French authorities are investigating a security incident involving Tchap, the French government’s encrypted internal messaging platform used by civil servants, ministries, and public agencies. Multiple outlets report that the compromise stems from an account hijacking scenario: a threat actor took over a legitimate user account and used that access to reach public chat rooms on the service. The Interministerial Directorate for Digital Affairs (DINUM) has been cited as warning about the breach and outlining the likely access path.
Several reports also note that a threat actor claimed responsibility through underground channels, stating that they obtained large volumes of data and possibly messages and user information. However, at least one outlet says French authorities do not yet know whether any sensitive data was actually exfiltrated.
France’s government has disclosed the scale of the exposure, with figures reported around 73,000 employees whose accounts were affected. Tchap is built on the open-source Matrix protocol and is intended to run on infrastructure managed by the French state rather than foreign providers. Officials continue to assess the extent of the compromise and what data, if any, may have been accessed or stolen.