News

2027: Atiku raises alarm over BVAS security

Former Vice President and presidential candidate of the African Democratic Congress (ADC), Atiku Abubakar, has raised concerns about what he describes as the “dangerous exposure” of Nigeria’s election technology.

This follows the failure of mock accreditation in Osun State on August 1, 2026, and recent revelations by Dr. Lawrence Bayode, the Director of ICT at the Independent National Electoral Commission (INEC).

During an appearance on Arise TV on Monday, Dr. Bayode disclosed that the Bimodal Voter Accreditation System (BVAS), introduced in 2021, is still operating on Android 10.

Atiku pointed out that while the INEC official did not mention it, Android 10 reached its end of life in 2023 and no longer receives security updates or patches, raising significant security concerns.

“Running a critical election platform like BVAS on an outdated operating system poses severe cyber and operational risks to our democracy,” Atiku said in a statement issued by his Media Office.

He questioned why INEC, “with its humongous budget,” has not updated the BVAS software ahead of the 2027 general elections, or at least before upcoming off-season elections like the Osun governorship poll where an updated version could have been test-run.

According to him, the Commission’s nonchalant handling of the issue is “suspicious and a deliberate attempt to subvert the integrity of the country’s elections.”

Atiku warned that the vulnerability could allow hackers to bypass the BVAS application entirely, gain root access to device files, and potentially alter cached voter logs or polling unit result files before transmission.

He further explained that because BVAS transmits polling unit results over weak public telecom networks to the INEC Result Viewing portal, IReV, “outdated cryptographic foundations elevate the risk of Man-in-the-Middle attacks, where sophisticated actors could intercept, block, or manipulate data packets.”

The former Vice President also flagged risks to biometric integrity.
“Because BVAS handles both fingerprint and facial recognition, an outdated biometric framework reduces the system’s accuracy and resilience against spoofing methods such as fingerprint and photo bypasses,” he said.

He added that “bugs or memory leaks within legacy system frameworks can cause the app to crash during peak voting hours — leading to technical glitches and delayed accreditations, as we have witnessed in the past.”

Citing cybersecurity experts, Atiku said, “running critical national infrastructure on an end-of-life operating system creates a broad attack surface.”

He therefore called for “an independent, comprehensive code and hardware audit of all BVAS devices to safeguard election integrity ahead of 2027.”