With 142 days left before Nigeria’s 2027 general elections, researchers discovered something that has no business existing on a national election body’s website: nearly 30 casino and gambling articles, published and live on inecnigeria.org itself. Not links pointing outward to gambling platforms, but actual pages hosted directly under the Independent National Electoral Commission’s own domain, the same domain more than 90 million registered Nigerian voters are expected to trust for accurate election information.
Who Found It, and What Was Actually There
The discovery came from Martin Uwakwe, an X user known by the handle @mundus01 who focuses on analysing public sector digital infrastructure and government websites. On August 26, he documented roughly 28 gambling and casino pages sitting on INEC’s official site, including Czech-language casino explainers and promotions like “instant casino France,” the kind of search engine bait content gambling operators use to game Google rankings. Premium Times independently reviewed the archived links Uwakwe provided and confirmed the pages had genuinely been published and hosted on INEC’s website. Since the discovery went public, some of the pages have started disappearing, several links now return a 404 error, and others have had their headers quietly changed to “Uncategorised,” signs that INEC is scrambling to clean up in real time.
The Name That Makes This Harder to Dismiss
What turns this from a strange but explainable glitch into a genuine governance concern is who the content appears to trace back to. Most of the clearest cluster of casino pages was published under the WordPress author name Ajuma Achor, a name that matches a real person listed professionally as Head of Marketing at Interra Networks, an ICT vendor that has previously supplied contact-centre and other services to INEC. Uwakwe laid out two possible explanations, and was careful not to claim certainty about either. Either INEC’s website has been compromised for a long time through an old or forgotten publishing account nobody was monitoring, or someone with legitimate access to that system is misusing it, potentially to sell paid SEO placements on the back of a trusted government domain. Neither explanation is reassuring, and INEC has not yet clarified which one it actually is.
Why the Casino Pages Aren’t the Real Danger
It’s worth being precise about what this incident does and doesn’t mean, and the researchers behind the discovery have been careful on this point. Gambling content sitting on a government website cannot change a vote count or alter an election result. The actual concern is what that access represents. If an unauthorised party, or a misused authorised account, can publish content freely on Nigeria’s official election website, the same weakness could plausibly be used for something far more damaging: phishing pages impersonating INEC, fake election announcements timed to cause confusion, or disinformation dressed up with the credibility of an official government domain. Researchers also flagged a second, related problem on voters.inecnigeria.org, a subdomain that was found serving unrelated Russian-language text and carrying an SSL certificate that appeared linked to a different domain entirely, a pattern consistent with what security researchers call a subdomain takeover. That subdomain has since gone dark as well.
INEC Isn’t the Only Target
This isn’t an isolated Nigerian embarrassment, and understanding that actually matters for how seriously it should be taken. The INEC discovery fits a pattern documented separately by Techpoint Africa: an Indonesian-linked network has been planting casino content inside roughly 20 government websites across 16 African countries, including Nigeria, Egypt, Kenya, Uganda, Ghana, and South Africa. The motive is straightforward search engine manipulation. Google trusts long-established official government domains far more than a brand-new gambling site, so hiding casino content inside a government content management system lets gambling operators inherit that trust and rank higher than they otherwise could. Chris Nwobi, a researcher at Zend Cybersecurity Threat Labs, has noted that attackers didn’t need sophisticated exploits to pull this off, just outdated software and administration panels left exposed to the open internet. Nigeria has seen this exact pattern before too. A similar gambling presence turned up on the website of Nigeria’s Federal High Court as early as November 2024, and by May 2026 multiple Nigerian government agencies were found serving the same Indonesian-branded content.
The Question Sitting Next to This One
This discovery lands only weeks after INEC’s own ICT director publicly confirmed that the Bimodal Voter Accreditation System devices used to verify voters at polling units still run on Android 10, an operating system that stopped receiving mainstream security support back in 2023. INEC maintains the devices carry additional security layers beyond the operating system itself, and it’s true that the website and the BVAS hardware are entirely separate systems: a compromised website does not prove a compromised voting device, and vice versa. But taken together, a public-facing website with an apparently unmonitored publishing gap and accreditation hardware running unsupported software for three years and counting, the two stories point at the same underlying question. Is Nigeria maintaining its election infrastructure with anything close to the seriousness that went into building it in the first place?
With 142 days on the clock, that’s a question INEC would be wise to answer clearly and publicly, before Nigerian voters are left to draw their own conclusions instead. Election security in 2027 isn’t only about what happens at the ballot box. It’s also about whether the digital systems Nigerians rely on to know what’s real can still be trusted to tell them.