💢 Decoded – France built a sovereign messenger for 825.000 civil servants. One social engineer walked in and…

Social engineering breached France’s sovereign messenger Tchap. OUCH!

On June 7, France’s national cybersecurity agency ANSSI detected a breach of Tchap, the encrypted messaging platform built by the French state for its civil servants. Mandatory since September 2025. Deployed across ministries, public administrations, and sensitive government bodies. Over 825k registered users – yoo-hoo!

The attacker used social engineering on government messaging infrastructure.
ONE account. That was enough.

What Tchap is, and why it matters that it was breached this way

Tchap is not a commercial product that cut corners on budget. It is France’s answer to the sovereign technology question that every European government has been wrestling with for years: how do you stop your civil servants from running sensitive conversations through WhatsApp, Signal, or Teams, platforms whose infrastructure is outside your jurisdiction? (my first draft was: ready not to be added to secret Signal chat?)

The answer the French built is based on Matrix protocol, self-hosted, audited, GDPR-aligned, with private messages end-to-end encrypted. The state built the room and handed out the keys, no third-party SaaS, no US hyperscaler relay in the path, no algorithmic content layer.
Technically, a serious effort guys!

The attacker, operating under the handle “Misère“, claims to have accessed 73.000 state agent records, 643.000 messages, nearly 60.000 files totalling 13.5 gigabytes!

13.5 GIGABYTES HOLY COW!

Among them, reportedly, items carrying the “Diffusion Restreinte” marking, France’s restricted distribution classification. ANSSI and DINUM have confirmed the breach but have not validated those figures. Several French infosec analysts are keeping the numbers out of their trackers pending independent confirmation

What ANSSI did confirm: the entry point was a hijacked valid public servant account, accessed through social engineering on Tchap’s education environment. Not a 0day, not a supply-chain compromise, not a nation-state exploit chain. A person was manipulated into yielding access.

What the architecture cannot protect against

There is a specific failure mode baked into the design of every sovereign messaging platform, and Tchap just demonstrated it in public.

The encryption is sound, the infrastructure is self-hosted, the servers are in France, under French law, outside US CLOUD Act reach. All of that holds. The private message layer (the thing the sovereign architecture is actually designed to protect) did not get breached through cryptographic weakness.

It got breached because Tchap has public chat rooms.
Public rooms, by design, are not end-to-end encrypted, they are readable by the server, which is fine for open discussion and makes moderation possible. The attacker exfiltrated from those rooms. The encryption did exactly what it was designed to do, and it was irrelevant, because the access came through the door the system left open.

Then, separately, a PowerShell script leaked hardcoded LDAP credentials. A directory search function allowed user enumeration across the service. Two years of conversations, spanning June 2023 to June 2026, pulled from an account that a social engineer convinced a public servant to hand over.

The architecture worked: the social engineering on government messaging infrastructure worked harder.

The post-breach narrative

Every time a sovereign or high-assurance platform gets breached via a human entry point, the post-breach conversation centers on the technical remediation. Patch the LDAP script, close the directory enumeration, review the public room access model, rotate credentials, add MFA to the education environment. Correct. Necessary. Not enough.

The conversation that does not happen with enough seriousness is about the person who got socially engineered.

What did the manipulation look like? Was it a pretext call? A spoofed internal notification? A carefully constructed message from someone claiming to be IT support? We do not know the specifics of this case, because the attacker has not published the methodology and ANSSI has not described it. What we know is the outcome: a valid account, yielded to someone who had no right to it, through a channel the platform’s security model had no way to intercept.

The Government of France deployed sovereign infrastructure to 825.000 people. It ran security awareness sessions, you do not roll out a mandatory platform to the entire civil service without some onboarding. It mandated the tool, policed the usage, and got the adoption numbers.

And then one social engineer asked a public servant the right question, in the right way, at the right moment, and got in.

What this reads as, from where we sit

We build social engineering simulations. We have watched, repeatedly, organizations that have invested seriously in technical controls and platform security discover that their exposure sits entirely in the behavioral layer, in the person who picks up the phone, responds to the urgent request, trusts the context the attacker constructed.

Sovereign infrastructure is not an argument against social engineering. It is, in a specific sense, a target for it. The more controlled and sensitive the environment, the more valuable the human credential that opens it. Attackers know this. The targeting follows the value.

That is not a failure of the encryption.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top