The Independent National Electoral Commission (INEC) and the Department of State Services (DSS) have launched separate investigations into the alleged unauthorised release of information from the nation’s voter registration database, raising fresh concerns over the security of electoral records.
INEC disclosed on Tuesday that preliminary findings showed the controversial voter information was accessed through valid staff credentials and not by hackers, as widely speculated.
The electoral umpire said the information, linked to a candidate who participated in a recent political party primary in the Federal Capital Territory (FCT), was allegedly retrieved from the Continuous Voter Registration (CVR) database and released without authorisation.
In a statement issued by the National Commissioner and Chairman of the Information and Voter Education Committee, Mohammed Kudu Haruna, INEC said it had swung into action immediately after reports of the alleged leak surfaced on social media and other media platforms.
According to the Commission, its audit trail has already identified the user account through which the information was accessed, while relevant personnel connected to the incident have been questioned.
INEC said investigators are examining all technical, administrative and operational aspects of the matter to determine responsibility and establish whether internal access-control procedures were violated.
The Commission, however, moved to calm public fears, insisting that there was no cyberattack on its systems and no evidence that external actors breached its database.
“Preliminary findings indicate there was no external breach of the CVR database, no hacking incident and no unauthorised external access to the Commission’s ICT infrastructure,” the statement said.
INEC explained that authorised registration officers participating in the ongoing nationwide voter registration exercise are granted controlled access to specific sections of the database strictly for official duties, adding that such access is withdrawn once the exercise ends.
The electoral body stressed that the incident under investigation involved only the retrieval of a specific voter record and did not compromise the personal information of over 90 million registered voters nationwide.
“The incident does not indicate any compromise of the Commission’s broader voter registration infrastructure or the personal data of registered voters,” INEC stated.
Meanwhile, the DSS has commenced its own independent investigation into the matter.
INEC said it would cooperate fully with security agencies and vowed to ensure that anyone found culpable faces appropriate legal sanctions.
The Commission reiterated its commitment to protecting voter information and maintaining public confidence in Nigeria’s electoral process.
It also urged Nigerians to ignore rumours and speculation while investigations continue, assuring that the outcome of the probe and any disciplinary measures taken would be made public.
The development comes amid growing concerns over data privacy and cybersecurity as Nigeria increasingly relies on digital platforms for electoral administration and voter management.

