Tchap Breach — France's Government Messaging App Hijacked
Attackers hijacked a legitimate user account on Tchap, France's sovereign government messaging platform, gaining access to a system used by hundreds of thousands of public-sector employees.
What Is This Threat?
In June 2026, Tchap — France's sovereign, government-run instant messaging platform — suffered a security incident. Attackers did not break the encryption or exploit a server flaw. Instead, they compromised a single legitimate user account and used it to access the platform from the inside.
Tchap is developed by DINUM (the French inter-ministerial digital directorate) with support from ANSSI, France's national cybersecurity agency. It is the official, self-hosted alternative to WhatsApp and Signal for the French public sector, used by hundreds of thousands of civil servants to exchange internal and sometimes sensitive government communications.
Why This Matters
Tchap was specifically built to keep government conversations off commercial platforms and inside French-controlled infrastructure. A breach of even one account is serious because:
How the Attack Worked
This was an account hijacking (identity-based) attack — one of the dominant intrusion patterns seen across France in 2026:
Why Account Hijacking Is So Effective
| Traditional attack | Identity-based attack (this case) |
|---|---|
| Exploits a software vulnerability | Uses valid, stolen credentials |
| Often triggers security alerts | Looks like a normal login |
| Blocked by patching | Not stopped by patching alone |
| Needs technical exploit | Needs only a password (and no MFA) |
Because the attacker "logs in" rather than "breaks in," these intrusions are far harder to detect — the activity looks legitimate until someone notices the account behaving oddly.
The Bigger Picture in France
The Tchap incident is part of a wave of identity-based and trusted-third-party attacks hitting French government bodies in 2026. In recent months, attackers have also targeted France Travail, the Interior Ministry, and sensitive national databases. Stolen or reused credentials — not zero-day exploits — are doing most of the damage.
Red Flags Checklist
How to Protect Yourself
- Enable multi-factor authentication (MFA) on every work and government account that offers it
- Never reuse work passwords on other sites — credential reuse is a primary cause of account hijacking
- Use a password manager to generate unique, strong passwords for each service
- Be suspicious of internal messages that create urgency or ask you to log in or approve something
- Verify unexpected requests from colleagues through a second channel (phone, in person)
- Keep devices free of infostealer malware by avoiding pirated software and unverified downloads
- Regularly review active sessions and connected devices, and log out unknown ones
What to Do If Affected
- 1.If you suspect your account is compromised, change your password immediately from a trusted device
- 2.Revoke all active sessions and re-authenticate on your devices
- 3.Enable MFA right away if it was not already on
- 4.Report the incident to your IT/security team without delay — do not wait to be sure
- 5.Warn colleagues that messages from your account during the incident window may be fraudulent
- 6.In France, public bodies should follow ANSSI reporting procedures for security incidents
- 7.Watch for follow-on spear-phishing that references the breach