Electronic invoicing : 115 targets for the price of one
Three days without bank transfers. Eleven months to repair three escalators at Châtelet. Two weeks without internet in Saint-Marcellin. To the list of services that no longer hold up in France, we can now add the IT security of the sovereign vaults. Four major incidents in ninety days, on four State information systems. And, in one hundred and twenty days, the legal obligation to push the entirety of business-to-business invoicing flows through some hundred private platforms accredited by that same administration.
The calendar doesn’t lie. Neither do the figures.
Four months between the breach and the rollout
The agenda speaks for itself.
On 18 February 2026, the Ministry of the Economy issued a statement: 1.2 million bank accounts consulted in the national register of bank accounts (FICOBA) since late January, by an actor who had usurped a civil servant’s credentials in the context of inter-ministerial exchanges. The register lists the some 300 million accounts opened in France. The DGFiP filed a complaint.
On 15 April, the moncompte.ants.gouv.fr portal was gutted by an IDOR flaw, the first vulnerability taught in any cybersecurity course. 11.7 million accounts officially confirmed, up to nineteen million rows claimed for sale on cybercriminal forums. Perpetrator arrested: a fifteen-year-old minor, with no specialized training, who described his own intrusion as banal. As early as September 2025, a similar alert had circulated. ANTS had publicly denied it, boasting of its “reinforced security measures”. The flaw stayed open for seven months.
In late April, the group LunarisSec reported a critical flaw to ANSSI on Mentor, the online training platform for public officials. A few days later, the same group announced the discovery of a “potentially critical” vulnerability on the tax website allowing the recovery of user data. No official confirmation to date, but the warning is public.
Fifth act scheduled: on 1 September 2026, electronic invoicing becomes mandatory for all French businesses subject to VAT. More than ten million economic actors. Two billion B2B invoices a year. And a single point of entry: 115 accredited private platforms (PA, formerly “partner dematerialization platforms” or PDP, the State quietly replaced the word “partner” with “accredited” in early 2025), through which everything will have to transit, by construction.
Four months between the last documented scandal and the extension to the entire private economy of a centralizing scheme.
What they sell you, what they build you
The official pitch has the coherence of an inter-ministerial presentation: fight against VAT fraud, administrative simplification, better real-time knowledge of business activity. Three legitimate objectives on the surface.
What’s built in practice has another signature. Every B2B invoice, as of 1 September, will be structured in the Factur-X, UBL or CII format, machine-readable XML. Issued by an accredited platform, transmitted to another accredited platform, archived at both, and whose data, supplier identity, customer identity, pre-tax amount, VAT due, rate applied, will be extracted and transmitted to the tax administration via the public invoicing portal. Four copies per invoice at minimum. No strong confidentiality between issuer and recipient: the platform sees everything, by design.
What this scheme produces isn’t a fight against fraud. It’s a complete graph of French business-to-business relationships, by amount, by date, by customer, updated in near real time, and hosted at around a hundred private operators. For the first time in French fiscal history, the State can describe private economic activity down to the invoice. And it has outsourced the operation.
The term PDP, partner dematerialization platform, was in fact dropped in early 2025 in favor of PA, accredited platform. The semantic shift is interesting: you no longer “partner”, you “accredit”. The State doesn’t ally itself, it certifies. But the operational risk stays entirely with the accredited operators.
And that’s where the system reveals its true design. By accrediting private operators rather than operating itself, the State builds a mechanism unprecedented in French fiscal history: responsibility without culpability. The reform, its architecture, its calendar, its data perimeter, its legal obligation, is entirely a political decision. But the incident, when it comes, will be entirely a private event. The minister will say, official statement in hand, that “a private actor failed in its obligations”, that “the State has referred the matter to the CNIL and ANSSI”, that “the planned sanctions will be applied”. He will be legally right, and politically intact.
Political risk has been transferred to private operational risk with no transfer of the decision. It’s the inverse of the classic sovereign model, where the State that decides is the State that answers. It’s also the inverse of the classic liberal model, where the operator that decides is the operator that answers. Here, the State decides and the operator answers. The position is comfortable for the decision-maker, untenable for the accredited operator, and opaque for the user business, which knows neither, on 1 September, whom it is subcontracting to nor who will own the leak.
The attack-surface calculation
The official figures let us pose the question cleanly.
According to the State Agency for Financial IT, about two billion B2B invoices circulate each year in France. Which is, roughly, six million invoices per working day. With ten million businesses concerned, the average number of invoices issued per business per month sits around 17, an average pulled down by micro-businesses, up by the large structures.
As of 26 March 2026, 112 platforms were definitively registered. The list published in mid-April counts 115. That number seems high until you look at the real distribution of the market: Pennylane, Cegid, Docaposte/SERES, Qonto, Sage, and a handful of other players will mechanically concentrate the majority of the flow. About ten platforms will probably capture eighty percent of the invoices, through the business-to-business network effect. The risk isn’t spread over 115 targets: it’s concentrated on ten.
To gauge the order of magnitude, you only have to stack up what has already leaked in France. Korben tallied it in April: since the start of 2024, more than 91 million rows have been exfiltrated from French public bodies, France Travail, Viamedis and Almerys, Pajemploi, CAF, ANTS, for a country of 68 million inhabitants. France has already leaked more than its population. And these are exclusively public leaks. The private operators accredited to handle B2B invoices will represent, on their own, several additional orders of magnitude in volume of structured data.
The phrase to remember isn’t “115 fresh targets”. It’s more disturbing: we haven’t multiplied the targets, we’ve merged them.
Four break-ins on sovereign vaults in ninety days
At the moment the State is forcing businesses to entrust their flows to a centralized system, its own perimeter is taking on water from every side.
FICOBA, late January 2026. A malicious actor uses a civil servant’s credentials to consult 1.2 million bank accounts. Not a technical flaw: a human flaw, in the context of inter-ministerial exchanges. Detection took several weeks. Bercy’s statement is dated 18 February, the incident had been under way since late January. Latency: three weeks minimum between exploitation and public alert.
ANTS, 15 April 2026. The API of the moncompte.ants.gouv.fr portal doesn’t check authorizations server-side. Any authenticated user can access any other’s data by modifying a numeric identifier in the request. It’s the most-taught error in OWASP, the world’s top 10 web vulnerabilities. It has been in those rankings for more than ten years. Finding it in April 2026 on the portal that centralizes applications for ID cards, passports, driver’s licenses and vehicle registration certificates for tens of millions of French citizens should, on its own, trigger a commission of inquiry. The official figure, 11.7 million accounts, results from an after-the-fact analysis of access logs. The databases put up for sale by the attacker claim nineteen million. The truth lies within that range.
Mentor platform, late April 2026. The online training service for public officials, precisely the people who handle the sovereign information systems, presented a critical flaw allowing unauthorized access. Reported to ANSSI by LunarisSec, which had previously claimed attacks against the universities of Toulouse, Burgundy and Aix-Marseille. An ambiguous actor, a credible report: the combination is unusual, and points to an institutional ecosystem where the official white hats aren’t enough to cover the perimeter.
impots.gouv.fr, early May 2026. The same group announces a “potentially critical” vulnerability on the tax portal allowing the recovery of user data, a public report relayed by the researcher Seblatombe. No official confirmation from the DGFiP, ANSSI or the CNIL at the time these lines are written. The report remains to be qualified. But the context, after FICOBA, ANTS and Mentor, makes any hasty response imprudent.
Add to this, in the broader public sphere since 2024, France Travail, Viamedis, Almerys, Pajemploi, CAF. Five more, several tens of millions of additional rows. The pace of major incidents on French public information systems has crossed a quantitative threshold: we’ve gone from rare events to ordinary ones. The penal code defines an offense as habitual when committed at least three times in five years. The State has crossed that threshold on its own systems in less than a quarter.
As for the viral rumor claiming that “impots.gouv.fr supposedly still runs on Microsoft Access in 2026”: it’s false, and it has to be said. The DGFiP is precisely, for twenty years, the French exception in matters of software sovereignty. Its CIO Tomasz Blanc publicly claims, in an interview with IT for Business last March, an information system operated without a single Microsoft license, on open-source building blocks, on an internal cloud named Nubo. It’s precisely this exception that makes the rest of this article relevant: if even the DGFiP, which does everything right in terms of architecture, can lose 1.2 million bank account records in January, then the argument that the 115 accredited platforms will be “more secure than the public servers” collapses by construction. Bercy isn’t Bercy because it uses Access. It’s Bercy in spite of everything, and it leaks anyway.
What we could have chosen, and didn’t
The technical debate has been settled for fifteen years. Zero-knowledge cryptography, partial homomorphic encryption, the separation between transaction metadata and business data, all these building blocks exist, are deployed in production at several financial players, and would allow fiscal aggregates to be computed without exposing the individual transactions to the platform operator. As I wrote in early May about France’s repeated leaks, zero-knowledge cryptography exists, France doesn’t want it.
Not out of incompetence: out of preference. Near-real-time tax control, which is the reform’s real political objective as I detailed in April, is strictly incompatible with strong confidentiality between the parties to a transaction. If the tax authority wants to see, the private third party must see too. If the private third party sees, the attacker who takes control of the private third party sees as well. There’s no middle ground in this space.
The chosen architecture is therefore the logical consequence of a deliberate political will, which was then sold to the economic fabric under the label “secure”. The two statements aren’t equivalent, and the pairing “centralized architecture + security” is at best commercial optimism, at worst a lie by omission.
The GDPR requires any data controller to implement “appropriate technical and organizational measures”. Article 32 will, obviously, be the next litigation weapon against failing PAs. But it intervenes ex post, after the leak. French and European regulation has, at this stage, produced no ex ante mechanism that structurally forbids what the architecture mechanically makes possible.
The realistic eighteen-month scenario
Not “if”, but “when”. The probable sequence, drawing on the pattern observed on ANTS:
First, a major PA suffers an intrusion, via a poorly designed API or stolen credentials. The platform is slow to detect, as the DGFiP was slow on FICOBA, as ANTS had denied in September 2025 before discovering the scale in April 2026. Typical latency: six to eight weeks between exploitation and notification.
Then, the domino effect on the client micro-businesses, which will have neither redundancy nor backup of their flows. The PA serves as the sole point of contact between the business and the administration. If it falls, the business can neither issue, nor receive, nor prove itself up to date. The sanctions regime, €15 per invoice not issued on time, €250 per omitted e-reporting, cap of €15,000/year, applies without regard to the cause. An SME whose PA is down for a month will, by construction, get a fine. The administrative correction will take a quarter.
Then the DGFiP discovers that its real time has become a black hole: the data it was expecting to compute the VAT collected and cross-check against the declarations stops arriving. A calibrated ministerial communication, a private actor, sanctions applied, the vigilant State, and the political architecture of responsibility without culpability does its work. A post mortem audit commissioned from the IGF. Later: a four-year parliamentary inquiry, a report under an elegant title like “The resilience of the electronic invoicing system: lessons learned”, and, as every time, the political answer will consist of adding a layer of control rather than correcting the architecture.
This isn’t a doom scenario: it’s the direct extrapolation of what happened on ANTS, with a factor of fifty in volume and a factor of ten in economic criticality.
What a business leader can do four months from the deadline
The useful, without the sermonizing.
Choose your accredited platform the way you choose your production host, not the way you choose your accounting software vendor. Three technical criteria and one legal criterion:
- Hosting in France, not just a “French registered office”. Several registered PAs belong to foreign groups or in reality host on AWS, GCP or Azure. Ask for the business registration of the hosting subcontractor, require a contractual mention, refuse evasive answers.
- Verified and up-to-date ISO/IEC 27001 certification. PA registration requires 27001. Ask for the recent audit report, not just the logo. A 2022 certification on a restricted scope says nothing about the security of the 2026 invoicing flow.
- Cyber coverage of the PA itself. In the event of a leak, the GDPR allows the PA to be sued for breach of Article 32. But it still needs an insurance policy that pays out. Ask for the amount and the exclusions.
- Contractual incident-notification clauses. A notification SLA within 24 or 48 hours with enforceable penalties. Not the vague mention “notification as soon as possible”.
Keep an off-platform backup. The PA archives, but the business remains responsible for its accounting obligations even if the PA disappears, is sanctioned, or gets gutted. Keeping a parallel invoicing chain, exportable in PDF + raw XML, outside the PA, on controlled storage, should be a hygiene reflex, like the monthly accounting export outside the SaaS software.
Check the list of registered PAs before signing, on the DGFiP’s official website, and not on the platforms’ commercial pages. The list has already been modified several times since January, by the removal or suspension of operators.
And as we wrote about Wero, bear in mind that an operator’s claimed sovereignty often hides a foreign infrastructure dependency that makes the guarantee cosmetic. An accountant who chooses their PA in May 2026 makes a decision whose consequences they’ll pay in September 2027, when it will be too late to migrate without a break in service.
1 September 2026 isn’t a date of administrative compliance. It’s the date on which ten million businesses simultaneously lose their autonomy over the most sensitive channel of their activity, in favor of around a hundred private operators certified by a State that no longer holds its own systems. The risk isn’t in the calendar. The risk is in the architecture.
And architecture doesn’t get debugged.