The images in this article were generated with artificial intelligence. How we publish
The Directorate Interministérielle du Numérique (DINUM) confirmed this week what was already running as a rumor: an intrusion into Tchap, the messaging platform developed for the French administration, affected a significant volume of civil service accounts. According to official figures, around 73,467 accounts Among more than 825,000 registered users, information associated with public profiles and messages has been compromised; DINUM has already notified the data protection authority (CNIL).
Tchap is based on the Matrix protocol, which allows decentralized and optionally encrypted architectures end to end. In this incident the technical explanation given by the administration itself is very relevant: the attacker used an account committed to access public rooms not encrypted where he was able to extract names, emails, avatars and the public entity to which the users belong. The private conversations, by the architecture of the platform, remain encrypted and, according to DINUM, their content was not deciphered by the intruder.

Beyond the official statement there are statements from the actor himself who claimed responsibility and published samples: he speaks of almost 650,000 scraped messages, more than 13.5 GB in documents and media, account and device metadata and even LDAP credentials embossed in scripts. If these allegations are confirmed, the scope goes from a simple "profile exposure" to a material that facilitates targeted follow-up, highly credible phishing campaigns and possible operational abuses against internal services.
The practical implications are clear: post and organizational exposure facilitates context-based screening campaigns (speed phishing), meeting links published in public forums can be intercepted or reused, and device metadata or sessions can allow for correlated activity or high-value accounts. In addition, hardcore credentials - if they exist - pose a risk of escalation or access to other corporate systems, so they should be treated as a critical vector.

The immediate action that any organisation affected or managing similar tools should be prioritized are forced rotation of credentials and revocation of active sessions, mandatory deployment of MFA with phishing-resistant factors, forensic analysis of logs to detect side movements, revision and rotation of any code-embedded credential and restoration of secure copies if there is evidence of manipulation. It is also essential to limit or reconfigure public rooms: if not necessary, close them or turn them into protected spaces. DINUM and Tchap leaders should coordinate with ANSSI and CNIL for containment and public communication; transparency reduces reputational risk and helps recipients to react properly ( CNIL, ANSSI).
For users the recommendation is practical: distrust from unexpected messages, do not re-use institutional passwords in other services, avoid sharing sensitive links or documents in open forums and configure additional authentication factors. At the organizational level, it is imperative to eliminate unsafe practices such as credentials embedded in scripts, to test the deployments before putting them into production and to adopt data minimization policies in collective spaces.
This incident also opens up a broader technical and governance debate: decentralization and the use of open protocols such as Matrix offer advantages in sovereignty and resilience, but are not immune to configuration errors, human errors or social engineering. The extreme-to-end encryption protects sensitive content, but does not replace access controls, security audit and staff training. The useful lesson for any administrator is to combine cryptographic protections with robust operational controls and a safety culture that treats the exposure of metadata and profiles with the same seriousness as that of the messages themselves.
Related
More news on the same subject.

The massive purchase of expired domains drives fraud, malware and streaming pirate: the business behind the dropcatch
An intelligence report on DNS published by Infoblox and disseminated by specialized media confirms that criminals are buying large-scale expired domains - the so-called dropcatc...

AmnesiaStealer MacOS malware that steals credentials and controls real-time browser sessions
Security researchers have documented a new malware family aimed at macOS - called AmnesiaStealer - that combines a dropper in shell, an infostealer written in Rust and a remote ...

Lazarus Group returns with a campaign aimed at defense and aerospace that combines kernel rootkit and social recruitment
The North Korean group known as Lazarus Group has again shown that it continues to improve intrusion techniques for the defence and aerospace industry. According to the research...

False VPN extensions in Chrome that intercept your traffic and watch you
Security researchers have identified a massive package of browser extensions that were presented as free VPN and proxy solutions, aimed mainly at Russian-speaking users seeking ...

August Alert: active operation of CVE-2026-68820 and four critical CERs failures without authentication on Windows
Microsoft published in its monthly patch cycle and among the August corrections there is a vulnerability that the company itself points out as actively exploited: CVE-2026-68820...

GPT five point six cyber OpenAI redefines cybersecurity and poses new risks
OpenAI presented this week GPT-5.6-Cyber, a variant of his family of models explicitly oriented to cybersecurity tasks such as vulnerability research, penetration tests and inci...

Kimsuky raises your game with local IA, RAG and GitHub as C2
A South Korean security firm, Genians, has published evidence that North Korean cyberespionage group Kimsuky is incorporating artificial intelligence (IA) models and components ...