INEC Denies Database Hack, Launches Probe Into Unauthorized Release of Voter Record
INEC Denies Database Hack, Launches Probe Into Unauthorized Release of Voter Record
By Divine Macaulay ·
The Independent National Electoral Commission (INEC) has dismissed reports suggesting that its Continuous Voter Registration (CVR) database was hacked, stating that preliminary findings show the incident stemmed from the misuse of authorized access credentials rather than an external cyberattack.
In a statement issued on Tuesday, the Commission said it had launched a comprehensive investigation following allegations circulating on social media and in parts of the media regarding the unauthorized access and publication of information relating to a candidate who participated in a recent political party primary election in the Federal Capital Territory (FCT).
According to INEC, authorized Registration Officers participating in the ongoing nationwide CVR exercise were granted controlled access to specific sections of the registration system for official duties, including registering new voters, processing transfer requests, and updating voter records. The Commission stressed that such access is strictly regulated and intended solely for official purposes.
INEC revealed that an audit trail from its preliminary investigation had identified the user account through which the information was accessed. Relevant personnel have since been questioned, while departments connected to the incident are cooperating with investigators.
The Commission said it is reviewing all technical, administrative, and operational aspects of the matter to determine individual responsibility, establish how the credentials were used, and identify any violations of internal access-control protocols.
“Preliminary findings indicate that there was no external breach of the CVR database, no hacking incident, and no unauthorized access to the Commission’s ICT infrastructure,” the statement said. “The information was accessed using valid credentials assigned to personnel involved in the ongoing CVR exercise but was released without authorization.”
INEC emphasized that the incident involved the retrieval of a specific voter record and does not suggest any compromise of the wider voter registration system or the personal data of more than 90 million registered voters.
Reaffirming its commitment to data security and voter privacy, the Commission said it takes the confidentiality and integrity of voter information seriously and would take appropriate action against anyone found culpable.
The Commission also disclosed that the Department of State Services (DSS) has independently commenced an investigation into the matter. INEC pledged full cooperation with security agencies and said anyone found responsible would face legal consequences.
The electoral body urged the public and media organizations to avoid speculation while investigations continue, assuring Nigerians that its findings and any actions taken would be made public in due course.