Electoral Body’s Digital Defenses Fail

Just 142 days before Nigeria’s 2027 general elections, the Independent National Electoral Commission (INEC) website was found to be serving casino pages—a clear indication of a security breach. The discovery occurred on August 26, 2026, raising serious concerns about the integrity of digital election infrastructure.

The compromised site featured direct links to Czech-language gambling explainers and promotions under the author name Ajuma Achor, who also appears as Head of Marketing at Interra Networks—an ICT firm that previously provided services to INEC. This suggests either a long-standing account vulnerability or authorized access being used for illicit SEO placements.

The same night, voters.inecnigeria.org was serving unrelated Russian text with an SSL certificate from a newly registered domain, indicating a possible subdomain takeover—a critical failure for voter registration and authentication services.

Part of a Coordinated Attack

This incident aligns with a recent campaign documented by Techpoint Africa involving Indonesian-linked actors planting casino content on government websites across 16 African countries. By leveraging the trust associated with official domains, attackers aim to boost search rankings for their gambling sites—a technique known as “SEO poisoning.”

Security experts note that these attacks exploit basic vulnerabilities like outdated software and exposed administration panels rather than requiring sophisticated exploits. Similar placements have already been observed on Nigeria’s Federal High Court site since November 2024.

Systemic Security Shortcomings

The INEC breach highlights deeper security challenges within the electoral system, including:

  • The use of Android 10 as the base operating system for Bimodal Voter Accreditation Systems (BVAS) despite Google ending mainstream support in 2023
  • A lack of timely software updates and independent security audits
  • Overlapping vendor relationships that create potential conflict-of-interest vulnerabilities

The BVAS devices collect biometric data, verify voter identities, and transmit results—making them prime targets for manipulation.

Implications for Election Integrity

While the attackers’ primary motive appears commercial, this security foothold could be exploited to:

  • Publish disinformation or fabricated election notices
  • Create phishing pages to harvest voter data
  • Launch timed disruptions on election day

The incident underscores the need for urgent digital security reforms to safeguard Nigeria’s electoral process and maintain public trust in democratic institutions.