2026 Tchap — French government messaging breach; 73,467 civil servants (public rooms)
Data compromised
Public chat room content and organizational metadata; private E2E conversations not affected per DINUM
Technical writeup
France’s Interministerial Directorate for Digital Affairs (DINUM) confirmed a June 7, 2026 security incident on Tchap, the government’s Matrix-based messaging platform for civil servants. ANSSI detected malicious activity via a compromised user account; DINUM blocked the account and stated end-to-end encrypted private chats were not impacted. In a June 12, 2026 update cited by BleepingComputer, DINUM said roughly 73,467 registered agents—under 9% of more than 825,000 users—may be affected because attackers accessed unencrypted public chat rooms, exposing names, email addresses, avatars, and public-sector organization affiliations. Actor marketing claiming ~650,000 messages and 13.5 GB of files remains partially unverified versus the official count; BreachHistory uses DINUM’s 73,467 figure.
Root cause
Compromised user account used to access public chat rooms on Tchap (Matrix-based civil-service messenger)
References
- https://www.numerique.gouv.fr/sinformer/espace-presse/incident-tchap/
- https://www.bleepingcomputer.com/news/security/french-govt-messaging-service-breached-in-account-hijacking-attack/
- https://www.helpnetsecurity.com/2026/06/09/tchap-french-government-secure-messaging-platform-breach/
- https://www.bleepingcomputer.com/news/security/french-govt-says-tchap-breach-affected-over-73-000-accounts/