logo

French govt messaging service breached in account hijacking attack

ID: 1f0d884e-d0e1-5e4e-b0d2-99dbb03963d3

STIX ID: report--1f0d884e-d0e1-5e4e-b0d2-99dbb03963d3

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2026-06-09

Date Updated: 2026-06-09

Author: Sergiu Gatlan

...
...

DINUM and ANSSI investigated a breach of Tchap, France's government Matrix-based messaging service, after a compromised user account was used to access conversations and media. A threat actor claiming responsibility said they performed social engineering to hijack an account and exfiltrated allegedly hardcoded LDAP credentials, about 13.5GB of files, roughly 650,000 messages and metadata for around 73,000 accounts; DINUM blocked the account, notified CNIL, and is analysing logs to assess exposed conversations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.