French authorities are investigating a security incident affecting Tchap, the government messaging platform used by public sector employees across France. The breach allegedly exposed data linked to more than 73,000 accounts after an attacker gained access through a compromised user account.

The incident has raised concerns about the security of government communication platforms and the growing threat posed by account hijacking and social engineering attacks. While investigators have confirmed unauthorized access, officials continue to assess the full scope of the compromise.

Attackers Allegedly Accessed More Than 73,000 Accounts

According to claims published online by a threat actor known as “misere,” the breach resulted in the theft of approximately 13.5GB of data. The attacker claims to have accessed information tied to 73,467 user accounts, more than 643,000 messages, nearly 60,000 shared media files, and hundreds of chat rooms used by government employees.

The threat actor also claimed to have accessed discussion rooms involving personnel from several French government ministries. French authorities have not verified the full extent of those claims and continue to investigate what information the attacker may have accessed.

Compromised Account Opened the Door

France’s digital affairs directorate, DINUM, confirmed that the incident began when an attacker gained access to a legitimate Tchap account. Investigators believe the compromise resulted from an account hijacking attack rather than a direct breach of the platform’s core infrastructure.

After detecting suspicious activity, authorities immediately blocked the compromised account and launched a forensic investigation. Officials are reviewing logs to determine which conversations and files the attacker may have viewed or exfiltrated.

The French cybersecurity agency ANSSI continues to work alongside DINUM to assess the incident and identify any additional security risks.

Private and Public Conversations Face Different Risks

Authorities emphasized that private conversations on Tchap use encryption protections. However, public chat rooms operate differently and remain accessible to any authorized platform user. Investigators currently believe the attacker may have accessed information stored within public discussion channels.

Following the breach, DINUM reminded users not to share sensitive, confidential, or personal information in public chat rooms. Officials also notified France’s data protection authority, CNIL, because some personal information may have been exposed through accessible conversations.

The investigation remains ongoing as authorities continue evaluating the potential impact on affected users.

Social Engineering Remains a Serious Threat

The Tchap incident highlights the effectiveness of social engineering attacks against government systems. Rather than exploiting a technical vulnerability, attackers often target users directly through phishing campaigns, credential theft, or other manipulation techniques.

Government agencies worldwide have reported increased attempts to compromise communication platforms through account takeovers. Recent warnings from European and U.S. authorities have highlighted efforts by threat actors to gain access to messaging applications used by government employees, military personnel, and other public officials.

Security experts continue to encourage organizations to strengthen account protections through multi-factor authentication, security awareness training, and improved monitoring of suspicious login activity.

Final Thoughts

The Tchap data breach has affected more than 73,000 accounts according to claims made by the attacker, although French authorities continue to investigate the full scope of the incident. Officials have confirmed that a compromised user account enabled unauthorized access to the government messaging platform.

While investigators work to determine what information the attacker accessed, the breach serves as another reminder that account hijacking and social engineering remain effective methods for targeting even highly restricted government communication systems.


0 responses to “Tchap Data Breach Impacts More Than 73,000 Accounts”