France has set up its own encrypted messenger so that civil servants don’t have to rely on WhatsApp or Telegram. Now that messenger has been compromised, and the government and the attacker can’t agree on how much was intercepted.
France’s National Cyber Security Agency, ANSSI, discovered that Tchap was compromised on June 7, and the Directorate of Digital Affairs (DINUM), which manages the platform, published an incident notification and moved to block the associated account. Crucially, it wasn’t a crack in encryption or infrastructure.
Officials say the attacker compromised the credentials rather than the system itself by taking over a legitimate user account.
The government’s account of the damage is tight. Tchap, that is built on the open Matrix protocolconducts both public and private conversations, and private ones end-to-end encrypted. DINUM states that even when impersonating an account, the history of those private encrypted chats remains inaccessible, and only unencrypted public chat rooms that any authenticated user can find and join may have been viewed.
Investigators are still working through the records to determine what conversations were accessed and whether any information was taken. DINUM warned data protection regulator CNIL because personal data may have been exposed in content an attacker could see, and reminded users that public rooms are no place for sensitive material.
The abuser tells a bigger story. A threat actor using the “Misère” handle claims to have accessed approximately 73,000 government agents, 643,000 messages, approximately 60,000 files of approximately 13.5 gigabytes, hundreds of chat rooms, and nearly 90 items referencing Diffusion Restrainte. 2023 – June 2026.
The attacker says that access was done through a social engineering account in Tchap’s educational environment, and that the directory search function allowed the user to be listed on the service.
These figures, relayed by dark web intelligence channels and repeated by French security authorities, have not been confirmed by ANSSI or DINUM, whose statements do not mention restricted documents, directory disclosures or any referenced volume.
Several French infosec analysts have kept the numbers out of public breach trackers due to a lack of independent confirmation. They remain an aggressor’s claim, not an established fact.
There is a technical nuance that makes it difficult to reassure the government.
End-to-end encryption protects messages in transit and at rest, so the server cannot hand over old private conversations. But security researchers note that completely stealing someone’s logged-in account is different: an attacker posing as that user can, in principle, see everything the account is doing at the time, including opening private rooms. Encryption is maintained; imitation is a hole.
That’s what Tchap represents, the creator of this sting. DINUM and ANSSI launched it in 2019 as a state-run, French-run alternative to WhatsApp, Telegram and Slack, so that government communications don’t sit on foreign-run services.
Since 2025, it has been handed over to hundreds of thousands of state agents across ministries, and falls in the middle of a wider French movement for technological independence that has seen Paris. order the ministries to Windows and Linux Europe is more open to it relying on foreign technology such as political risk.
The gap between “several public rooms” and “73,000 accounts and restricted document references” will be bridged not by press releases, but by journal analysis. For a service whose entire capabilities can be trusted to manage its own secure communications, even existing breaches are an awkward challenge.
The high-profile, unconfirmed hacking claim is the kind of story that sovereignty skeptics and France’s opponents will be happy to amplify.






