French govt messaging service breached in account hijacking attack
France says attackers used a hijacked account to breach Tchap, the government's encrypted messaging platform. Officials blocked the account and are checking what data may have been exposed.
Intelligence analysis by GPT-5.4 Mini

DINUM says ANSSI found unauthorized access to Tchap after a user account was compromised. The investigation is focused on which chats and files were reachable, while officials warned that public rooms are not encrypted.
A government chat app got in trouble when someone slipped in using a stolen account, like opening a locked door with a copied key. Officials locked that key and are checking which rooms and papers the intruder may have seen.
Analysis
What happened
France's digital affairs directorate, DINUM, said ANSSI detected a breach of Tchap on Sunday and traced it to a compromised user account. Tchap is the French government’s internal messaging and collaboration service, built with ANSSI and based on Matrix.
The service has grown to more than 300,000 monthly users and over 500,000 app downloads after Prime Minister François Bayrou required civil servants to use it for work communication and banned foreign messaging apps for official use in August 2025.
What officials say
DINUM said the account used for the malicious activity was identified and blocked quickly to cut off persistent access. The agency also notified France’s data protection authority, the CNIL, because some users may have shared personal data in conversations the attacker could reach. Officials reminded users that public chat rooms on Tchap can be joined by anyone and are not encrypted, so sensitive information should stay in private rooms.
What the attacker claims
A threat actor claimed responsibility over the weekend and said they used social engineering to gain access through a valid account on an education shard. The same claim included alleged theft of hardcoded LDAP credentials, more than 13.5 GB of documents and media, nearly 650,000 messages, and account metadata for over 73,000 users. Those claims were not independently verified in the article.
The breach matters because it combines account takeover, possible file exposure, and the risk of users treating public government chat spaces as private. The investigation is still ongoing, with log analysis meant to determine which conversations and data were actually accessed.
Key points
- DINUM said ANSSI detected unauthorized access to Tchap through a compromised user account.
- Officials blocked the account and opened an investigation into logs and accessed conversations.
- The agency warned that Tchap public chat rooms are accessible to any user and are not encrypted.
- An attacker claimed to have stolen messages, files, and account metadata, but those claims were not verified in the article.
Blocking the compromised account quickly may limit any further access, and the log review could show exactly what was touched. The warning about public rooms could also push users to keep sensitive information out of open chats.
If the attacker’s claims are accurate, the breach could expose personal data, meeting links, messages, and shared files across multiple shards. A successful social-engineering entry point also suggests that other accounts or reused credentials may be vulnerable.



