Skip to main content
Back to overview
Medium

French government messaging platform Tchap breached via compromised user account

DINUM, the French government's digital affairs directorate, warned that hackers breached Tchap, France's encrypted messaging platform for public sector workers, using a compromised user account.

Key points

  • Tchap, an encrypted messaging platform for French public sector, was breached.
  • Compromise occurred via a hijacked user account, likely through social engineering.
  • Over 73,000 French government employees' accounts potentially affected.

Connected intelligence

Signal brief

Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.

02

Likely method

Phishing Social Engineering

Threat source not confirmed

03

Potential impact

Potential fraud or account takeover risk

Confidentiality

Published
Jun 12, 2026
Updated
Jun 29, 2026
Confidence
Medium
Evidence
3 sources

Structured assessment

Signal analysis

This analysis groups the signal by industry, likely incident action and impacted security area. It helps compare this signal with other published signals without treating the labels as final determinations.

Threat source

Threat source not confirmed

Watch phishing, executive impersonation and account-takeover exposure.

Business impact

Potential fraud or account takeover risk
Impact area
Confidentiality
Likely asset
User or customer data

Mentioned entities

DinumData DisclosureFrenchTchapDINUMFranceANSSICNILCompromiseOver

Quick context

Questions about this signal

What happened in this signal?

DINUM, the French government's digital affairs directorate, warned that hackers breached Tchap, France's encrypted messaging platform for public sector workers, using a compromised user account. The incident was detected by ANSSI, after which the affected account was blocked and an investigation launched into what conversations and data may have been accessed. DINUM has notified France's data protection authority, CNIL, due to the potential exposure of personal data. A threat actor claimed responsibility, alleging they used social engineering to access an education-related account and scrape messages, account information, and files, including 13.5GB of data from the French tax authority and other civil servants.

When was this signal reported?

Shadow Tier lists Jun 12, 2026 as the signal date.

Which organization is connected to this signal?

Dinum is the organization connected to this public signal.

Explore Dinum
Which attack pattern is relevant?

This signal is connected to phishing and social-engineering intelligence based on its reported incident context.

Explore phishing and social-engineering intelligence