SYS::ONLINE
Wasteland.
Briefs1594
Issues21
SinceFeb 2026
LIVE
▣ Breach FRENCH-GOVERNMENT- 2026-07-29

Tchap: 'Misere' Account Hijack Breach of France's Government Messaging Platform

"France's sovereign, government-only messaging service Tchap was compromised on 7 June 2026 after an attacker took over a legitimate user account. The intrusion was detected by ANSSI, France's national cybersecurity…"

France's sovereign, government-only messaging service Tchap was compromised on 7 June 2026 after an attacker took over a legitimate user account. The intrusion was detected by ANSSI, France's national cybersecurity agency, and disclosed the following day by DINUM, the interministerial digital directorate that operates the platform. DINUM's figures, as relayed by SecurityWeek and multiple secondary outlets, put the impact at 73,467 affected agents out of more than 825,000 registered users, or under 9 percent of the user base. A previously unknown threat actor calling itself "misere" claimed responsibility and broadly agreed with the government's account count, but asserted a far larger haul: 13.5GB of files spanning more than 643,000 messages. That second claim has not been independently verified, and the government has not confirmed it. Note that none of the available reporting is a first-party DINUM or CNIL publication; every version of the official position reaching this brief passes through press intermediaries.

What Happened

The timeline is consistent across sources. On 7 June 2026, ANSSI detected suspicious activity on Tchap, the Matrix-based instant messaging service launched in 2019 for French public sector use and pushed hard across the administration by a July 2025 prime ministerial circular, per AEF info. DINUM investigated, blocked the affected account, and publicly confirmed the compromise on 8 June, describing it as the result of an account usurpation rather than a break in the platform's cryptography.

Tchap's architecture matters to what follows. It offers end-to-end encrypted rooms alongside "public" rooms that are open to all Tchap users and are not encrypted. The official position is that the attacker's visibility was confined to the public rooms, and that private conversations remained encrypted and unreadable even from a hijacked account. DINUM notified CNIL, France's data protection regulator, of the potential exposure of personal data.

The disagreement is over scope, not over whether a breach occurred. Officials frame this as a contained incident affecting non-encrypted spaces. Misere frames it as a bulk theft of government user data and message content. SecurityWeek is explicit that the actor's side is unverifiable: the claim was relayed by the OSINT FrenchBreaches community rather than published directly, and the original posting is no longer available online. SecurityWeek also raises a plausibility question, asking whether an otherwise unknown actor could realistically collect and exfiltrate 13.5GB in a single day. Accounts genuinely differ here, and neither version has been closed out publicly.

What Was Taken

The confirmed side, attributed to DINUM through the reporting, covers account directory data rather than conversation secrets. Privacy01 and OpsecInsider list first and last names, email addresses, profile avatars, government organization affiliation, public chat room messages, and account and device metadata. OpsecInsider singles out the affiliation field as the sharpest element: it binds each named individual and work email to a specific ministry or department, converting an ordinary contact list into a mapped org chart of who serves where.

Volume figures vary by source and by whose account you accept. On users, DINUM's number is 73,467 affected of 825,000-plus registered, cited that way by SecurityWeek, OpsecInsider and Privacy01; stcadoc.org reports the actor claiming "over 73,000 user accounts," and SecurityWeek characterizes misere's own claim as "more than 70k accounts," which it notes aligns with the official count. On content, SecurityWeek reports misere claiming 13.5GB across more than 643,000 messages; Security Boulevard's headline treats 643,000 stolen government messages as the framing figure; stcadoc.org adds, from the actor's claims alone, nearly 60,000 media files and hundreds of chat rooms.

Two further claims sit on a single OTHER-tier source and should be treated as unconfirmed. stcadoc.org reports the actor asserting that the stolen material includes documents marked "Diffusion Restreinte," France's restricted-distribution classification, and that user enumeration was possible through a directory search function. If either holds up, the severity assessment changes materially: restricted-distribution content in a public room would be a handling failure independent of the intrusion, and a working enumeration path would explain how a single hijacked account reached a five-figure user list. Neither has been corroborated elsewhere in this source set.

Why It Matters

Tchap exists precisely so that French civil servants would not route sensitive work conversation through WhatsApp, Telegram or Signal. The sovereignty argument was that domestic control of infrastructure plus strong encryption beats trusting foreign platforms. This incident does not refute the encryption claim; by all available accounts the end-to-end encrypted rooms held. It refutes something else, which is the assumption that a sovereign platform's non-encrypted surfaces and its identity layer are low-risk by comparison.

Security Curated frames the event as a test of French digital autonomy, and the framing is fair even if its language runs hot. The practical damage is a high-fidelity targeting dataset: verified names, verified government emails, and departmental affiliation for tens of thousands of public sector employees, all drawn from a directory that had been vouched for as the trustworthy alternative. That is a spear-phishing kit with institutional credibility attached, and it lands against a backdrop AEF info describes, in which French intelligence services had already flagged a surge in attack campaigns against instant messaging accounts in sovereign-function sectors.

There is a governance lesson too. A platform mandated top-down for wide adoption accumulates a directory whose value grows faster than its perceived sensitivity. The messages were the protected asset; the membership list turned out to be the one that leaked.

The Attack Technique

The mechanism, per DINUM as reported, is account hijacking rather than exploitation of a platform vulnerability or a defeat of Matrix encryption. The attacker operated with a legitimate account's authority, which is why encrypted room content stayed out of reach while every unencrypted surface that account could see was fair game.

On how the account itself was taken, the most specific detail comes from a single OTHER-tier relay: Vuink, republishing The Register, reports the criminal claiming they "social engineered" a valid agent account tied to Tchap's education environment. That has not been confirmed by DINUM in the available reporting, but it is consistent with the official description of usurpation and with the pattern of intelligence warnings about messaging-account campaigns in the public sector. Treat it as the actor's account of their own tradecraft, not as established fact.

Post-access behavior, again per the actor's claims, looks like bulk collection rather than targeted reading: joining or scraping public rooms at scale, pulling message history and media, and, if the enumeration claim is accurate, walking the user directory to assemble the account list. DINUM identified the malicious account and blocked it, and investigators have been working through logs to establish what was actually reached.

What Organizations Should Do

  1. Harden authentication on internal messaging before anything else. This breach began at login, not in the protocol. Enforce phishing-resistant MFA (FIDO2 or certificate-based) on chat platforms, and treat federated or secondary environments such as education, contractor or training tenants as full-privilege entry points, because they are.
  2. Audit what lives in your unencrypted rooms. Every open channel should be reviewed for content that was never meant for platform-wide readership, especially anything carrying a restricted-handling marking. Classification policy has to be enforced at post time, not discovered during incident response.
  3. Rate-limit and log directory access. User search and member enumeration are the mechanism that turns one stolen account into a bulk dataset. Cap query volume per account, alert on directory sweeps, and constrain visibility of affiliation fields so a single compromise cannot export the org chart.
  4. Segment room membership by need. Default-open rooms that all users can join give any hijacked account platform-wide reach. Scope room discovery and joinability to departments or roles so blast radius tracks the compromised account's actual remit.
  5. Assume the directory data is now targeting material and brief accordingly. Warn affected staff that name, work email and department are in adversary hands, and prepare for convincing spear-phishing that references real colleagues and real reporting lines. Pair the warning with an out-of-band verification route for unusual requests.
  6. Retain and review session logs for lateral messaging activity. Detection here came from anomaly monitoring, not from the platform. Ensure chat platform telemetry (joins, bulk downloads, media pulls, device registrations) flows to your SIEM with retention long enough to reconstruct a multi-day intrusion, and hunt retroactively for the same pattern.

Sources: French Government Hacked! Tchap Messaging App Compromised - What Yo... | French Government Messaging Platform Breached by Mysterious ‘Misere... | Tchap Data Breach Hits 73.000 French Officials | France Built Its Own Messaging App to Replace Signal. Then Hackers... | France probes compromise of gov messaging platform after account hi... | Tchap Breach Exposes Data of Over 73,000 French Government Employee... | Is the Misere Breach a Threat to French Data Sovereignty? Security... | La Dinum confirme une compromission de la messagerie Tchap à la sui...