l0grisk intelligence · english

// analysis

France’s e-invoicing agency left 878 email addresses visible

Illustration for the analysis: France’s e-invoicing agency left 878 email addresses visible

An AIFE invitation displayed 878 distinct addresses in its recipient fields. An internal mailing error that calls for a clear response.

dated revision: September 04, 2026French originalprimary sourcesno tracker

On 28 August 2026, France’s Agency for State Financial IT, AIFE, invited accredited e-invoicing platforms to a meeting about security. The invitation went out with the recipient list displayed in the “To” and “Cc” fields. The copy examined by l0g contains 895 visible entries, or 878 distinct addresses after exact duplicates are removed. This was an internal mailing mistake made with an ordinary email tool. A bulk-mailing service or the “Bcc” field would have kept the list private.

About the email. The message is not public. A copy was provided anonymously to l0g. We are not publishing the raw file, the addresses, the domains or the registration link. We sent our questions to AIFE on 31 August. As of 4 September, the agency had answered none of them.

895 visible entries, 878 distinct addresses

The “To” field contains 881 entries, while “Cc” contains 14. The resulting 895 entries include 17 exact duplicates. After those are removed, 878 distinct addresses remain across 212 email domains.

878distinct visible addresses

In practical terms: anyone who received this version of the message could browse the list placed in its visible recipient fields.

895 entries in total, including 17 exact duplicates. Some identify individuals, while others are shared mailboxes.

The figure does not mean 878 people or 878 platforms. One company may have several contacts, one person may use more than one address, and some mailboxes are generic. We also do not know how many messages were successfully delivered.

The underlying mistake is straightforward. There was no need to show the full list in order to send the invitation. Judging by their labels, some mailboxes relate to support, administration, interoperability or operations. l0g is publishing none of them.

A very simple mailing mistakeThe 895 entries were placed in the To and Cc fields, so each recipient could see the list. A bulk-mailing tool or the Bcc field would have prevented the disclosure.A VERY SIMPLE MAILING MISTAKEThe recipient fields made the list visible.BEFORE SENDING895 entriesplaced in “To”and “Cc”AFTER SENDINGEvery recipientcan see theentire listCORRECT SETUPBulk emailor “Bcc” keepsthe list privateIt starts with the email configuration.A very simple mailing mistakeThe 895 entries were placed in the To and Cc fields, so each recipient could see the list. A bulk-mailing tool or the Bcc field would have prevented the disclosure.A SIMPLE MAILING MISTAKEThe list was in the visible fields.BEFORE SENDING895 entries in “To”and “Cc”AFTER SENDINGEvery recipientcan see the full listCORRECT SETUPBulk email or “Bcc”keeps the list privateA configuration error.
A properly configured bulk mailing separates the message from its distribution list. Here, both went out together.

Why the list matters to recipients

The email does more than display contact details. It connects them to a real meeting, a specific date, familiar terminology, a follow-up file and an expected confirmation message. A later email reusing those details could therefore look familiar to the people involved.

The sensible response is practical: tell recipients that the list circulated, restate the official channels for documents and meeting links, and check subsequent mailings. The facts do not require a more dramatic story. What happened was a distribution error.

The mistake occurred in an ecosystem that has just become central to French business. Since 1 September 2026, companies subject to VAT must be able to receive electronic invoices through an accredited platform. l0g examined the architecture and its dependencies in a five-part investigation into France’s new e-invoicing chain.

Platform oversight continues after launch

The invitation also gives a glimpse of AIFE’s planned follow-up: a dedicated security unit, a post-production file, bilateral reviews and a process leading to the compliance audit.

Platforms do not start operating without prior checks. Their registration file includes information about data security and an ISO/IEC 27001 certificate. France’s tax authority says final registration is granted only after real-world interoperability tests have succeeded. AIFE also says it helped operators connect to the public infrastructure and complete the required technical and functional tests.

The full compliance audit has a different timetable. Article 242 nonies B of Annex II to the French Tax Code allows the report to be submitted up to one year after registration is notified. Article 41 septies A of Annex IV requires the initial audit to cover at least one month of activity after that notification. If the report identifies non-compliance, the stated deadline for corrective measures cannot exceed three months after the report is submitted.

The email therefore describes a genuine follow-up process without giving its detailed schedule or criteria. Our questions were intended to clarify those points.

A practical response and a GDPR assessment

AIFE can address the error in plain terms: inform the people affected, confirm the official communication channels, review how mailing lists are handled and document its data-protection assessment.

A work address is personal data when it identifies an individual. France’s data protection authority notes that an unauthorised disclosure can be accidental. Every personal-data breach must be recorded internally. Notification to the CNIL then depends on the risk to people’s rights and freedoms, while direct notification to individuals depends on a high risk. l0g cannot make that assessment on AIFE’s behalf. (CNIL, rules for personal-data breaches)

We therefore asked whether the assessment had been carried out, what measures had been taken and whether the recipients had been warned.

Eight questions unanswered as of 4 September

On 31 August, l0g sent AIFE eight questions about the mailing error and its oversight of platforms after they entered production.

Read the eight questions sent to AIFE
  1. What exactly will the post-production follow-up file contain, and when must platforms submit it?
  2. Will the announced bilateral reviews cover every accredited platform? Under what timetable or priority order?
  3. What does the “security trajectory until the audit” mean: normal improvement, reservations already identified or outstanding non-compliance?
  4. As of 1 September 2026, how many platforms had already submitted their full compliance audit report?
  5. Which security incidents must be reported to AIFE, within what time and through which procedure?
  6. Which findings or failures can lead the administration to restrict or suspend a platform’s activity?
  7. Will AIFE publish aggregated results from audits, technical tests, recovery tests and reported incidents?
  8. Was the 28 August recipient disclosure entered in the breach register and assessed under the GDPR? Was notification to the CNIL or the people affected considered necessary?

As of 4 September, AIFE had provided no answer. Any substantive response will be added to this article.

The mistake comes down to an email field. The remedy should be equally concrete: warn people, clarify the official channels and make sure the list is not sent again. For an agency coordinating a digital project of this scale, that is part of day-to-day discipline.


Method and limits

  • Non-public source: a copy of an email dated 28 August 2026, provided anonymously to l0g.
  • Message check: review of the authentication headers and delivery chain before publication.
  • Counting: local extraction of the To and Cc fields, lower-case normalisation and exact deduplication. No address was tested for validity or deliverability.
  • Protection: no recipient address, domain, registration link or technical message identifier is published.
  • Scope: the figures describe the copy received by l0g. They do not establish how many messages were successfully delivered.
  • Cut-off: 4 September 2026, 9:00 am Paris time.

Main public sources

This analysis is not investment advice.

// cite this analysis

l0g, “France’s e-invoicing agency left 878 email addresses visible”, l0g.fr, published September 04, 2026, updated September 04, 2026, https://l0g.fr/en/analysis/france-e-invoicing-aife-cyber-email-878-addresses/


$ cd ../analysis