Concerns have emerged over the digital security of websites operated by Nigeria’s Independent National Electoral Commission (INEC) after unrelated casino and gambling content was reportedly discovered on the Commission’s official website ahead of the 2027 general elections.
Researchers reportedly found casino-related pages hosted directly on inecnigeria.org, including foreign-language gambling content published through the website’s content management system (CMS). The discovery has raised questions about the security of the platform and the level of access available to third parties.
The reported content did not simply redirect visitors to external gambling websites. Instead, the pages appeared to be hosted directly on INEC’s official domain, which serves as an important source of electoral information for Nigerian voters.
Separate concerns have also been raised regarding voters.inecnigeria.org, with researchers reportedly identifying unrelated Russian-language content and an SSL certificate apparently associated with another domain. These findings have prompted speculation about a possible subdomain takeover, although the precise cause and extent of any compromise would require confirmation from INEC or an independent technical investigation.
The potential security implications extend beyond the presence of gambling content itself. While the publication of casino pages on an electoral website does not, by itself, indicate that election results or voting systems have been compromised, unauthorized access to an official government platform could create opportunities for more serious forms of abuse.
A compromised website could potentially be used to distribute phishing pages, publish fraudulent election announcements, impersonate electoral authorities or spread misleading information to voters. Such risks are particularly significant as Nigeria approaches the 2027 elections and increasingly relies on digital platforms to communicate election-related information.
The concerns come alongside questions about the security and maintenance of other election-related technologies. INEC has previously confirmed that its Bimodal Voter Accreditation System (BVAS) devices operate on Android 10, an operating system that reached the end of mainstream security support in 2023. The Commission has maintained that additional security measures are deployed on the devices.
However, the security of INEC’s public-facing websites and its BVAS infrastructure are separate issues. The discovery of unauthorized or unrelated content on a website does not establish that BVAS devices or election results have been compromised.
Nevertheless, the developments highlight the importance of maintaining strong cybersecurity controls across all digital systems associated with electoral administration. These include secure credentials, timely software updates, continuous monitoring, access controls, vulnerability management and rapid incident response.
With the 2027 elections approaching, cybersecurity experts and election stakeholders are likely to expect greater transparency from INEC regarding the reported website incidents, including how the content was published, whether unauthorized access occurred, what systems may have been affected and what measures have been implemented to prevent a recurrence.
Protecting election integrity extends beyond securing voting equipment and ballots. Public confidence also depends on ensuring that the digital platforms Nigerians use to obtain official election information remain secure, authentic and reliable.



