Desk live·
ForensicPost
Nation-state/Public sector/File 26-0517

The Secure Messenger the French State Built for Itself

Around 73,500 accounts — roughly 9% of the user base — were hijacked on Tchap, the French government messaging platform, in June 2026. Building your own is a defensible choice with its own exposure.

Constructed geometry · not a chart of case data
JurisdictionFrancethe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetTchap (French government)
Actormisere
S. Rosler9 min readConfidence: medium1 source reviewed

Approximately 73,500 accounts on Tchap, the French government’s messaging platform, were hijacked in an incident attributed to an actor operating as "misere". The figure represents roughly 9% of the user base. A 13.5 GB data claim associated with the incident is unverified.

Sovereign Platforms Are A Real Trade, Not A Free Win

Tchap exists because the French state decided its internal communications should not depend on a foreign commercial messenger. That reasoning is sound: it removes a dependency, keeps data under domestic jurisdiction, and allows the security model to be inspected by the operator.

The trade is that the state now owns the whole problem. A commercial platform serving hundreds of millions has a security team proportional to that scale and receives attack telemetry from every customer. A national platform serving hundreds of thousands has neither.

Nine Per Cent Is A Specific Kind Of Number

It is large enough to indicate a systemic weakness rather than individually targeted accounts, and small enough to suggest a bounded condition — a particular authentication path, account type or provisioning route — rather than total platform compromise.

For an internal government messenger the sensitivity is not primarily message content. It is the graph: who is in which channel, who joined when, and which working groups exist at all. Organisational structure is intelligence, and a hijacked account reveals it without any message needing to be read.

Graded medium. The account figure is consistently reported; the access route is not established and the data claim is unverified.

How we reported this

Compiled from public reporting, listed below. The data-volume claim originates with the actor and is unverified. The access route has not been established. Corrections: corrections@forensicpost.com.

Sources
  1. List of recent data breaches in 2026Bright Defense
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary