The official website of the Independent National Electoral Commission (INEC) hosted dozens of gambling and casino-related articles, raising fresh questions about the security of the electoral body’s digital infrastructure ahead of the 2027 general elections.
The discovery was made by X user Martin Uwakwe, who analyses public-sector digital infrastructure, election data and government websites.
Uwakwe, posting through the handle @mundus01, said he found about 28 casino and gambling pages published directly on INEC’s official domain.
He stressed that the pages were not links directing visitors from INEC’s website to gambling platforms, but articles hosted within the Commission’s own website.
One of the pages identified was titled “Discover the Excitement of Instant Casino France” and was hosted under the INEC domain.
Uwakwe said most of the pages were published under the WordPress author name “Ajuma Achor”. He subsequently found a LinkedIn profile belonging to a person with the same name who had worked with Interra Networks, a technology vendor that previously worked on INEC’s website.
He said the profile indicated that Achor left the company several years ago.
Although the casino pages have since been removed from INEC’s live website, Uwakwe said they had already been archived by the Wayback Machine.
“Even though these pages have now been deleted, they were already archived on the Wayback Machine. We need a thorough independent audit of INEC’s technical infrastructure,” he said.
Chronicle NG reviewed the archived links provided by Uwakwe and confirmed that the casino-related pages had been published and hosted on INEC’s website.
The discovery has raised questions about how the content was uploaded and who had, or still has, publishing access to INEC’s content management system.
Uwakwe said he could not establish exactly how the pages came to be published but identified two possible explanations.
“Either INEC’s website has been compromised for a long time without anyone noticing, possibly through an old or compromised publishing account; or someone with access to INEC’s website is abusing that access to publish casino content, potentially as paid SEO placements,” he said.
He argued that the incident should trigger wider scrutiny of INEC’s digital security as the 2027 elections approach.
“If someone can quietly publish dozens of casino pages on INEC’s official website, then the bigger question is: what stops that same access from being used on election day to publish false information, fake results or a misleading announcement capable of causing chaos across the country?” he asked.
Uwakwe said simply deleting the pages was insufficient, urging INEC to establish how the content got onto its website and whether unauthorised access remained possible.
“This needs more than deleting the casino pages. INEC needs to determine who has publishing access, how these pages got there, and whether that access still exists,” he said.
Separate IReV vulnerability
Uwakwe’s discovery of the casino pages came amid a separate issue involving INEC’s Election Result Viewing Portal (IReV).
In an earlier post, he said he had privately contacted INEC with detailed information about what he described as a major vulnerability in the IReV portal that could affect the 2027 general election.
He said he received no acknowledgement for three days, despite sending a follow-up message.
“I noticed a major vulnerability in the @inecnigeria IReV portal that can affect the 2027 General election and reached out to them with detailed information. It has now been three days, and I have even sent a follow-up, but I have received no acknowledgment, not even a simple ‘Received.’”
“More concerning, nothing appears to have been done to address the vulnerability I discovered,” he wrote.
However, Uwakwe later clarified that the IReV vulnerability was “a completely different issue” from the casino pages found on INEC’s website.
Asked about the nature of the IReV vulnerability, he declined to disclose details publicly, saying doing so could expose the system to abuse.
“I don’t want to make it public so bad actors don’t take advantage of it, that was why I reached out to INEC directly, and the director of ICT has assured me they are working to fix it ASAP. I will keep monitoring and possibly escalate if it doesn’t get fixed,” he said.
INEC ICT director responds
In a fresh post on Thursday, Uwakwe said INEC’s Director of Information and Communication Technology had responded to his concerns and explained steps being taken to address the IReV vulnerabilities.
“I woke up to a detailed message from the Director of ICT at INEC explaining what they are doing to fix the vulnerabilities I identified in the IReV portal,” he wrote.
“Hopefully, they can get this sorted as soon as possible.”
He also clarified that the website and casino issue was not the vulnerability he had initially reported to INEC.
“It was after I made the post about INEC not responding to my email that I discovered the casino links. Since I didn’t get a response regarding the IReV issue, I felt there was no point going that route, hence the post that has now went viral,” he said.
INEC yet to comment
INEC spokesperson Mohammed Haruna was contacted by telephone and WhatsApp for clarification on the casino pages, the “Ajuma Achor” WordPress account and who had publishing access to the Commission’s website.
Enquiries also sought to establish whether INEC was aware that the pages had been hosted on its official domain, whether the incident was under investigation and whether the Commission had conducted, or planned to conduct, a security audit of its digital infrastructure.
There was no response to the enquiries as of the time of filing this report.
The casino pages have since been deleted from INEC’s live website, but their presence in archived records means the incident remains traceable.









