INEC denies database hack, launches probe into unauthorised voter record disclosure

The Independent National Electoral Commission (INEC) has denied reports that its Continuous Voter Registration (CVR) database was hacked, saying preliminary investigations indicate that a voter record linked to a political party primary in the Federal Capital Territory was accessed using authorised credentials and not through an external cyberattack.
INEC disclosed this on Tuesday as it announced a full-scale investigation into the unauthorised release of information obtained from its voter registration system.
In a statement signed by the National Commissioner and Chairman of the Information and Voter Education Committee, Mohammed Kudu Haruna, the commission said an audit of its systems showed no evidence of a breach of its database or information technology infrastructure.
“Preliminary findings from the Commission’s audit trail so far indicate that there was no external breach of the CVR database, no hacking incident and no unauthorised external access to the Commission’s ICT infrastructure,” the statement said.
According to the commission, the information at the centre of the controversy was accessed through a valid user account assigned to personnel participating in the ongoing voter registration exercise.
“Rather, the information in question was accessed through valid user credentials assigned to personnel participating in the ongoing CVR exercise but released without authority,” INEC stated.
The commission explained that registration officers are granted limited access to specific sections of the CVR platform to perform official duties such as processing new registrations, transfer requests and updates to voter records. It added that such access is revoked once the exercise ends.







