All Breaches
June 7, 2026 Verified Sensitive Record Government

Tchap 2026 Data Breach

The Tchap 2026 data breach is an incident in which unauthorized access to the French government's messaging platform for public-sector employees was obtained through a compromised user account. France's Interministerial Directorate for Digital Affairs, DINUM, confirmed that a Tchap account was compromised on June 7, 2026 and that an attacker could access information shared in public chat rooms.

DINUM's updated official statement says 73,467 of more than 825,000 registered public servants were potentially affected, less than nine percent of registered users. At least first and last names, email addresses, public-sector entities, and avatars were accessible. Encrypted private-conversation content remained protected, while messages in public rooms were not encrypted by design.

How Was the Incident Confirmed?

DINUM said an investigation coordinated with ANSSI found that a Tchap user account had been abused after account impersonation or compromise. The account responsible for malicious requests was identified and immediately blocked to remove the attacker's persistent access. The incident was reported to France's data-protection authority, CNIL, because personal data may have been exposed.

This official statement establishes a completed platform breach rather than only an attacker claim or discovered vulnerability. The public account did not conclusively identify how the account was taken over; the social-engineering explanation came from the attacker. LeakData therefore attributes no specific phishing technique, malware, vulnerability, or threat group as the verified cause.

What Does the 73,467-User Figure Mean?

DINUM said 73,467 public servants may have been affected based on the accessible account and public-conversation scope. This is not the platform's complete population of more than 825,000 registered users; it represents less than nine percent of the total. LeakData uses the officially disclosed upper bound of 73,467 in pwnCount and totalRecords.

“Potentially affected” does not mean that every field for every user was viewed or extracted. DINUM said it continued reviewing event logs and the conversations the attacker could access. If a later official update publishes a confirmed, deduplicated, or narrowed count, the record can be revised using that new total.

What Data May Have Been Exposed?

DINUM said potentially exposed user-account data included at least last names, first names, email addresses, the public-sector entity to which each user belonged, and avatars. Public-room messages and content shared by users in rooms accessible to the attacker are also within the incident boundary. The data classes reflect the confirmed minimum account fields and potentially accessed public-room content.

The official investigation had not yet determined the full nature of exfiltrated data. Additional attacker claims concerning meeting links, device metadata, hundreds of thousands of messages, documents, or hardcoded credentials were not confirmed by an independent forensic result. LeakData therefore does not record those volumes, document sizes, or specific technical secrets as verified data classes.

Difference Between Public and Private Conversations

Tchap supports both public and private conversations. DINUM said private conversations are encrypted and that their historical content remains inaccessible even when a user account is compromised. Potential access was limited to public conversations, which were designed to be discoverable and joinable by every Tchap user and whose messages were not encrypted.

A room being open to platform users does not authorize malicious automated collection or removal of personal data from its context. The event is treated as a breach because a compromised account used malicious requests to maintain access and collect information without authorization. The record also prevents the incorrect conclusion that encrypted private messages were exposed.

DINUM's Response

DINUM blocked the account responsible for the malicious requests, cut off the attacker's access, and began reviewing event logs with specialist teams. It coordinated with ANSSI, notified CNIL, and reminded all Tchap users that public rooms are discoverable, joinable, and unencrypted. Diagnosis and remediation continued to determine the attack method and required protections.

The agency reiterated that personal, sensitive, or professionally confidential information must not be shared in public rooms and should be reserved for private conversations. Users should review unexpected sessions and authentication requests, verify messages sent in their organization's name, and watch for phishing aimed at the disclosed email addresses. These are precautionary steps aligned with the verified account and employer fields.

How to Interpret This LeakData Record

This record establishes that a Tchap user account was compromised on June 7, 2026 and that an attacker could access public-room data. The 73,467 figure is the official upper bound of potentially affected public servants. First names, last names, email addresses, entities, and avatars are the minimum accessible account fields; the full volume of extracted public-room messages remained under investigation.

The verified boundary is that encrypted private conversations and their history remained protected, while the impact was limited to public rooms and related user information. The attacker, account-takeover technique, and complete exfiltrated content were undisclosed. LeakData records the real breach while excluding unverified attacker claims and preserving the distinction between potential scope and confirmed data access.

73.5 Thousand
Affected Accounts
6
Data Types
Medium
Severity
Yes
Verification

Exposed Data Types

6
First names (potentially exposed)
Last names (potentially exposed)
Email addresses (potentially exposed)
Public-sector entities (potentially exposed)
Avatars (potentially exposed)
Public chat room content (potentially accessed)

Additional Information

Added DateJuly 27, 2026
Breach DateJune 7, 2026
Domaintchap.gouv.fr
SourceCompromised Tchap account used for malicious data access
Last Content UpdateJuly 27, 2026

Verification and editorial method

LeakData compares the incident name, date, affected-record count, and exposed data types with accessible sources. Unverified fields are not presented as facts, and records are updated when new evidence becomes available.

Report missing or incorrect information