France's government-built encrypted messenger Tchap, built on the Matrix protocol, was breached on June 7 via a hijacked user account. ANSSI and DINUM say only public chat rooms were exposed since private conversations are end-to-end encrypted, but a threat actor claiming the handle 'Misère' alleges access to 73,000 state agent accounts, 643,000 messages, nearly 60,000 files totalling 13.5 GB, and documents marked with France's restricted-distribution classification. The attacker claims entry via social engineering on Tchap's education environment and user enumeration through a directory-search function. Security researchers note that while E2E encryption protects message content, a fully hijacked logged-in client can still see whatever the account sees in real time. The discrepancy between official and attacker accounts remains unresolved pending log analysis. The incident is particularly embarrassing given Tchap was created specifically to keep French government communications off foreign-controlled platforms.

4m read timeFrom thenextweb.com
Post cover image
86 Impressions