INEC Probes Unauthorised Access, Disclosure of Information from CVR Database

2 months ago 30
ARTICLE AD BOX

• Insists no external breach of CVR database, no hacking incident

Adedayo Akinwale in Abuja

The Independent National Electoral Commission (INEC) has begun an inquiry into an alleged unauthorised access to its Continuous Voter Registration (CVR) database and the subsequent release of a candidate’s information during a recent primary election in the Federal Capital Territory (FCT).

Lere Olayinka, a media aide to FCT Minister Nyesom Wike, posted personal data belonging to Nollywood actor Emeka Ike on an INEC administrative webpage.

Following the disclosure, Ike threatened legal action against Olayinka for sharing his voter information.

Ike, a native of Imo State, had contested the House of Representatives seat for the AMAC/Bwari Federal Constituency in the FCT under the Nigerian Democratic Congress and was defeated.

INEC National Commissioner and Chairman of the Information and Voter Education Committee, Mohammed Haruna, released a statement on Tuesday announcing that the Commission has immediately started a thorough investigation to determine the facts surrounding the incident.

He said, “The Independent National Electoral Commission (INEC) has received allegations circulating on social media and in some media outlets that the CVR database was accessed without authorisation and that information about a candidate was published during the recent primaries in the Federal Capital Territory.”

“We take these allegations seriously and have promptly begun a comprehensive investigation to establish the facts,” Haruna added.

He explained that during the nationwide CVR exercise, authorised INEC Registration Officers were given controlled access to specific parts of the CVR system to register new applicants, process transfer requests, and update voter records as needed. Such access is limited to official duties and is revoked once the exercise concludes.

The audit trail from the preliminary investigation has identified the user account that accessed the information. Relevant personnel have been questioned, and all units involved are cooperating fully with the inquiry.

Haruna emphasised that the Commission is examining all technical, administrative, and operational aspects of the matter to assign responsibility, understand how the credentials were used, and identify any breach of internal access‑control protocols before taking appropriate action against those involved.

Preliminary findings from the audit trail indicate that there was no external breach of the CVR database, no hacking incident, and no unauthorised external access to INEC’s ICT infrastructure.

“Instead, the information was accessed through valid user credentials assigned to personnel participating in the CVR exercise but was released without authority,” Haruna said.

The incident concerns the retrieval of a single voter record and does not suggest any compromise of INEC’s broader voter registration infrastructure or the personal data of more than 90 million registered voters.

INEC reiterated its commitment to the security, confidentiality, and integrity of voter data, and pledged to maintain transparency, institutional integrity, and the protection of voters’ personal information.

The Commission noted that the Department of State Services (DSS) has independently launched its own investigation into the matter.

Haruna added that INEC will continue to cooperate fully with all relevant security agencies and will refer any culpable individual for appropriate legal action.

The Commission urged the public and media to ignore unfounded speculations while investigations continue.

It assured that it would keep the public informed of its final findings and any measures taken in response to the incident in due course.

Read more on this