CSIDB logo
Incident

French Government

Incident posture

Attack window
Jun 2026
Location
France
Status
Unknown
CIA posture
Available to members
Updated
2026-09-01 14:02

Linked entities

Victim
French Government
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Jun 2026
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

On June 7, 2026, the French government's Tchap messaging service was breached, exposing personal data of over 73,000 government employees; DINUM announced the incident and threat actor 'misere' claimed responsibility.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

0 techniques

Description

On June 8, 2026, DINUM, the French government's interministerial digital directorate, publicly disclosed that Tchap, the official sovereign instant messaging service used by French government employees, had been breached the previous day. Tchap is a "secure" communication platform designed to combine data sovereignty with enhanced security over third-party foreign systems, and it includes end-to-end encrypted chat rooms alongside "public" chat rooms that are not encrypted. The breach was attributed to account hijacking, and at the time of disclosure, DINUM stated that the incident affected a portion of the platform's registered user base. Reports confirmed that the number of affected accounts aligned with a claim made by an entity identifying itself as "misere," which stated that it had stolen more than 70,000 user accounts, a figure consistent with the 73,467 affected agents that DINUM acknowledged out of the more than 825,000 registered users on the platform, representing less than 9 percent of the total user population.

The threat actor operating under the name "misere" publicly claimed responsibility for the breach and asserted that it had exfiltrated 13.5GB of files comprising more than 643,000 messages. This claim was reported by the OSINT FrenchBreaches community, although the original statement from misere was not directly available on the internet at the time of the article's publication, making independent verification impossible. The exposed user account data, as specified in DINUM's breach disclosure, included at minimum each affected user's first and last name, email address, affiliated government entity, and avatar. This combination of data would expose which government department each user belonged to and provide contact information, potentially facilitating further targeted attacks. Misere additionally claimed to have scraped 640,000 chat messages in plaintext, though this particular element of the exfiltration was not independently confirmed and could not be substantiated beyond the actor's own assertion.

The method by which the system was compromised was described as account hijacking, and the operational details surrounding the intrusion were not fully elucidated in the official disclosure. The breach was reported as having occurred, rather than merely being discovered, on June 7, 2026, and the public announcement was issued the following day. No information was provided regarding whether the affected accounts belonged to users of the encrypted chat rooms or the non-encrypted public chat rooms, nor was it clarified whether the messages claimed to have been stolen originated from the encrypted or non-encrypted portions of the platform. The identity and prior activity of the threat actor "misere" remained unestablished, as there was no public record of any threat actor operating under that name prior to the Tchap incident.

The potential consequences of the breach extended beyond the immediate loss of account credentials. The combination of government employee names, official email addresses, affiliated entities, and potentially the contents of public chat messages would provide a foundation for subsequent targeted spear-phishing operations against the ministries employing the affected Tchap users. Such data would be valuable both to financially motivated cybercriminal groups and to state-sponsored actors whose ultimate interest lay not in the messaging platform itself but in the broader government infrastructure it connected to. The exposed data could be used to map inter-agency communications, identify personnel within sensitive departments, and craft convincing social engineering attacks leveraging the knowledge of each user's specific government affiliation and role.

No public attribution of the breach to any known threat actor, criminal group, or state-sponsored entity was made in connection with this incident. The threat actor "misere" did not surface in any known prior incident reporting, and the name itself provided no established link to any previously documented campaigns or known adversaries. The response from DINUM was limited to the public acknowledgment of the breach, the specification of the number of affected users, and the enumeration of the data categories potentially exposed. There was no indication in the available reporting of specific containment actions taken, forensic analysis results, or remediation steps deployed in the immediate aftermath of the disclosure, nor was there any public statement regarding whether the compromised accounts had been secured, whether the underlying vulnerability exploited by the threat actor had been identified and patched, or whether any law enforcement investigation had been initiated. The incident as described remained an account-hijacking event targeting a sovereign government communications platform, resulting in the exposure of identifying information for tens of thousands of French government employees and the unverified claim of additional message data theft.

Sources

Sources available to members: 1 source.

CSIDB