NewsMacro12 of 16 Nigerian Government Websites Found Hosting Gambling Content Remain Live, Technext Findings Show

12 of 16 Nigerian Government Websites Found Hosting Gambling Content Remain Live, Technext Findings Show

Author: TechNext24·

Key Takeaways

  • Technext identified gambling or betting content on the websites of 16 Nigerian federal ministries and agencies, with 12 still actively compromised at the time of publication.
  • Four agencies — the Ministry of Interior, Nigeria Immigration Service, NAMA, and NNRA — appeared to have remediated the issue when re-checked five hours before publication.
  • The compromised content appeared to stem from at least six separate operations, based on the Indonesian, Vietnamese, Portuguese, Thai, Polish, and Spanish languages found.
  • Security researchers said recurring compromises like NAERLS's indicate the original entry points remained open and reflect neglect of government websites as continuously managed infrastructure.
  • Technext contacted all 16 affected agencies for comment, but only NNRA responded, requesting a screenshot, while none of Nigeria's 22 registered political parties showed similar compromise.
12 of 16 Nigerian Government Websites Found Hosting Gambling Content Remain Live, Technext Findings Show

Gambling and betting content has been discovered on the websites of 16 Nigerian federal ministries and agencies, and 12 of them were still carrying active pages as of publication, according to checks by Technext.

The findings build on Technext's earlier report about casino pages discovered on inecnigeria.org, which itself followed a July dossier by Techpoint Africa documenting an Indonesia-linked gambling operation spanning 16 African countries.

Technext's own verification, conducted using only publicly available search methods, shows the problem runs considerably deeper within Nigeria's own government infrastructure, raising questions not only about cleanup but about how public websites are maintained over time.

The 16 agencies hosting gambling content

The affected bodies span election-adjacent institutions, financial and IT regulators, a nuclear safety authority, a university, and a judicial oversight organization. They include the Nigeria Deposit Insurance Corporation (NDIC), the National Information Technology Development Agency (NITDA), the Nigeria Immigration Service, and the Federal Ministries of Education and Interior.

Also affected are the National Agricultural Extension, Research and Liaison Services (NAERLS), the Nigerian College of Aviation Technology, the Nigerian Airspace Management Agency (NAMA), the Oil and Gas Free Zones Authority, the Small and Medium Enterprise Development Agency of Nigeria (SMEDAN), the National Open University of Nigeria, the National Judicial Council (NJC), the National Library of Nigeria, the Nigerian Nuclear Regulatory Authority (NNRA), the Federal Fire Service, and the Nigerian Electricity Management Services Agency (NEMSA).

The content varied by agency and, based on language alone, appeared to originate from at least six separate operations: Indonesian, Vietnamese, Portuguese, Thai, Polish, and Spanish. NAERLS was previously named in Techpoint's July dossier and taken down within hours after a direct report to the Minister of Communications, Innovation and Digital Economy. It was found compromised again in August, and the same pattern repeated in this latest check.

One case stood apart. A compromised page on NAMA's website did not lead to gambling content at all; it auto-redirected to a WhatsApp group recruiting members into what presented as a United States stock-trading signals scheme — a different fraud type entirely, now apparently taken down.

What has been fixed, and what hasn't

Technext re-checked all 16 agencies five hours before publication. Four appear to have remediated the issue: the Ministry of Interior, the Nigeria Immigration Service (whose link now redirects to a legitimate appointment page), NAMA, and NNRA, whose links now redirect to a map or return an error.

The remaining 12 are still live, in some cases more extensively than when first reported. The National Open University's website carries more than 50 active gambling links. NEMSA has 40, though several originally flagged pages now redirect to legitimate agency content, including its contractor directories and security unit page.

The National Judicial Council has 19 active links. One subdomain, pay.njc.gov.ng, now returns a browser certificate warning, and at least one compromised link redirects entirely off the .gov.ng domain to a Chilean retail website now serving casino content.

The Federal Fire Service's compromised pages include an article dated 4 September — days after Technext's checks began — indicating the content is still being actively published rather than sitting untouched.

Why this isn't just about casino ads

Martin Uwakwe, the researcher who first documented the INEC compromise on X, said the pattern points to government websites being "treated as one-time communications projects rather than continuously managed public infrastructure." He noted that his comments on the wider list were based on Technext's account rather than his own independent verification of each site, and cautioned against assuming that a gambling page proves deeper systems, such as election databases, have been compromised without forensic evidence.

Chris Nwobi, founder of Zend Cybersecurity Threat Labs, who first identified the wider African campaign in Techpoint's July report, put it more bluntly: gambling content reappearing after clean-up is "the whole story, not the casino ads, the neglect."

Uwakwe recommended that agencies preserve evidence before deleting compromised pages, rotate all administrator and vendor credentials, and separate public-facing websites from any systems handling sensitive data. He said repeat compromises, such as NAERLS's, usually mean the visible content was removed while the original point of entry stayed open.

Agencies respond to Technext's request for comment

Technext contacted all 16 affected agencies for comment, with a deadline of 5pm on Monday, 7 September. None responded by time of publication, except NNRA, which called to request a screenshot of the finding but did not respond further afterwards.

Technext also checked all 22 political parties registered with the Independent National Electoral Commission ahead of the 2027 elections using the same methods. None showed evidence of similar compromise.

A data visualisation version of the story is available here.