On July 25, 2025, French Prime Minister François Bayrou signed circular n°6497/SG, requiring all civil servants to use Tchap — France's government-built messaging platform — for work-related communications and prohibiting the use of foreign applications including WhatsApp, Signal, and Telegram. The reasoning was sound. Consumer messaging apps pose sovereignty and security risks when used on government devices. France would control its own communications infrastructure. By June 2026, Tchap had scaled to over 300,000 monthly active users across every ministry.
On June 7, 2026, ANSSI — France's national cybersecurity agency — detected unauthorized access to the platform. A single compromised account had been used to move laterally through Tchap's infrastructure. A threat actor using the handle "Misère" subsequently claimed responsibility on a dark web forum, alleging the exfiltration of 73,467 user accounts, 643,459 messages, 876 chat rooms with full history, and 59,386 shared media files totalling approximately 13.5 gigabytes. The claimed dataset spans June 2023 to June 2026 — three years of government communications from the platform built specifically to keep them safe.
ANSSI and DINUM have not verified those figures. What they have confirmed is that the breach was real, that it originated from a compromised user account, and that the attack vector was social engineering — not a software vulnerability in the platform itself.
The Right Problem, the Wrong Architecture
France's decision to build a sovereign messaging platform was correct. It remains correct. The reasoning behind the Bayrou circular — that government communications should not travel through infrastructure operated by foreign commercial entities, subject to foreign jurisdiction, outside government control — is precisely the reasoning that every allied government should be applying to its own communications.
The failure was not in the decision to build sovereign infrastructure. The failure was in the architectural assumptions behind how that infrastructure was built.
Tchap is built on the Matrix open protocol, deployed as a fork of the Riot client (now Element). Matrix provides genuine end-to-end encryption for private conversations. But the platform's architecture created exposure that the encryption could not cover. Public chat rooms — used extensively across ministries for coordination, policy discussion, and operational planning — are not end-to-end encrypted. They are accessible to any authenticated user on the platform. Once an attacker has a valid account, those rooms and their full history are readable.
"The attacker did not break the encryption. The attacker logged in. The architecture treated authentication as the security boundary — and a single socially engineered credential crossed it."
More critically, the investigation revealed hardcoded credentials embedded in Tchap's LDAP authentication layer. Once inside the platform through the initial compromised account, the attacker discovered these credentials and gained an authentication path that bypassed the need to compromise additional accounts individually. A single point of entry became a platform-wide breach — not because the encryption failed, but because the infrastructure behind it was not built to contain a compromised session.
What Encryption Cannot Fix
The Tchap breach illustrates a structural problem that encryption alone cannot solve, regardless of whether the encryption is classical or post-quantum, open-source or proprietary, consumer or sovereign.
End-to-end encryption protects the content of messages in transit between devices. It does not protect messages at the endpoints. It does not prevent a compromised device from reading everything the legitimate user can read. It does not enforce access controls within a platform once authentication has been passed. It does not segment exposure so that a single compromised credential cannot reach years of accumulated communications across hundreds of chat rooms.
Tchap's encryption worked. The private conversations on the platform remained protected by Matrix's end-to-end encryption. But the platform's security model treated encryption and access control as separate concerns — and the access control failed. The attacker did not need to break the cryptography. The attacker needed one password and one set of hardcoded credentials that should never have existed.
This is the lesson that matters for every government considering sovereign communications infrastructure: encryption is necessary but it is not sufficient. The architecture around the encryption — session containment, credential management, lateral movement prevention, access segmentation — determines whether a single compromised account becomes a single incident or a platform-wide catastrophe.
The Sovereignty Question Stands
It would be a mistake to read the Tchap breach as evidence that sovereign messaging is the wrong approach. The opposite conclusion is more defensible. If French government communications had remained on Signal or WhatsApp when this attack campaign struck, the exposure would have been worse — and France would have had no ability to detect it, no ability to investigate it on its own infrastructure, and no ability to respond at the platform level.
ANSSI detected the breach. DINUM blocked the compromised account. The investigation is being conducted by French agencies on French infrastructure under French law. CNIL was notified in accordance with French data protection requirements. Every one of these response actions was possible because France owned the platform. None of them would have been available if the communications had been hosted on foreign commercial infrastructure.
The sovereignty instinct was correct. The implementation was not hardened to the standard that sovereign government communications demand. These are different problems. The first is strategic. The second is engineering.
"France proved that a government can build and mandate sovereign communications infrastructure. The breach proved that building it is not the same as hardening it. Sovereignty is the starting point, not the finish line."
What Hardened Sovereign Infrastructure Requires
The Tchap breach is an architectural case study. Every vulnerability that the attacker exploited — social engineering of a single account, lateral movement through the platform, hardcoded credentials in the authentication layer, unencrypted public rooms accessible to any authenticated session — has a known countermeasure. The question is whether those countermeasures are built into the architecture from the beginning or bolted on after a breach forces the issue.
Institutional communications infrastructure that is built for the threat environment governments actually face requires several properties that Tchap's architecture did not enforce. Session containment must ensure that a compromised credential cannot access historical communications beyond the scope of that specific account. Credential management must prohibit hardcoded secrets anywhere in the authentication chain. All communications — not just those marked as private — must be encrypted end-to-end by default, because the distinction between "public within the organization" and "accessible to an attacker with a valid session" is no distinction at all. And the cryptographic layer must be quantum-resistant, because the communications being protected today will still be sensitive when nation-state quantum decryption capability arrives — and three years of accumulated government messages are precisely the kind of dataset that harvest-now-decrypt-later programs are designed to collect.
France demonstrated that sovereign communications infrastructure is achievable. The breach demonstrated what it costs when that infrastructure is not hardened to the standard the threat demands. Every allied government watching this incident is now confronting the same question: build sovereign infrastructure that is genuinely hardened from day one, or build it the way Tchap was built and learn the lessons the hard way.
The Tchap breach does not discredit sovereign messaging. It defines the engineering standard that sovereign messaging must meet. France had the right instinct. The next generation of sovereign communications infrastructure must have the right architecture.
If your organization is evaluating sovereign communications infrastructure, we built ours to meet the standard the Tchap breach defined.
Get in Touch