INEC Traces Source Of CVR Data Leak, Rules Out Hacking

By Anayo Akwitti

The Independent National Electoral Commission (INEC) says it has identified the source of the recent leakage of information from its Continuous Voter Registration (CVR) database, dismissing claims that its systems were hacked or compromised by external actors.

The clarification follows widespread reports on social media and in sections of the media alleging unauthorised access to the Commission’s voter registration database after details relating to a candidate in a recent political party primary election in the Federal Capital Territory surfaced online.

In a statement issued on Tuesday, National Commissioner and Chairman of the Information and Voter Education Committee (IVEC), Mohammed Haruna, disclosed that a preliminary investigation had enabled the Commission to trace the source of the information leak through its internal audit trail.

According to him, the investigation identified the specific user account through which the information was accessed, prompting the questioning of relevant personnel while all units connected to the incident continue to cooperate with investigators.

Haruna explained that the Commission is conducting a comprehensive review of the technical, administrative and operational circumstances surrounding the incident to determine individual responsibility and establish whether internal access-control protocols were violated.

He stressed that preliminary findings showed no evidence of an external breach, cyberattack or unauthorised access to INEC’s ICT infrastructure.

“Preliminary findings from the Commission’s audit trail so far indicate that there was no external breach of the CVR database, no hacking incident, and no unauthorised external access to the Commission’s ICT infrastructure,” he stated.

The INEC spokesman, however, acknowledged that the information was accessed through valid credentials assigned to personnel involved in the ongoing Continuous Voter Registration exercise and was subsequently released without authorisation.

He noted that the incident was limited to the retrieval of a specific voter record and did not compromise the Commission’s broader voter registration infrastructure or the personal data of more than 90 million registered voters.

Reaffirming the Commission’s commitment to data protection, Haruna said INEC remains dedicated to safeguarding the security, confidentiality and integrity of voter information while ensuring transparency and accountability in its operations.

The Commission assured Nigerians that appropriate action would be taken against anyone found culpable after the conclusion of the investigation.

RELATED NEWS

LIVE
Democracy Radio
On air