2027: BVAS Software Outdated, Can Easily Be Manipulated – Atiku

Presidential candidate of the African Democratic Congress (ADC), Atiku Abubakar, has raised the alarm over the continued use of an outdated operating system on the Bimodal Voter Accreditation System (BVAS), warning that the lapse could expose the 2027 general elections to manipulation.

In a statement issued by his media office in Abuja on Tuesday, Atiku referenced the mock-accreditation failures recorded in Osun State on August 1, alongside a disclosure by the Independent National Electoral Commission’s (INEC) Director of ICT, Dr Lawrence Bayode, who revealed on Arise TV that the BVAS, first deployed in 2021, is still running on Android version 10.

That operating system reached end-of-life in 2023 and no longer receives security patches.

Atiku said running a sensitive election technology platform on an obsolete operating system poses “severe cyber and operational risks,” and questioned why INEC, despite its substantial budget, had failed to update the software ahead of 2027 or test a newer version during recent off-season polls such as the Osun governorship election.

He described the commission’s handling of the matter as suspicious, describing it as “a deliberate attempt to subvert the integrity of the country’s elections.”

The former Vice President warned that the vulnerability could allow “criminal elements or hackers to bypass the BVAS application entirely, gain root access to the device file system, and potentially alter cached voter logs or polling unit result files before they are transmitted.”

Advertisement

He also flagged risks around the transmission of results, noting that because BVAS machines send data over weak public telecommunication networks to the INEC Result Viewing (IReV) portal, outdated cryptographic protections raise the danger of Man-in-the-Middle attacks, through which “sophisticated actors could intercept, block, or manipulate data packets over the air.”

On the device’s biometric functions, Atiku said an outdated framework could end up “reducing the system’s accuracy and resilience against spoofing methods such as fingerprint and photo bypasses.”

He further raised concern that “bugs or memory leaks within legacy system frameworks can cause the app to crash during peak voting hours,” a scenario he linked to the technical glitches and delayed accreditation witnessed in past elections.

Citing the position of cybersecurity experts, Atiku said “running critical national infrastructure on an end-of-life operating system creates a broad attack surface,” and called for an independent, comprehensive audit of BVAS devices, insisting that such a step was “vital to safeguard election integrity.”

The ADC candidate urged INEC to act swiftly to address the vulnerability ahead of the 2027 general elections.

Advertisement

Leave a comment

Advertisement