Tchap Account Takeover Exposes 73,000 French Government Users
France's sovereign messaging platform wasn't broken — a user was. Social engineering got an attacker inside, and unencrypted public rooms did the rest.

France's Tchap platform — the Matrix-based messaging service built for government employees who were supposed to stop using WhatsApp — has been breached. Not cryptographically. Socially.
According to DINUM, France's interministerial digital directorate, an attacker took over a single user account, reportedly belonging to someone in the education sector, through social engineering. The underlying encryption was never touched. It didn't need to be.
Once inside, the attacker had access to whatever that account could see. Tchap's public chat rooms are accessible to any authenticated user and are not end-to-end encrypted. That's by design — it's the platform's open-collaboration tier. The attacker apparently saw all of it.
The exposure claim, posted publicly online, is specific: 73,467 user accounts, 643,459 messages, 876 chat rooms with full message history, 59,386 media files totalling 13.51 GB. DINUM confirmed the 73,467-user figure matches the population that could have been affected. It said it has revoked the compromised account's access and is investigating the full scope of what was accessed.
Some of the exposed material reportedly includes references to documents marked Diffusion Restreinte — France's lowest formal classification tier, roughly equivalent to "official sensitive" in UK government parlance. That's not state-secrets territory, but it's not nothing.
This is a classic privilege-abuse scenario wearing a government-messaging costume. The attacker didn't defeat the cryptography. They defeated a person, got valid credentials, and walked through the front door. SQL injection with extra steps, except here the injection vector was a phone call or a phishing lure aimed at a civil servant.
Tchap's architecture did exactly what it was designed to do. The public rooms are public. DINUM has now issued a reminder to all 825,000 users that public rooms carry no confidentiality guarantees and should never hold sensitive material. That guidance existed before this incident. It apparently needed repeating.
The real question is what account-recovery and MFA posture Tchap enforces. Social engineering works best when account takeover is easy. DINUM hasn't said which controls the attacker bypassed to seize the account, and that gap in the disclosure matters more than the message count.



