LIVE: New phishing campaigns targeting mobile users —View latest threats →

Back to Threats
High💾 Data BreachNEW

Tchap Breach — France's Government Messaging App Hijacked

Attackers hijacked a legitimate user account on Tchap, France's sovereign government messaging platform, gaining access to a system used by hundreds of thousands of public-sector employees.

Published: 22 June 2026

What Is This Threat?

In June 2026, Tchap — France's sovereign, government-run instant messaging platform — suffered a security incident. Attackers did not break the encryption or exploit a server flaw. Instead, they compromised a single legitimate user account and used it to access the platform from the inside.

Tchap is developed by DINUM (the French inter-ministerial digital directorate) with support from ANSSI, France's national cybersecurity agency. It is the official, self-hosted alternative to WhatsApp and Signal for the French public sector, used by hundreds of thousands of civil servants to exchange internal and sometimes sensitive government communications.

Why This Matters

Tchap was specifically built to keep government conversations off commercial platforms and inside French-controlled infrastructure. A breach of even one account is serious because:

  • A trusted internal account can read group conversations and directories
  • Attackers can harvest the names, roles, and contact details of other officials
  • A hijacked government identity is a powerful springboard for spear-phishing colleagues
  • It undermines confidence in a platform designed to be the "secure" choice
  • How the Attack Worked

    This was an account hijacking (identity-based) attack — one of the dominant intrusion patterns seen across France in 2026:

  • Attackers obtained valid credentials for one Tchap user (via phishing, credential reuse, or infostealer malware)
  • They authenticated as that legitimate user — no exploit or malware needed on the server side
  • From inside, they could access conversations and contact directories available to that account
  • The trusted account becomes a launch point for further internal social engineering
  • Why Account Hijacking Is So Effective

    | Traditional attack | Identity-based attack (this case) |

    |---|---|

    | Exploits a software vulnerability | Uses valid, stolen credentials |

    | Often triggers security alerts | Looks like a normal login |

    | Blocked by patching | Not stopped by patching alone |

    | Needs technical exploit | Needs only a password (and no MFA) |

    Because the attacker "logs in" rather than "breaks in," these intrusions are far harder to detect — the activity looks legitimate until someone notices the account behaving oddly.

    The Bigger Picture in France

    The Tchap incident is part of a wave of identity-based and trusted-third-party attacks hitting French government bodies in 2026. In recent months, attackers have also targeted France Travail, the Interior Ministry, and sensitive national databases. Stolen or reused credentials — not zero-day exploits — are doing most of the damage.

    Red Flags Checklist

  • ❌ A colleague's account sends unusual messages, links, or requests
  • ❌ Login notifications from unfamiliar devices or locations
  • ❌ Messages pushing urgency or asking for credentials/approvals
  • ❌ Contacts you never messaged suddenly appearing in conversations
  • ❌ Account settings (recovery email, sessions) changed without your action
  • How to Protect Yourself

    • Enable multi-factor authentication (MFA) on every work and government account that offers it
    • Never reuse work passwords on other sites — credential reuse is a primary cause of account hijacking
    • Use a password manager to generate unique, strong passwords for each service
    • Be suspicious of internal messages that create urgency or ask you to log in or approve something
    • Verify unexpected requests from colleagues through a second channel (phone, in person)
    • Keep devices free of infostealer malware by avoiding pirated software and unverified downloads
    • Regularly review active sessions and connected devices, and log out unknown ones

    What to Do If Affected

    1. 1.If you suspect your account is compromised, change your password immediately from a trusted device
    2. 2.Revoke all active sessions and re-authenticate on your devices
    3. 3.Enable MFA right away if it was not already on
    4. 4.Report the incident to your IT/security team without delay — do not wait to be sure
    5. 5.Warn colleagues that messages from your account during the incident window may be fraudulent
    6. 6.In France, public bodies should follow ANSSI reporting procedures for security incidents
    7. 7.Watch for follow-on spear-phishing that references the breach
    #Tchap#France#account hijacking#government#identity#ANSSI#2026