ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

French government messaging app Tchap suffers security breach, hundreds of thousands of messages allegedly stolen

France’s national cybersecurity agency confirmed a security incident involving Tchap, the government-built instant messaging platform used exclusively by French civil servants, after detecting unauthorized access on June 7, 2026. Investigators are now working to determine the full scope of the breach, including what user data may have been exposed.


Tchap is developed jointly by DINUM, the French government’s digital affairs directorate, and ANSSI, the national cybersecurity agency. Built as a fork of the secure chat application Riot, the platform is restricted to users holding a .gouv or equivalent government email address. The service counts more than 300,000 monthly active users and has surpassed 500,000 downloads on the Google Play Store.


The breach came less than a year after Prime Minister Francois Bayrou, in August 2025, required all civil servants to use Tchap for work-related communications and prohibited the use of foreign applications such as WhatsApp and Signal for official purposes.


ANSSI said the attacker gained entry through a compromised user account. The agency noted that private conversations on the platform are protected by encryption, while public conversations are not and are accessible to all users. Following the incident, a notification was sent to all Tchap users reminding them of this distinction. DINUM has also notified CNIL, France’s data protection authority, of the breach, given that personal data shared within the affected account’s conversations may have been accessible to the attacker.


A threat actor using the alias "misere" separately claimed responsibility for the attack on a dark web forum, alleging the intrusion was carried out through social engineering. The individual claimed to have exfiltrated 13.5 gigabytes of data, including 73,467 user accounts, 643,459 messages, 876 chat rooms along with their message histories, and 59,386 shared media files. The actor also alleged having accessed discussion rooms involving staff from multiple French ministries. Those claims have not been independently verified, and the investigation into what data was actually accessed remains ongoing.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543