Nigerian media recently reported that a researcher had uncovered dozens of casino and gambling articles quietly published on the domain of Nigeria’s Independent National Electoral Commission (INEC).
What made the incident particularly concerning was how quietly it appeared to have been placed on a legitimate government domain for years, some of these articles dated as far back as December 2025. The pages were reportedly published through what appeared to be a legitimate author account and remained undetected on one of the country’s most sensitive public websites, an institution whose digital platforms will play an important role in public communication and trust ahead of the 2027 general elections.
This incident reflects a well-known attack pattern often described as SEO poisoning or parasite hosting. In such cases, attackers, or sometimes insiders operating for financial gain, exploit the authority of a trusted website to host spam, gambling, pharmaceutical or scam-related content. Because government websites typically carry strong domain authority and public trust, they can be particularly attractive targets.
If you’re familiar with Nigerian politics, you see how concerning this is, not just for Nigerian institutions, but for state agency websites all over Africa. The INEC case therefore raises a question every public institution should be asking: Could this happen to our website, and would we even notice if it did?
I put together this article focused on how to better secure public institutions’ websites. It's simple really, state agencies need layered controls covering access, publishing, monitoring, infrastructure, incident response and governance. You see how much of it is incident on the personnel managing the website.
1. CMS as critical infrastructure
Following 7 years of developing websites for public institutions, we noticed that most government websites are often managed by communications teams separately from the organisation’s broader IT and cybersecurity functions. That separation can create gaps that attackers exploit.
A public website should be governed as part of the institution’s critical digital infrastructure, especially where its compromise could damage public trust.
Agencies should maintain a current inventory of every CMS component, including plugins, themes, integrations and third-party scripts, with clear ownership assigned to each. They should also classify the website according to the potential impact of a compromise, including reputational and public-trust risks, rather than considering only the sensitivity of the data it stores.
It's easy to think a government website must contain voter records, financial information or confidential databases before it’s considered a serious security concern, but that is not true. A compromised public platform can still undermine confidence in the institution behind it.
2. Publishing access and vendor accounts
One of the most important lessons from the INEC incident is the danger of stale or poorly managed access.
Every CMS user, administrator, API account, contractor and technology vendor with publishing privileges should be reviewed regularly. Agencies should know exactly who can publish content, what level of access they have and why that access is still required.
Vendor and contractor accounts should be disabled immediately when contracts end or responsibilities change. Content staff should receive only the permissions they need, rather than broad administrative privileges.
Multi-factor authentication should be mandatory for privileged and publishing accounts, particularly administrator and vendor accounts. Passwords, API keys and other credentials should also be rotated periodically and whenever personnel or vendors change.
The principle should be that no one should retain access merely because they might need it again someday.
3. Monitor content integrity
Typical website monitoring programs are designed to simply ensure the website is online. But that’s not enough. The INEC incident illustrates a different problem. A website can be fully operational while its content is being manipulated.
Government agencies therefore need content-integrity monitoring alongside uptime monitoring.
Automated systems can flag unexpected new pages, unusual publishing activity, unexplained changes to categories, sudden increases in the number of posts or content containing terms associated with gambling, spam and other malicious campaigns.
Agencies should also monitor their XML sitemaps and search-engine indexes to identify pages that have been published without authorisation.
Regular manual checks remain useful as well. A designated staff member outside the immediate web team should periodically review recently published pages and sitemap entries for unusual content.
The objective is to detect content drift before search engines, journalists or the public do.
4. Harden the technical environment
CMS hijacking can result from outdated software, vulnerable plugins, weak credentials or insecure hosting configurations.
Government agencies should maintain strict patching schedules for CMS cores, themes, plugins and other software components. Unused extensions should be removed rather than left installed.
At EnspireFX, we use web application firewall to add an additional layer of protection against malicious traffic and known attack patterns.
And where appropriate, agencies should restrict access to administrative interfaces through measures such as VPNs, IP allowlisting and other network controls. They should also disable unnecessary administrative features that could be abused to modify website files or inject malicious code.
Backups are equally important. Organisations should maintain secure, versioned and preferably immutable backups that allow compromised systems to be restored quickly and compared against known-good versions.
Security should be built into the hosting environment rather than treated as something added after a compromise.
5. Establish a clear vulnerability disclosure process
Another important issue raised by the INEC reporting is how organisations respond when external researchers identify security weaknesses.
A researcher who responsibly reports a vulnerability should know where to send the information, who receives it and what happens next.
Government agencies should publish a clear vulnerability disclosure policy and maintain a monitored reporting channel. Reports should be acknowledged within a defined period, such as 48 to 72 hours, with clear internal responsibility for triage and escalation.
The objective is not simply to thank researchers. It is to ensure that credible warnings reach people who can assess and fix the problem.
Agencies can also consider structured security research programmes, including bug bounty or responsible disclosure initiatives where appropriate.
A vulnerability that is reported and ignored today can become a major incident tomorrow.
6. Conduct independent and recurring security audits
A major website rebuild or technical migration should not be allowed to become a substitute for understanding what went wrong.
State agencies should conduct independent security assessments regularly, particularly before major national events such as elections.
These assessments should cover more than the external network perimeter. They should examine CMS accounts, publishing permissions, administrator access, third-party integrations, plugins, themes, hosting configurations and editorial workflows.
Where possible, agencies should publish a summary of significant findings and remediation measures. Transparency can help demonstrate that identified weaknesses are being addressed rather than simply hidden.
Major infrastructure changes should also be documented clearly, including what changed, why it changed and what security improvements were introduced.
7. Prepare the public communication response
Cybersecurity incidents are also communication crises. When a government website is compromised, silence or confusing messaging can deepen public concern, particularly when the affected institution already operates in an environment where public trust is critical.
Agencies should prepare communication templates for incidents involving unauthorised content, website defacement, account compromise and potential data exposure.
Once an incident is confirmed, the institution should provide timely and factual updates explaining what happened, what systems are affected, what actions are being taken and whether independent verification is underway.
The technical and communications teams should work from the same verified information so that public statements are accurate and consistent.
The bigger picture
The Nigerian EC website incident is a reminder that government website security is much more than firewalls, passwords and keeping servers online, and more about site access, content integrity, vendor management, continuous monitoring, vulnerability reporting and institutional accountability.
For public institutions preparing for high-stakes events such as national elections, a compromised website is more than a technical embarrassment. It can become a credibility problem.
A malicious article on an election commission website may not alter a single vote, but it can raise uncomfortable questions about who has access to the institution’s digital systems and how effectively those systems are being monitored.
The strongest defence is therefore not necessarily the most expensive technology. It is disciplined digital governance.
Agencies need to know who can access their CMS, what they can do, what is being published, whether anything unusual is happening and how quickly they can respond when something goes wrong.
The institutions that take those questions seriously are far more likely to detect a compromise early, contain it quickly and preserve the public trust on which their digital platforms ultimately depend.
About The Author
Rev. Dennis Gyamfi Bediako is the CEO of EnspireFX Websites Ltd (enspirefx.com), a corporate web design company based in Accra, Ghana. Contact: 0550919202; Email: [email protected]



UN backs effort to drop Mercator map and show size of Africa more accurately
CUTS Raises Cartel Concerns Over Cement Manufacturers’ Uniform GH¢12 Surcharge
I have not been invited by OSP over fake GH¢70,000 memo — Patricia Appiagyei
Vetting committee has never taken bribes or gifts from nominees — Bernard Ahiafo...
Chief Justice Baffoe-Bonnie clarifies controversial remarks
Dunkwa-Ayanfuri road construction to commence in 2027 – Finance Minister
PRESEC, St. Augustine’s College and Accra Academy set for NSMQ grand finale on S...
Appiagyei denies alleged GH¢70,000 vetting payment in memo
Lawyer challenges GRA’s power to grant passenger baggage tax exemptions
Agbogbloshie waste heap is as high as 10-storey building – Mahama Ayariga