Nigeria’s electoral commission is facing fresh cybersecurity questions after casino and gambling pages were discovered on its official website just 142 days before the 2027 election.
The pages were found on the website of the Independent National Electoral Commission (INEC) on August 26, 2026, with data researcher Mundus documenting dozens of gambling-related articles hosted directly on the official domain.
The discovery comes as INEC prepares for the next general election and weeks after the commission confirmed that its Bimodal Voter Accreditation System (BVAS) devices continue to run on Android 10.
The incident does not, by itself, prove that INEC’s election systems or voter database have been compromised. However, the presence of unauthorised-looking content on an official electoral website raises questions about publishing access, account security and the commission’s wider cybersecurity controls.
Casino pages appeared on INEC’s official website
The gambling content was not simply linked from INEC’s website. The pages were hosted on the official INEC domain and included casino-related articles written for search-engine visibility.
According to the investigation, about 28 gambling pages were identified, including Czech-language casino explainers and promotions targeting searches such as “instant casino France”.
The pages were clustered under a WordPress author account named Ajuma Achor.
The discovery is significant because publishing content directly to an official government domain generally requires access to the website’s content management system or another authorised publishing mechanism.
However, it is not yet clear how the pages were uploaded.
Similar Read: INEC’s New Online Voter Registration Portal Crashes Hours After Launch
One possibility is that an old or compromised publishing account was still active. Another is that an individual with legitimate access to the website used the account to publish commercial SEO content.
Until INEC completes a forensic investigation, it would be premature to conclude that the website was taken over by a specific foreign hacking group.
What is clear is that gambling content was able to appear on a website Nigerians rely on for official election information.
A wider Indonesian-linked gambling campaign
The INEC incident comes against the backdrop of a wider campaign involving casino operators placing gambling content on government websites across Africa.

Research by Techpoint Africa previously identified an Indonesian-linked gambling syndicate that had inserted casino pages into government websites across several African countries.
The campaign reportedly affected about 20 government websites in 16 African countries, including Nigeria, Egypt, Kenya, Uganda and Ghana.
According to cybersecurity researcher Chris Nwobi of Zend Cybersecurity Threat Labs, the objective was primarily commercial rather than political.
Instead of attacking government systems to steal sensitive information, the operators reportedly exploited weaknesses in government websites to publish casino content. Because established government domains carry significant search authority, gambling operators can potentially use those domains to improve the visibility of their own businesses.
Nwobi said the campaign did not necessarily require sophisticated hacking techniques. Outdated website software, exposed administration panels and weak security controls could provide enough access to publish content.
Several Nigerian government websites had previously been associated with similar gambling-related activity, including the Federal High Court website and other public-sector domains.
The researchers have linked some of the activity to Indonesian infrastructure and commercial identifiers.
However, the evidence currently available does not conclusively establish that the same operators were responsible for the newly discovered INEC pages.
That distinction matters, particularly because INEC manages election infrastructure and any claim of a foreign cyberattack could have significant political consequences.
Why the INEC breach matters before an election
Casino articles may appear relatively harmless compared with a stolen database or ransomware attack.
But the underlying security issue is more important.
If an unauthorised person can publish dozens of pages on an electoral commission’s official website, it raises questions about who has publishing access, how those accounts are protected and whether old credentials or third-party access have been properly revoked.
A compromised government website could potentially be used for more than gambling advertisements.
The same type of access could theoretically be abused to publish fake election announcements, misleading voter information or phishing pages designed to collect personal information.
That does not mean any of those things happened on INEC’s website.
There is currently no evidence from the discovery of casino pages alone that Nigeria’s voter register, election results or BVAS systems were accessed.
The concern is that a weakness capable of allowing unauthorised publishing could provide an avenue for a more damaging attack if it is not identified and closed.
Voter portal also raises concerns
A separate issue was reportedly identified around INEC’s voter-facing infrastructure.
Reports on August 26 indicated that voters.inecnigeria.org was serving unrelated Russian-language content and was associated with an SSL certificate belonging to another, unrelated domain.
That type of configuration can be consistent with a possible subdomain takeover, although it requires a proper technical investigation before being described as a confirmed takeover.
For an electoral body, however, even the possibility is concerning.
Voters depend on official digital platforms to determine whether information about registration, polling locations and other election services is legitimate.
A compromised or misconfigured voter-facing subdomain could therefore create opportunities for phishing, misinformation or confusion, particularly during an election period.
INEC’s BVAS devices still run Android 10
The website incident also comes at a sensitive time for INEC’s election technology.
The commission’s Director of ICT, Dr Lawrence Bayode, recently confirmed that its BVAS devices still operate on Android 10.

The devices were deployed with the Android 10 operating system when the hardware was acquired, and INEC has said upgrading the operating system would present hardware and performance challenges.
Bayode has also defended the security of the customised BVAS environment, explaining that the devices do not simply operate as ordinary consumer Android phones. INEC uses customised software and additional security controls around the system.
He has maintained that the existing configuration is performing adequately.
The issue nevertheless continues to attract cybersecurity concerns because Android 10 is an older operating system and maintaining security over an ageing technology stack requires more than simply keeping the hardware operational.
The important distinction is that running Android 10 does not prove that BVAS is compromised.
Likewise, the discovery of casino pages on INEC’s public website does not prove that BVAS or the national voter register has been breached.
The two systems should not be treated as the same infrastructure.
But they raise a common question: how effectively is INEC managing the security lifecycle of the technology it will depend on during the 2027 election?
What the incident means for voter data
The biggest concern is not the casino advertisements themselves.
It is the possibility that weaknesses in digital infrastructure could eventually be exploited for something more serious.
INEC manages extremely sensitive election information, including voter registration records and biometric information used during accreditation.
A website publishing account cannot automatically provide access to BVAS or the national voter register. Similarly, an ageing operating system does not automatically mean that election data can be manipulated.
However, election security depends on multiple layers working together.

The public website must be protected. Administrative accounts must be properly controlled. Third-party access must be audited. Subdomains must be monitored. Election devices must receive appropriate security maintenance, and any vulnerabilities must be identified before election day.
A weakness in one layer does not necessarily compromise the entire election system, but it can undermine public confidence in the institution responsible for running it.
What INEC needs to do before the 2027 election
The immediate priority should be a forensic investigation into how the casino pages appeared on INEC’s website.
INEC should establish:
- Which account or vulnerability was used to publish the pages.
- How long the gambling content was accessible.
- Whether the responsible account was compromised or authorised.
- Whether any other sections of the website were modified.
- Whether the voter-facing subdomain was compromised or simply misconfigured.
- Whether any voter information or other sensitive systems were accessed.
The commission should also conduct a comprehensive audit of its website administrators, vendors, third-party accounts and subdomains.
The wider Indonesian-linked gambling campaign makes that investigation even more important, but attribution should come from technical evidence rather than assumption.
With Nigeria’s 2027 election approaching, the objective should be straightforward: ensure that every official digital channel Nigerians use to access election information can be trusted.
INEC’s current election information lists January 16, 2027, for the Presidential/House of Assembly election and February 6 for the Governorship/State House of Assembly election.
That leaves little room for unresolved cybersecurity weaknesses.
The casino pages may have been created for nothing more than search-engine traffic and gambling promotion. But for Nigeria’s electoral commission, their appearance on an official domain is still a warning that website security cannot be treated as an afterthought.
With the 2027 election approaching, INEC needs to find out exactly how those pages got there and make sure the same weakness cannot be used for something far more damaging.
Also Read: Nigeria Crypto Market Expands as SEC Admits Yellow Card, Blockchain.com and Pisi Into ARIP


