Over 73,000 French govt employees affected in Tchap messenger breach
A breach of France’s Tchap messaging platform affected 73,467 public-sector accounts. Private chats stayed encrypted, but public-room data may have exposed names and emails.
Intelligence analysis by GPT-5.4 Mini

France says a compromised Tchap account let an attacker access public chat-room data on its government messaging platform. The incident affected 73,467 of more than 825,000 registered agents, while private encrypted chats remained protected.
It is like someone sneaking into one locker in a school and copying names from the public noticeboard, while the locked private notes stay safe. The thief got some contact details from Tchap’s open rooms, but the private chats were still locked away.
Analysis
What happened
DINUM, France’s digital affairs directorate, says a threat actor gained access to Tchap through a compromised user account. The agency notified CNIL because some personal data shared by users may have been exposed, then later said the incident affected 73,467 agents, or less than 9% of the platform’s more than 825,000 registered users.
What was exposed
DINUM draws a line between private and public communication inside Tchap. Private conversations are encrypted and remained protected, but public chat rooms are open by design and not encrypted. From those public rooms, the attacker could access names, email addresses, avatar images, and the public-sector organization attached to affected accounts.
Why this matters
Even when message content is not taken, exposed account metadata can still be useful to attackers. Names, emails, and organization details can support phishing, impersonation, and other social-engineering attempts against civil servants.
The article also notes that the threat actor claimed responsibility over the weekend and shared sample files, saying the breach followed a social-engineering attack. Those claims are not attributed by the French government in the article, but they raise the possibility of a broader theft than DINUM has confirmed so far. The attacker allegedly scraped nearly 650,000 messages and more than 13.5GB of documents and media, along with hardcoded LDAP credentials, though those allegations remain unverified in the report.
Tchap was developed by DINUM with ANSSI and is based on Matrix. It became the default work messaging app for French civil servants in August 2025 and has since grown to more than 300,000 monthly users, making even a limited breach operationally significant.
Key points
- DINUM says a compromised user account was used to access Tchap.
- 73,467 accounts were affected, according to the government update.
- Private chats stayed encrypted, but public-room data was exposed.
- The exposed data included names, emails, avatars, and organization details.
- The threat actor also claimed larger-scale scraping, but those claims are unverified in the article.
DINUM says it identified the malicious account and blocked it, which could stop further access while investigators review what was reached. Private conversations remained encrypted, limiting the confirmed exposure to public-room data.
The exposed names, emails, organization details, and avatars could still help phishing or impersonation attacks against public employees. If the attacker’s broader claims are accurate, the incident may involve far more data than the government has confirmed so far.



