The Independent National Electoral Commission (INEC) has launched an internal investigation into an employee with legitimate database access following the unauthorized disclosure of a voter record belonging to an FCT party primary candidate.
The Department of State Services (DSS) has also initiated a parallel, independent probe into the incident, according to a statement released Tuesday by Mohammed Kudu Haruna, National Commissioner and Chairman of the Information and Voter Education Committee.
The official response follows widespread allegations of a database compromise circulating on social media and across various media outlets.
Internal Audit Rules Out External Hacking
Preliminary findings from INEC’s internal audit trail indicate that the commission’s core Information and Communications Technology (ICT) infrastructure remains secure.
"Preliminary findings from the Commission’s audit trail so far indicate that there was no external breach of the CVR database, no hacking incident, and no unauthorized external access to the Commission’s ICT infrastructure," Haruna stated. "Rather, the information in question was accessed through valid user credentials assigned to personnel participating in the ongoing CVR exercise but released without authority."
Registration officers nationwide are granted strictly controlled access to specific database components to facilitate:
-
The registration of new applicants
-
The processing of voter transfer requests
-
The updating of existing voter records
The commission emphasized that this access is restricted entirely to official duties and is automatically revoked upon the conclusion of the Continuous Voter Registration (CVR) exercise.
Investigation and Accountability Measures
Using its digital audit trail, INEC investigators successfully isolated the specific user account used to retrieve the candidate's record. Relevant personnel have already undergone questioning, and all connected administrative units are reportedly cooperating with the inquiry.
INEC is currently reviewing all technical, administrative, and operational protocols to determine how the breach occurred and to establish individual liability.
To reassure the public, the commission clarified the scope of the incident, confirming that only a single voter record was compromised. The personal data of the country's more than 90 million registered voters remains secure, and the overall integrity of the voter registration infrastructure has not been impacted.
Next Steps
While the DSS proceeds with its independent investigation, INEC has pledged full cooperation with the security agency and all other relevant authorities. The electoral umpire warned that any individuals found culpable will face criminal prosecution.
The commission urged the public and the media to refrain from speculation while the investigation runs its course, promising to publish its final findings and any subsequent corrective measures once the probe concludes.
