FROM BALLOT BOX RIGGING TO CYBER RIGGING?
AWC POLITICAL DESK, SEPTEMBER 2026
As Nigeria moves deeper into electronic election-result transmission, the biggest question may no longer be who controls the ballot box—but who controls the digital pipeline.
Nigeria’s continuing debate over the electronic transmission of election results deserves to move beyond the political argument over whether results should be transmitted digitally.
The more fundamental question is this:
As Nigeria digitises the pathway between the polling unit, BVAS and the INEC Result Viewing Portal (IReV), how secure is that pathway against deliberate cyber manipulation?
This is not an accusation against INEC, any political party or any candidate. It is a risk scenario that Nigeria’s election-security architecture must be capable of answering before the next major election.
Under Nigeria’s current electoral technology architecture, BVAS plays a critical role in voter accreditation and result management, while IReV provides public access to electronic copies of polling-unit result sheets. INEC says the system is designed to improve transparency and reduce manipulation during collation.
But every digital system introduces a different category of risk.
COULD THE ATTACK MOVE FROM THE PHYSICAL POLLING UNIT TO THE DIGITAL PIPELINE?
Imagine a hypothetical situation.
Political parties and candidates spend months campaigning, mobilising supporters, studying voting patterns and persuading citizens through manifestos and political messaging.
But instead of attempting to manipulate voters physically on Election Day, a sophisticated adversary decides to attack the technology through which the results are transmitted.
Could such an adversary attempt to disrupt communication between the BVAS and the central result-management infrastructure?
Could an attacker attempt to compromise an application, authentication mechanism, server, database, network connection or software update associated with the transmission process?
Could a denial-of-service attack prevent legitimate result uploads at a critical moment?
Could compromised credentials or malicious software be used to interfere with data before it reaches the public portal?
And, perhaps most importantly:
What happens if the result displayed electronically is inconsistent with the physical result sheet signed and displayed at the polling unit?
These are not questions that should be dismissed simply because the system has not been publicly shown to have suffered such an attack.
They are questions that should be answered through penetration testing, independent cybersecurity audits, red-team exercises, cryptographic verification, system redundancy and publicly verifiable election records.
THE ‘WRONG RESULTS UPLOADING’ SCENARIO
The most extreme scenario is worth examining conceptually.
Suppose malicious code was somehow introduced into an election-result ecosystem and programmed to activate at a particular period during result transmission.
The objective would theoretically be to prevent, delay or interfere with legitimate uploads while causing unauthorised information to appear on the electronic platform.
That sounds like a political thriller.
But cybersecurity professionals routinely conduct precisely this kind of threat modelling: What happens if an authorised account is compromised? What happens if a server is attacked? What happens if communications are disrupted? What happens if software is altered? What happens if data is manipulated between its point of creation and its final destination?
The critical point is that BVAS is not supposed to be the only source of truth.
The physical polling-unit result sheet remains crucial. INEC’s own explanation of the result process describes the EC8A result sheet and electronic upload as components of the broader results-management architecture.
Therefore, a properly designed system should make it extraordinarily difficult for a cyberattack on one component to manufacture an entirely different election outcome.
THE ANSWER MUST BE MULTIPLE LAYERS OF VERIFICATION
Nigeria should therefore consider the principle of “trust, but independently verify.”
Every electronic result should be capable of being reconciled with:
- The physical result sheet completed at the polling unit;
- The number of accredited voters recorded by BVAS;
- The number of votes recorded for each candidate;
- The number of rejected or invalid ballots;
- The result sheet displayed publicly at the polling unit;
- The electronic image uploaded to IReV;
- The original device record and audit trail;
- The time and identity associated with each upload;
- And the subsequent collation figures.
INEC has already acknowledged the importance of strengthening the technology. In its review of the 2023 election, the Commission recommended upgrades to BVAS, better network mapping, greater use of satellite services in poorly connected areas and mock testing of the results-management system before elections.
That is encouraging.
But independent testing is equally important.
A 2023 Yiaga Africa assessment of electronic transmission in the Ekiti and Osun governorship elections specifically recommended penetration tests and mock exercises to assess the robustness, security and capacity of INEC’s servers and devices, with the findings made available to the public.
That recommendation remains highly relevant.
CAN A CYBERATTACK CHANGE AN ELECTION?
In theory, any sufficiently complex digital election infrastructure can become a target for cyberattack.
That does not mean that an attacker can simply sit somewhere and replace Nigeria’s election results.
The architecture contains multiple layers, human processes and physical records. An attack capable of changing national election outcomes would have to overcome, or exploit, multiple controls.
And that is precisely why Nigeria must conduct serious adversarial testing before Election Day, rather than discovering vulnerabilities during or after an election.
The appropriate question is not:
“Can somebody hack IReV?”
It is:
“If somebody tries to compromise the election-result transmission system, what independent mechanisms will detect it, stop it, expose it and enable the genuine result to be reconstructed?”
That is a much more important question.
ELECTRONIC TRANSMISSION SHOULD NOT BECOME A NEW BLACK BOX
Technology was introduced into Nigeria’s electoral process partly to reduce human manipulation, improve transparency and make results easier to verify.
INEC itself describes IReV as a transparency mechanism through which members of the public can view polling-unit result sheets.
Therefore, the public should not merely be told that the system is secure.
The system should be demonstrably secure.
Political parties, accredited observers, cybersecurity specialists and civil-society organisations should be allowed meaningful opportunities to scrutinise the security architecture without exposing sensitive operational information that could itself facilitate attacks.
There should be independent penetration testing.
There should be pre-election stress tests.
There should be red-team exercises designed to simulate hostile actors.
There should be immutable audit logs.
There should be strong authentication and separation of privileges.
There should be independent backups.
And there should be a clear procedure for reconciling electronically transmitted results with the original polling-unit documents whenever there is a discrepancy.
THE REAL DANGER MAY BE THE LOSS OF PUBLIC TRUST
Perhaps the greatest danger is not even a successful cyberattack.
It is the belief that a cyberattack may have occurred when nobody can independently prove whether it did or did not.
An election can be technically accurate and still become politically unstable if citizens do not trust the system producing the results.
That is why transparency must accompany technology.
Nigeria’s experience in 2023 demonstrated that electronic result transmission can itself become a major political and legal issue. Courts and election tribunals subsequently considered questions surrounding BVAS, IReV and electronic transmission, illustrating the importance of clear rules and verifiable procedures.
THE QUESTION FOR 2027
As Nigeria prepares for another major electoral cycle, the country should not wait for political parties to raise allegations after results have been announced.
The questions should be answered before the first ballot is cast.
Can a legitimate BVAS upload be independently authenticated?
Can a malicious upload be detected?
Can an interrupted transmission be recovered without altering the underlying result?
Can the public independently reconcile the electronic result with the physical polling-unit result?
Can INEC prove that the software running on election devices has not been altered?
Can the Commission demonstrate that no central administrator or compromised credential can secretly alter results across the about 176,846 polling-unit in Nigeria?
And if the electronic system fails completely, what independent fallback mechanism guarantees that the election result survives the failure?
These are not questions against electronic voting or electronic transmission.
They are questions for electronic transmission.
Nigeria should embrace technology—but it must never surrender the fundamental principle that every digital result must remain traceable to a real vote cast by a real voter and recorded at a real polling unit.
Because if Nigeria moves from ballot-box manipulation to digital manipulation, it will not have solved electoral rigging.
It will simply have moved the battlefield from the polling station to cyberspace.
The strongest point in your concept is therefore not that such a nationwide attack is known to be planned or currently possible, but that Nigeria should subject the entire election-result technology chain to adversarial testing precisely because sophisticated attackers will look for the weakest link. INEC’s own recent statements show that it recognises result-management as a major vulnerability and has added safeguards to BVAS.


