Tchap Account Takeover Exposes 73,000 French Government Users
France's sovereign messaging platform wasn't broken, a user was. Social engineering got an attacker inside, and unencrypted public rooms did the rest.

Key points - An attacker seized a single Tchap account through social engineering, not by breaking the platform's encryption - Public chat rooms accessible to the compromised account potentially exposed 73,467 users - The breach included hundreds of thousands of messages and tens of thousands of media files - Some material reportedly referenced documents at France's lowest formal classification tier - DINUM has not disclosed which authentication controls the attacker bypassed
France's Tchap platform, the Matrix-based messaging service built for government employees, has been breached. Not cryptographically. Socially.
According to DINUM, France's interministerial digital directorate, an attacker took over a single account belonging to someone in the education sector. The encryption was never touched. It didn't need to be.
What did the attacker actually access?
Tchap's public chat rooms are open to any authenticated user and carry no end-to-end encryption. That's by design, the platform's open-collaboration tier. Once inside, the attacker could see all of it.
DINUM confirmed the 73,467-user figure matches the population potentially affected, revoked the compromised account's access, and is investigating the full scope.
Some exposed material reportedly references documents marked Diffusion Restreinte, France's lowest formal classification tier, roughly equivalent to "official sensitive" in UK government terms. Not state-secrets territory, but not nothing.
Should you worry about the platform's design?
Tchap's architecture did exactly what it was designed to do. This is a privilege-abuse scenario in a government-messaging costume. The attacker didn't defeat the cryptography; they defeated a person, then walked through the front door with valid credentials. Our earlier look at prompt-bombing attacks from 28 May made the same point: the weakest link in most account-security chains is the moment a tired or deceived user hands over access.
DINUM has since reminded all 825,000 users that public rooms carry no confidentiality guarantees and should never hold sensitive material. That guidance existed before this incident. It apparently needed repeating.
What actually needs answering?
The real gap in the disclosure is account-recovery posture. Social engineering works best when takeover is straightforward. DINUM hasn't said which controls the attacker bypassed, and that silence matters more than the message count. If Tchap lacks enforced multi-factor authentication or has a weak account-recovery path, the architecture problem isn't the public rooms; it's the front door.
For security teams running similar sovereign or self-hosted messaging deployments, the lesson is the one it always is: classify your data tiers before you configure your rooms, enforce MFA without exceptions, and treat account-recovery flows as an attack surface worth auditing now rather than after the next incident.



