French govt messaging service breached in account hijacking attack
ID: 1f0d884e-d0e1-5e4e-b0d2-99dbb03963d3
STIX ID: report--1f0d884e-d0e1-5e4e-b0d2-99dbb03963d3
Feed Name: Bleeping Computer
DINUM and ANSSI investigated a breach of Tchap, France's government Matrix-based messaging service, after a compromised user account was used to access conversations and media. A threat actor claiming responsibility said they performed social engineering to hijack an account and exfiltrated allegedly hardcoded LDAP credentials, about 13.5GB of files, roughly 650,000 messages and metadata for around 73,000 accounts; DINUM blocked the account, notified CNIL, and is analysing logs to assess exposed conversations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
