chat rooms, exposing names, email addresses, and government organization details. Consequently, France’s data protection authority has been notified as officials investigate the full scope of the incident.
What Happened: Tchap Messenger Breach Exposes 73,000 French Government Accounts
On June 9, 2026, DINUM (the French government’s digital affairs directorate) reported that an unauthorized party had gained access to the Tchap platform. The attacker used a compromised user account to infiltrate the system and harvest information from public chat rooms.
Tchap is an encrypted messaging service built on the Matrix protocol. It was developed by DINUM in collaboration with ANSSI, France’s cybersecurity agency, in 2018. Furthermore, the platform became the default work communication app for all French civil servants in August 2025. It now serves over 300,000 monthly users and has more than 825,000 registered accounts.
In an update on June 12, 2026, DINUM confirmed that 73,467 agents were affected by the incident. This figure represents roughly 9 percent of all registered users on the platform. The attacker scraped data from public forums, which are open to all users and not encrypted by design. Therefore, private conversations remained protected, but public room content was fully exposed.
Technical Details of the Tchap Messenger Breach
The breach began with a compromised user account. The attacker leveraged this account to access the Tchap platform and systematically scrape data from public chat rooms. While Tchap encrypts private direct messages and private group conversations, public forums lack end-to-end encryption.
DINUM quickly identified the malicious account and blocked it to remove persistent access. However, the attacker had already collected a significant volume of data during the intrusion window.
Data Exposed in Public Chat Rooms
The following categories of information were accessed during the breach:
- Personal identifiers: Last names, first names, and email addresses of affected users.
- Organizational data: The public sector entity each user belongs to.
- Profile images: User avatars uploaded to the platform.
- Public messages: An estimated 650,000 messages scraped from public forums.
- Shared files: Over 13.5 GB of documents and media files uploaded to public rooms.
- Technical metadata: Account and device metadata, as well as hardcoded LDAP credentials leaked via a PowerShell script.
Attacker Claims and Attribution
An unidentified threat actor claimed responsibility for the attack over the weekend. The actor stated they gained access through a social engineering attack and published a sample of stolen files as proof. However, DINUM has not officially attributed the breach to any specific group. French authorities continue to investigate the incident.
Business and Operational Impact
The Tchap messenger breach carries significant implications for the French public sector and beyond. The impact spans operational, reputational, and security domains:
- Government communications exposure: Public sector employees’ identities and affiliations are now in attacker hands. This information can enable targeted phishing and social engineering against high-value government targets.
- Meeting link compromise: Exposed meeting links from public chat rooms could allow unauthorized access to future or ongoing government discussions.
- Document leakage: Over 13.5 GB of shared files may contain sensitive operational details, policy drafts, or internal guidance.
- Credential risk: Hardcoded LDAP credentials leaked via a PowerShell script create an immediate privilege escalation risk if those credentials are still active.
- Reputational damage: A breach of a government-endorsed encrypted messaging platform undermines trust in France’s secure communication infrastructure.
- Regulatory scrutiny: CNIL, France’s data protection authority, has been notified. This may lead to compliance reviews and potential penalties.
Moreover, this incident highlights a broader risk in encrypted messaging platforms. Public rooms that are not encrypted create a blind spot that attackers can exploit even when private channels are secure.
Mitigation and Recommendations
Organizations using Tchap or similar government-grade messaging platforms should act immediately to reduce risk and strengthen controls.
Immediate Actions for Defenders
- Audit public room membership and content. Review all public forums for sensitive data, shared credentials, or confidential documents. Remove or relocate sensitive discussions to encrypted private rooms.
- Rotate exposed credentials. If LDAP or service account credentials were shared in public chat rooms, change them immediately. Also review any integration keys or API tokens posted in public channels.
- Review user account access logs. Identify any accounts with anomalous login patterns, excessive data downloads, or unusual scraping behavior.
- Enable multi-factor authentication (MFA). Ensure all Tchap accounts require MFA. Compromised passwords alone should not grant platform access.
- Warn users about phishing risks. Inform affected employees that their email addresses and organizational details are exposed. Provide guidance on spotting targeted phishing attempts.
Long-Term Hardening Measures
In addition to immediate fixes, organizations should re-evaluate how public rooms are used within secure messaging platforms. Public forums should be reserved for non-sensitive announcements only. Furthermore, implement automated data loss prevention scanning for files and messages shared in any room that lacks end-to-end encryption.
Administrators should also disable file uploads in public rooms where possible. If file sharing is required, route uploads through a secure document management system with access controls and audit logging.
Bottom line: The Tchap breach proves that encryption alone is not enough. Public rooms in messaging platforms remain a persistent blind spot. Audit your public channels, rotate exposed credentials, and treat messaging platforms as part of your overall attack surface.
Incident Summary
| CVE ID / Incident: | Tchap encrypted messaging platform breach (no CVE assigned) |
| Affected Systems: | Tchap public chat rooms; 73,467 of 825,000+ registered French public sector accounts |
| Disclosure Date: | June 9, 2026 (updated June 12, 2026) |
| Patch Status: | N/A — platform compromise via compromised user account |
| Threat Actor: | Unattributed; an unidentified actor claimed responsibility |
| Data Exposed: | Names, email addresses, organizations, avatars, ~650,000 public messages, 13.5 GB+ of files, LDAP credentials |
References
- DINUM (French Government Digital Affairs Directorate), “Incident sur la messagerie Tchap — Mise à jour,” June 12, 2026, https://www.bleepingcomputer.com/news/security/french-govt-says-tchap-breach-affected-over-73-000-accounts/ (via BleepingComputer coverage)
- BleepingComputer, “Over 73,000 French govt employees affected in Tchap messenger breach,” June 12, 2026, https://www.bleepingcomputer.com/news/security/french-govt-says-tchap-breach-affected-over-73-000-accounts/
- BleepingComputer, “French govt messaging service breached in account hijacking attack,” June 9, 2026, https://www.bleepingcomputer.com/news/security/french-govt-messaging-service-breached-in-account-hijacking-attack/
- Legifrance, “Circulaire relative à l’utilisation de Tchap,” August 2025, http://www.legifrance.gouv.fr/circulaire/id/45618
- ANSSI (French Cybersecurity Agency), Tchap platform overview and security guidance, https://www.ssi.gouv.fr/