:

73K FRENCH GOVT EMPLOYEES HIT IN TCHAP BREACH

SECURITY DESK1 MIN READ
FRI, JUN 12, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

The French government disclosed a security breach affecting over 73,000 public sector employee accounts on Tchap, its encrypted messaging platform. The incident marks a significant compromise of government communications infrastructure.

Tchap, developed as a secure alternative to commercial messaging services, serves as the primary communication tool for French public administration. The breach exposed accounts across multiple government departments, raising questions about the platform's security protocols. French authorities have not yet disclosed specific details about the attack vector or timeline of the compromise. Officials confirmed that the incident affects employee accounts but have not indicated whether classified communications were accessed. The breach comes as governments worldwide face mounting pressure to protect digital infrastructure from sophisticated cyber threats. France's choice to develop a domestic encrypted messaging system was intended to reduce reliance on foreign platforms, though the vulnerability exposes gaps in implementation. Officials stated they are investigating the incident and notifying affected employees. The government has not announced mandatory password resets or other immediate remedial measures, though security reviews are underway.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

D-Link has alerted users of a maximum-severity zero-day vulnerability (CVE-2026-86296) affecting DIR-822A dual-band Wi-Fi routers. The flaw has no available patch and public exploit code is already circulating.

JUST NOWSecurity Desk

A cross-site request forgery (CSRF) vulnerability in WordPress Core, dubbed 'Click2Shell,' enables attackers to execute PHP code on vulnerable servers. Technical details and working exploits are now public.

8H AGOSecurity Desk

The ShinyHunters extortion group took control of the dark web leak site belonging to the prolific Cl0p ransomware gang over the weekend. The attackers set an eight-figure extortion demand pegged at 2.333% of Cl0p's estimated net worth.

9H AGOSecurity Desk

The FBI's CJIS Security Policy v6.1 strengthens encryption requirements and vulnerability scanning mandates. Agencies must prepare for updated password, MFA, and identity verification standards ahead of compliance audits.

11H AGOSecurity Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.