French authorities are investigating a breach of Tchap, the encrypted messaging service used across the French public sector, after ANSSI detected suspicious activity tied to a compromised account and DINUM blocked the access. Officials said the confirmed exposure was limited to public chat rooms on an education-related Tchap shard, while private one-to-one and private group conversations remained protected by encryption. DINUM said it alerted users, notified France’s data protection authority CNIL, and is reviewing logs to determine what data may have been accessed or exfiltrated.
A threat actor claimed the intrusion was achieved through social engineering and alleged far broader access than the government has confirmed, including roughly 643,000 messages from 876 public rooms, data tied to about 73,000 accounts, media files, and possible references to documents marked "Diffusion restreinte". Other unverified claims included theft of account data and hardcoded LDAP credentials, as well as weaknesses in file access controls. French officials have not validated those assertions and said the investigation is ongoing.

See attribution, scope, and your downstream exposure.
7 events from the most recent confirmed update back to the earliest known activity.
French authorities disclosed that the Tchap breach affected 73,467 public-sector employees, representing less than 9% of registered users. DINUM said the exposure involved data from unencrypted public chat rooms, including possible names, email addresses, avatar images, and affiliated organizations.
French authorities opened a criminal investigation into the Tchap intrusion, with the Paris prosecutor assigning the Office anti-cybercriminalité (Ofac) to investigate suspected unauthorized access and misuse of personal data in a state-run system.
DINUM disclosed that Tchap had been breached via a compromised account and said the confirmed exposure was limited to non-encrypted public chat rooms, while private conversations remained protected by encryption. Authorities said they were still assessing what was accessed or exfiltrated.
A threat actor publicly claimed the intrusion was achieved through social engineering of a valid account on an education-related Tchap shard, enabling access to public chat rooms. The actor alleged theft of messages, files, account data, and other material, though French authorities had not verified the broader claims.
French officials notified CNIL because personal information may have been exposed through accessible conversations, and DINUM said users were alerted about the incident. These actions were part of the official response to the Tchap breach.
After the compromise was identified, DINUM blocked the originating account and began reviewing logs to determine what data may have been accessed or exfiltrated. DINUM also said the incident may have exposed personal data in conversations.
French authorities said ANSSI detected suspicious activity involving a compromised Tchap user account on June 7, triggering the incident response. The compromise was tied to an account hijacking on the French government messaging platform.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
10 references tracked. Mallory keeps watching after this page renders.
securityweek.com
Open sourcebleepingcomputer.com
Open sourcexakep.ru
Open sourcezdnet.fr
Open sourcehelpnetsecurity.com
Open sourcetheregister.com
Open sourcebleepingcomputer.com
Open sourcezdnet.fr
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.