French govt messaging service breached in account hijacking attack
DINUM, the digital affairs directorate of the French government, warned that hackers used a hijacked user account to breach Tchap, the French government's encrypted messaging platform. [...]
AI Analysis
Technical Summary
DINUM, the French government's digital affairs directorate, disclosed that hackers breached Tchap, an encrypted messaging platform for the French public sector, by hijacking a user account through social engineering. The attacker accessed the platform via a compromised account on the education shard and allegedly exfiltrated over 13.5GB of documents and media files, nearly 650,000 messages, and metadata from over 73,000 accounts. The attacker also claimed to have obtained hardcoded LDAP credentials leaked via a PowerShell script. Public chat rooms on Tchap are not encrypted and accessible to all users, which was reiterated to users post-incident. The compromised account was immediately blocked, and an investigation is ongoing to determine the extent of data accessed and exfiltrated. No vendor advisory or patch information is available.
Potential Impact
The breach exposed a large volume of user data including messages, files, email addresses, organizational information, meeting links, and device metadata. Sensitive information shared in private chats may have been accessed. Public chat rooms are not encrypted and accessible to any user, potentially increasing exposure of non-sensitive data. The incident risks privacy violations and potential misuse of exposed data. The breach also undermines trust in the government’s secure communication platform.
Mitigation Recommendations
The compromised account has been blocked to remove attacker access. Users were notified to avoid sharing personal, sensitive, or confidential information in public chat rooms, which are not encrypted. No official patch or fix has been announced; patch status is not yet confirmed — check with DINUM or ANSSI for updates. Organizations using Tchap should review user account security and consider additional authentication controls to prevent social engineering attacks.
French govt messaging service breached in account hijacking attack
Description
DINUM, the digital affairs directorate of the French government, warned that hackers used a hijacked user account to breach Tchap, the French government's encrypted messaging platform. [...]
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
DINUM, the French government's digital affairs directorate, disclosed that hackers breached Tchap, an encrypted messaging platform for the French public sector, by hijacking a user account through social engineering. The attacker accessed the platform via a compromised account on the education shard and allegedly exfiltrated over 13.5GB of documents and media files, nearly 650,000 messages, and metadata from over 73,000 accounts. The attacker also claimed to have obtained hardcoded LDAP credentials leaked via a PowerShell script. Public chat rooms on Tchap are not encrypted and accessible to all users, which was reiterated to users post-incident. The compromised account was immediately blocked, and an investigation is ongoing to determine the extent of data accessed and exfiltrated. No vendor advisory or patch information is available.
Potential Impact
The breach exposed a large volume of user data including messages, files, email addresses, organizational information, meeting links, and device metadata. Sensitive information shared in private chats may have been accessed. Public chat rooms are not encrypted and accessible to any user, potentially increasing exposure of non-sensitive data. The incident risks privacy violations and potential misuse of exposed data. The breach also undermines trust in the government’s secure communication platform.
Mitigation Recommendations
The compromised account has been blocked to remove attacker access. Users were notified to avoid sharing personal, sensitive, or confidential information in public chat rooms, which are not encrypted. No official patch or fix has been announced; patch status is not yet confirmed — check with DINUM or ANSSI for updates. Organizations using Tchap should review user account security and consider additional authentication controls to prevent social engineering attacks.
Technical Details
- Article Source
- {"url":"https://www.bleepingcomputer.com/news/security/french-govt-messaging-service-breached-in-account-hijacking-attack/","fetched":true,"fetchedAt":"2026-06-09T10:55:43.922Z","wordCount":869}
Threat ID: 6a27f12f8dd33fbd852125ab
Added to database: 6/9/2026, 10:55:43 AM
Last enriched: 6/9/2026, 10:55:54 AM
Last updated: 6/9/2026, 1:30:25 PM
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.