news.mlab.sh
Back to the feed
threat-intel

French Government Messaging Platform Breached by Mysterious ‘Misere’ Hacker

High
Summary

A breach of the French government’s secure messaging platform, Tchap, has resulted in the theft of personal data for over 70,000 government employees. The incident was initially attributed to a threat actor calling itself ‘misere,’ who claimed responsibility for the breach and the theft of 13.5GB of data. While the initial announcement downplayed the impact, experts suggest a sophisticated attack may have occurred, potentially involving the exfiltration of large amounts of data through legitimate API requests. The motivations behind the attack remain unclear, with speculation ranging from a minor embarrassment to a precursor for a larger cyberwar operation.

On June 7, 2026, the French government’s Tchap messaging platform was breached, impacting over 73,000 government employees. The breach, initially announced by DINUM, the French government’s interministerial digital directorate, revealed that personal data including names, email addresses, affiliated entities, and avatars were compromised. The threat actor, identified as ‘misere,’ claimed responsibility for the breach and the theft of 13.5GB of data, aligning with the initial reported number of affected accounts. However, the source of this claim is unverified, reported by the OSINT FrenchBreaches community.

Expert analysis, provided by Ilia Kolochenko of ImmuniWeb, suggests a more complex scenario than a simple account take-over. Kolochenko highlighted a trend among state actors since 2024 – infiltrating systems and laying low, focusing on silently backdooring critical national infrastructure and its suppliers. This strategy aims to gain control of a nation’s infrastructure, potentially preparing for a coordinated cyberattack during or in defense of a kinetic conflict. Kolochenko’s assessment suggests that the attack could be a reconnaissance operation or a precursor to a larger, more disruptive attack.

Kolochenko also pointed out that the name ‘misere’ is likely a pseudonym, possibly adopted to avoid detection or to impersonate another group. He believes the attack may not be an APT attack, but rather a deliberate attempt to gather intelligence or create a backdoor into critical systems. The compromised data, including email addresses, could be used for targeted phishing campaigns or further exploitation of government systems.

Read the full article at SecurityWeek