Nice Mayor Éric Ciotti Urges Lecornu to Suspend E-Invoicing After DGFiP Hack
Nice mayor Éric Ciotti asked PM Sébastien Lecornu to delay France's Sept. 1 e-invoicing mandate after the DGFiP hack exposed 678,000 taxpayer accounts.
On Friday, August 22, 2026, Nice mayor and Union of the Right for the Republic (UDR) leader Éric Ciotti wrote to Prime Minister Sébastien Lecornu asking him to suspend France’s mandatory electronic invoicing reform, set to take effect on September 1. Ciotti argued that the recent DGFiP tax-authority data breach shows the state is not ready to handle a vast new flow of business billing data — and that pushing ahead would expose companies to further fraud and leaks.
The letter landed less than two weeks after Bercy confirmed that hackers had accessed systems at the Direction générale des Finances publiques (DGFiP), exposing information tied to 678,000 individuals and professionals. With the reform deadline now days away, Ciotti’s intervention turned a technical compliance issue into a national political fight over cybersecurity, bureaucracy, and the pace of digital government.
Editor’s note: This article draws on reporting from Le JDD, France 24 (AFP), Challenges, Le Figaro, the French Ministry of Economy and Finance, and specialist tax-policy coverage, August 14–22, 2026. Government timelines and breach figures may be updated as investigations continue.
What Ciotti is asking for
In a letter to Lecornu seen by Le JDD, Ciotti called on the prime minister to “suspend this deadline.” His party wants the government to postpone the rule requiring VAT-registered businesses to receive invoices electronically through a state-accredited platform (PA) or the public invoicing portal.
Ciotti’s core argument is timing and trust. After intrusions that compromised tax-agency systems, he said, France should not rush to multiply digital touchpoints before fixing basic security failures.
“Multiplying collection and exchange points before learning the lessons of these failures would expose our businesses even more to leaks and scams,” Ciotti wrote, according to Le JDD.
He warned that each invoice sent through the new system would transmit detailed commercial data to the administration — supplier and customer identities, tax lines, and payment amounts — creating what he described as a map of the French economy inside infrastructure that had already failed under attack this summer.
Ciotti also noted that the European Union obligation for structured e-invoicing applies mainly to cross-border transactions and is not scheduled until 2030, suggesting France is moving faster than Brussels requires.
The September 1 e-invoicing reform
France’s reform is one of the most ambitious e-invoicing rollouts in Europe. From September 1, 2026, large VAT-registered companies must be able to receive structured electronic invoices. Smaller firms face later phases, but the September start is the first hard milestone for the largest businesses.
| Requirement | Detail |
|---|---|
| Who is affected first | Large enterprises subject to VAT (phased rollout continues into 2027 for SMEs) |
| Invoice format | Structured data — e.g. Factur-X, UBL, or CII — not a simple PDF by email between businesses |
| Transmission | Through one of roughly 137 accredited platforms or the Portail Public de Facturation (PPF) |
| E-reporting | Transaction data reported to DGFiP in near real time |
| Penalties | Fines for non-compliant issuance or failure to receive electronically (amounts vary by violation type) |
Business-to-consumer invoices and many international flows follow different rules, but B2B compliance still demands software changes, platform contracts, and staff training — costs that employer groups and opposition politicians say fall heavily on small firms.
Ciotti’s letter cited a national consultation led by Bouches-du-Rhône MP Gérault Verny, which collected hundreds of business testimonies about added cost, lost time, and daily administrative complexity. According to UDR, nine in ten respondents issue fewer than 50 invoices per month — a profile typical of micro-businesses with limited IT capacity.
The DGFiP breach that raised the stakes
The political pressure on Lecornu did not start with Ciotti’s letter. It followed a breach that shook confidence in France’s fiscal IT systems.
| Timeline | Event |
|---|---|
| Late June – late July 2026 | Intruders accessed DGFiP systems using compromised credentials belonging to a tax-agency employee and an authorized third party |
| August 12–13 | A malicious actor publicly claimed access; Bercy acknowledged the incident |
| August 14–18 | Ministry confirmed 678,000 individuals and professionals affected; notifications began |
| August 17 | Lecornu asked ANSSI, France’s cybersecurity agency, for a deep audit and chaired an interministerial crisis cell |
Officials said usernames and passwords were not among the exposed data in most cases, and that fewer than 250 accounts may have involved access to messages between taxpayers and the administration. DGFiP head Amélie Verdier told reporters that for many professionals, exposed fields were public or quasi-public business data, though investigators were still checking whether some tax messages leaked.
Importantly, government statements and independent tax analysts have stressed that the breach did not originate in France’s dedicated e-invoicing platform network. The incident involved broader DGFiP information systems and credential security. Still, opponents argue the same ministry that failed to prevent the hack should not simultaneously demand that millions of invoices flow through its digital ecosystem.
In a Le Figaro opinion piece published August 20, Ciotti accused the state of leaving taxpayers in the dark for weeks and said stolen fiscal data effectively “armed” criminals in a country already struggling with organized fraud.
Government response so far
Matignon has not announced a delay. After the breach became public, Lecornu’s immediate focus was investigation and victim notification, not pausing unrelated reforms.
On August 17, his office said the prime minister ordered ANSSI to conduct an in-depth audit of the DGFiP incident, complementing a judicial inquiry. Lecornu also demanded that every affected person be informed individually, with details on exposed data and recommended precautions. DGFiP began emailing more than 350,000 individuals that week.
Business reporting in Challenges and elsewhere indicates the government still considers the September 1 rollout technically on track, separating the hack from the accredited-platform architecture built for e-invoicing. Tax officials have pointed to years of preparation, pilot testing, and platform certification.
That position leaves Ciotti and allies arguing policy, not just security optics: even if the breach and the invoicing pipes are not the same system, both sit under the same ministry and the same credibility test.
Who else is calling for a pause
Ciotti is not alone on the right. Cannes mayor David Lisnard, a presidential hopeful, said on August 21 that generalized e-invoicing should be suspended because “the state is not reliable.” Reconquête MEP Sarah Knafo made a similar demand on social media, linking the invoicing mandate to broader plans for online identity verification.
The convergence of cybersecurity anxiety and SME frustration gives opposition figures a single rallying point days before a reform that touches nearly every VAT-registered company in France.
What happens next
With September 1 approaching, businesses that have not finished platform selection or technical integration face a compressed window. A government delay would require a formal decision from Bercy and Matignon; none had been announced as of August 22.
ANSSI’s audit and judicial proceedings could take months. Even if invoicing proceeds on schedule, the breach may reshape parliamentary debate on state IT spending, third-party access controls, and how quickly France should centralize commercial data.
For readers searching who is mayor of Nice in this context: Éric Ciotti has held the office while leading the UDR and positioning himself as a hard-line conservative voice on security and administrative overreach. His letter to Lecornu is both a policy challenge and a reminder of how national scandals can elevate local executives into broader French political debates.
Discussion
France is betting that digitizing invoices will cut fraud and modernize tax collection — but the DGFiP hack arrived at the worst possible moment for public trust.
1. Should a cybersecurity breach delay a major digital reform, even when officials say the hacked system is separate from the new one?
Ciotti says the ministry has not earned the right to expand its data footprint. The government says the platforms are ready. Where would you draw the line?
2. Is France moving too fast compared with the EU’s 2030 cross-border timetable?
Supporters see first-mover advantage and tighter VAT control; critics see avoidable cost for small firms issuing only a few dozen invoices a month. Does national ambition outweigh compliance burden?
If you run a business — in France or elsewhere — how much would a last-minute delay help versus the disruption of yet another changed deadline?
Discuss this topic with 8 billion people:
Opinions
Your Opinion Always Matters
Discuss, debate, and vote on hot topics.
Scan to open APP
Foresight
Foresight Builds Future Confidence
Share your method to predict the future.
Scan to open APP
CameraReal
Show Your Authentic World
Capture traceable, tamper-proof photos to restore verifiable trust in social media.
Scan to open APP