Tchap’s Encryption Held. One Stolen Account Still Exposed Public Rooms Used by 73,467 Officials.
France built Tchap so public-sector staff could communicate without moving official conversations onto consumer messaging platforms. On 7 June 2026, one compromised user account showed that sovereign hosting and encrypted private rooms do not remove the identity and access-control problem.
DINUM, the French interministerial digital directorate, said an attacker gained access after an account takeover. The agency blocked the affected account, investigated the incident with ANSSI and said that content potentially viewed was limited to public conversations. It estimated that 73,467 of Tchap’s more than 825,000 registered users were concerned.
The official notice is deliberately narrower than the attacker’s public claims. Reporting attributed to the intruder described 643,000 messages, almost 60,000 files and 13.5 GB of data. Those figures have not been independently verified. They must not be treated as a confirmed measure of the breach.
The encryption was not reported broken
Tchap supports public and private rooms. DINUM said private conversations are encrypted and that their history was not accessible through the hijacked account. No evidence presented by the government indicates a compromise of Tchap’s encryption or underlying infrastructure.
That distinction matters, but it does not make the incident trivial. Public in this context describes room access inside a government collaboration service. It does not necessarily mean that every message was intended for the open internet. A valid account could still expose discussions, membership information, shared files and operational context from rooms that many staff reasonably treated as an official workspace.
The incident therefore sits at the boundary between cryptography and authorisation. Encryption can protect a private room from someone who does not hold the right keys. It cannot protect a shared space from an account that the service accepts as a legitimate participant.
One identity reached a much larger organisational graph
The number of registered users associated with accessible public rooms illustrates the blast radius created by collaboration platforms. A single account does not only expose its owner’s inbox. It can reveal group memberships, organisational relationships, contact information and the content available wherever that identity has permission to enter.
For government, defence, healthcare and regulated organisations, that graph can be valuable even when the most sensitive messages remain encrypted. An adversary can use names, roles, project references and shared documents to improve phishing, impersonation and targeting. The breach may therefore create follow-on risk beyond the data directly viewed during the session.
The attacker and the government describe different incidents
DINUM called the event a contained intrusion and said it affected public conversations. The attacker claimed a larger collection spanning several years and said some material carried restricted-distribution markings. Neither the claimed volume nor the sensitivity labels have been independently substantiated.
The responsible editorial position is to preserve both facts: the French government confirmed an account compromise with potential access affecting 73,467 users, while the more dramatic claims remain allegations. Investigation results, notifications and any regulatory findings may narrow that gap later.
What collaboration-service operators should change
- Require phishing-resistant multifactor authentication for staff accounts, especially identities with broad room membership.
- Detect unusual enumeration, bulk history access, rapid room traversal and abnormal file retrieval from a single session.
- Limit the history visible when a user joins or re-enters large shared rooms.
- Separate genuinely public organisational channels from spaces that merely have broad internal membership.
- Provide administrators with a fast way to revoke sessions, tokens, linked devices and delegated access after an account takeover.
- Review the breached identity’s room memberships and warn affected users about credible follow-on phishing or impersonation.
Tchap’s encryption appears to have done what it was designed to do. The failure was that a stolen identity could still see a large amount of shared organisational material. Secure messaging needs both properties: strong protection for message content and strict limits on what any one authenticated account can reach.
Sources: DINUM incident notice (published 8 June 2026; no publication time provided) and The Next Web (published 9 June 2026 at 12:04; page does not identify the timezone).


