The official website of the Independent National Electoral Commission (INEC) has been compromised, with multiple gambling and casino pages directly hosted on its domain. The security breach comes just 142 days before Nigerians will head to the polls for the 2027 General Elections.
The incident was first exposed on X by data researcher @mundus01, who documented roughly 28 foreign casino and gambling articles hosted on inecnigeria.org. The defacement consists of live, published pages on the main domain, including Czech-language casino guides and instant casino France promotional content, rather than simple outbound redirects.
A critical lead in the breach involves the CMS metadata, which reveals that the pages were published under the WordPress author handle “Ajuma Achor.” Historical records identify a person by that same name as the former Head of Marketing at Interra Networks, a technology firm previously contracted to supply contact-centre and ICT services to INEC.
The researcher points to two alarming possibilities: either INEC’s portal has suffered an undetected long-term breach via dormant publishing credentials, or an internal account with administrative access is actively abusing the platform for paid Search Engine Optimization (SEO) spam.
In a secondary failure flagged the same night, voters.inecnigeria.org began serving Russian-language content paired with an SSL certificate issued to an unrelated domain, a classic signature of a subdomain takeover on voter-facing infrastructure.



