INEC Website Hacked? Panic as Casino Ads, Russian Text Reportedly Spill Onto INEC Portal

INEC Website Hacked? Panic as Casino Ads, Russian Text Reportedly Spill Onto INEC Portal

The official website of Nigeria’s Independent National Electoral Commission (INEC) has reportedly been compromised, with dozens of online casino and gambling pages allegedly hosted on the commission’s digital platform, Ejes Gist News understands.

The discovery was made public by a United States-based Nigerian data and technology analyst, who raised serious concerns regarding the cybersecurity framework of INEC’s portal less than six months before the scheduled 2027 general elections.

The tech analyst, identified on the social media platform X by the handle @mundus01, stated that he identified multiple gambling-related articles published directly under the domain of the electoral body. Emphasizing the nature of the security vulnerability, the analyst clarified that the issue involved pages hosted directly on the commission’s infrastructure rather than external hyperlinks.

INEC Website hacked

 

“I found multiple casino and gambling articles hosted directly on @inecnigeria official website,” he wrote in a series of posts addressing the issue. “I am not talking about INEC linking to casino websites. These are actual gambling pages published under inecnigeria dot org.”

Also Read : Vote APC or Face Violence: Amnesty International Calls for Immediate Arrest of Kuje Chairman

According to the analyst’s findings, approximately 28 casino and gambling pages were hosted on the portal. A significant portion of these pages appeared to have been published under the Content Management System (CMS) author profile named “Ajuma Achor.”

Subsequent background verification by the analyst revealed that an individual with the same name had previously worked for Interra Networks, a technology firm that had engaged in web support services for INEC. However, public professional records on LinkedIn indicate that the individual left Interra Networks several years ago.

Allegations of Compromised Accounts and SEO Spam

The discovery has raised fundamental questions regarding access control management within the electoral body’s administrative backend. Experts are questioning whether an unrevoked, inactive, or compromised publishing credential remains active, or if current administrative credentials have been improperly accessed.

“Either INEC’s website has been compromised for a long time without anyone noticing, possibly through an old or compromised publishing account,” the analyst noted. “Or someone with access to INEC’s website is abusing that access to publish casino content, potentially as paid SEO placements.”

The researcher explained that while current public data cannot conclusively determine which of the two scenarios caused the breach, both possibilities represent severe administrative and security failures. He warned that if unauthorized users are capable of publishing dozens of pages on INEC’s primary platform without immediate detection, similar access could potentially be exploited to circulate false information during an active election cycle.

The analyst raised concerns regarding whether such unauthorized access could be leveraged to disseminate unverified election results, fraudulent official announcements, or misleading public notices designed to create electoral instability and public disorder. Consequently, he called on the commission to perform more than a surface-level deletion of the gambling content.

“INEC needs to determine who has publishing access, how these pages got there, and whether that access still exists,” he stated.

Vulnerabilities on Voter Subdomain and Wider Cybersecurity Risks

The technical concerns raised regarding the electoral body’s digital infrastructure appear to extend beyond the unauthorized casino postings on the main domain name.

The US-based analyst raised a secondary security warning regarding INEC’s dedicated voter portal. He reported that the subdomain voters.inecnigeria.org was actively displaying unrelated Russian-language text and serving an Secure Sockets Layer (SSL) certificate belonging to a newly registered, unrelated external domain.

“URGENT: @inecnigeria, voters.inecnigeria.org is serving unrelated Russian text and an SSL certificate for a newly registered, unrelated domain. This is a critical security failure and possible subdomain takeover,” he published on X.

Following the discovery, the analyst advised INEC to temporarily take the affected voter subdomain offline to contain potential risks. He further recommended that the commission initiate a joint technical investigation alongside the Nigeria Computer Emergency Response Team (ngCERT) to resolve potential Domain Name System (DNS) misconfigurations and secure the platform.

The revelations have generated fresh discussions regarding the cyber resilience of INEC’s core IT infrastructure ahead of the 2027 general elections, a period during which millions of voters, political organizations, and international observers rely heavily on the commission’s online platforms for critical electoral information.

Broader Scrutiny and Electoral Context Ahead of 2027

The reported digital vulnerabilities follow prior public debates surrounding the administration and institutional independence of the electoral body.

Previous public scrutiny has centered on concerns regarding the perceived independence of INEC Chairman, Joash Amupitan, following political claims and debates concerning his past online statements and historic political associations.

Additionally, the electoral umpire has faced questions regarding data protection standards and the handling of sensitive voter registry information. In June 2026, allegations emerged claiming that an aide to the Minister of the Federal Capital Territory (FCT), Nyesom Wike, gained unauthorized access to confidential voter data belonging to Emeka Ike, a Nollywood actor and politician affiliated with the Nigeria Democratic Congress (NDC).

The recent findings regarding unauthorized web pages and subdomain irregularities are expected to draw further focus toward the commission’s administrative controls, internal audit mechanisms, and overall preparedness to protect electoral systems. At the time of reporting, the claims regarding the origin of the gambling content and the mechanism of the breach remain unconfirmed by INEC, pending an official response from the commission or cybersecurity regulatory authorities.

 

Leave a Comment

Your email address will not be published.