Commission says info on FCT political candidate accessed with valid credentials, DSS launches parallel probe_
*ABUJA* — The Independent National Electoral Commission [INEC] has launched an investigation into allegations of unauthorized disclosure of information from its Continuous Voter Registration [CVR] database after reports surfaced online about the leak of a political candidate’s record in the Federal Capital Territory.
In a press statement issued Monday, June 2, 2026, and signed by National Commissioner and Chairman of the Information and Voter Education Committee [IVEC], Mohammed Kudu Haruna, the Commission said it took the allegations seriously and had begun a thorough probe to establish the facts.
“The attention of the Independent National Electoral Commission (INEC) has been drawn to allegations currently circulating on social media and in some sections of the media regarding the alleged unauthorised access to the Commission’s Continuous Voter Registration (CVR) database and the subsequent publication of information on a candidate in the recent primaries of a political party in the Federal Capital Territory,” the statement read.
*No external hack, INEC says*
According to INEC, preliminary findings from its audit trail show there was no external breach of the CVR database and no hacking of its ICT infrastructure.
“Preliminary findings from the Commission’s audit trail so far, however, indicate that there was no external breach of the CVR database, no hacking incident, and no unauthorised external access to the Commission’s ICT infrastructure. Rather, the information in question was accessed through valid user credentials assigned to personnel participating in the ongoing CVR exercise but released without authority,” Haruna stated.
The Commission explained that as part of the ongoing nationwide CVR exercise, authorized Registration Officers were granted controlled access to specific components of the system to register new voters, process transfers, and update records. Such access is limited to official duties and is withdrawn after the exercise.
INEC said the audit trail helped it identify the user account used to access the record. Relevant personnel have since been questioned, and all units connected to the incident are cooperating with investigators.
“The Commission is also examining all technical, administrative and operational factors associated with the matter in order to establish individual responsibility and determine the circumstances surrounding the use of those credentials and identify any breach of internal access-control protocols before taking appropriate action against anyone involved,” the statement added.
*Scope of incident limited*
INEC stressed that the case relates only to the retrieval of a specific voter record and does not suggest a compromise of its broader voter registration infrastructure or the personal data of over 90 million registered voters.
The Commission reaffirmed its commitment to data security and voter privacy.
“The Commission wishes to state categorically that it takes the security, confidentiality and integrity of voter data with the utmost seriousness and remains committed to transparency, institutional integrity, and the protection of voters’ personal information,” Haruna said.
*DSS opens independent investigation*
The Department of State Services [DSS] has also commenced its own independent investigation into the matter. INEC said it will cooperate fully with security agencies and will refer anyone found culpable for legal action.
“Members of the public and the media are therefore urged to disregard unfounded speculations while investigations remain ongoing. The Commission will continue to keep the public informed of its final findings and any measures taken in response to the incident in due course,” the statement concluded.
The incident comes amid heightened political activity following party primaries held across the country, including in the FCT, raising concerns about data privacy and the security of electoral records.











