US Court Filing Alleges Tinubu Govt Pays US Firm $750,000 Monthly

US Court Filing Alleges Tinubu Govt Pays US Firm $750,000 Monthly

A fresh court filing in the United States (US) has alleged that the Nigerian government pays $750,000 monthly to DCI Group AZ, LLC, an affiliate associated with American public affairs firm DCI Group.

The allegation was contained in a document submitted by American transparency activist Aaron Greenspan in his ongoing lawsuit seeking US government records linked to President Bola Tinubu and an alleged federal investigation in the early 1990s involving Tinubu and Abiodun Agbele.

Greenspan filed the request for judicial notice on October 8, 2026, as part of his efforts to persuade the court to allow limited discovery involving Tinubu, who joined the case in October 2023.

The filing also alleges that an online account managed by the DCI affiliate published a post attacking Greenspan on August 5, 2026.

However, the document does not establish that the Nigerian government directed or funded the alleged attack, or that the monthly payment was connected to it. It also does not establish who was responsible for the attacks on Greenspan’s website.

In the filing, Greenspan referred to allegations by federal prosecutors that a Washington public affairs and lobbying firm had engaged Israeli contractors whose operators allegedly hacked electronic accounts belonging to targets connected to a project for the firm’s client.

According to the filing, the hacked information was subsequently provided to the lobbying firm.

Greenspan cited documents filed by the US Department of Justice, statements by a defendant’s lawyer in the United Kingdom and reports by two news organizations, which he said identified the firm as DCI Group.

The filing stated: “DCI Group AZ, LLC is paid $750,000 per month by Intervenor’s government, and on August 5, 2026 an account it manages published a post attacking Plaintiff in writing.”

The request asks the court to take judicial notice of the existence and contents of public records attached to the filing.

A separate one-page document submitted alongside it is marked as a proposed order. Although the document contains wording that would grant the request, the copy provided has neither a date nor a judge’s signature. It therefore does not establish that the court approved the request.

The application for judicial notice is also separate from Greenspan’s main request for permission to pursue limited discovery.

Tinubu joined the lawsuit in October 2023, citing privacy concerns over confidential tax records and federal law-enforcement documents.

In April 2025, US District Judge Beryl A. Howell ruled that the Federal Bureau of Investigation and the Drug Enforcement Administration could not maintain blanket refusals to confirm or deny whether records responsive to Greenspan’s requests existed.

However, the judge upheld the Central Intelligence Agency’s refusal to confirm or deny the existence of such records.

The ruling concerned the agencies’ responses to Greenspan’s information requests. It did not establish criminal wrongdoing by Tinubu or direct the release of all the records sought by the plaintiff.

The latest filing is part of Greenspan’s continuing effort to obtain permission to pursue limited discovery in the case.

In September, it was reported that Greenspan had asked a federal court in Washington for permission to put four questions to Tinubu over a series of denial-of-service attacks on his website, PlainSite.

In a reply filed on September 28 in Greenspan v. Executive Office for U.S. Attorneys, Case No. 1:23-cv-01816-BAH, Greenspan argued that Tinubu, who had intervened in the lawsuit, had not denied that he, his government or anyone acting on his behalf, including DCI Group AZ, was involved in the attacks.

“If that is so, the four requests for admission can be answered in minutes,” Greenspan wrote.

The filings, however, do not establish that Tinubu or DCI Group carried out the attacks. They also contain no evidence identifying those responsible.

Greenspan Disputes Tinubu’s Position On Attack Evidence

Tinubu’s opposition to Greenspan’s discovery request, filed as ECF No. 109, argued that “there is no independent verification” of the alleged attacks.

Greenspan rejected the argument, pointing to a technical mitigation report attached to an earlier motion. The report was generated on May 29, 2025, by PlainSite’s internet service provider through its own mitigation system.

According to Greenspan, the report recorded traffic reaching 941.9 megabits per second and 1.8 million packets per second at PlainSite’s protected address.

About half of the traffic was identified and dropped as hostile, while 110,700 source hosts were blocked.

Greenspan argued that Tinubu’s opposition did not address the report, challenge its authenticity or present contrary technical evidence.

He also told the court that attacks on the website resumed after he filed his motion on September 9.

In a supplemental declaration made under penalty of perjury, Greenspan said the number of individual addresses blocked by PlainSite’s firewall had fallen to about 69,000 by September 7, after the intense attacks stopped in late August.

He said the number began rising sharply around September 18, reached approximately 500,000 on September 23 and stood at 390,957 on the morning of September 24.

Greenspan also drew attention to the timing of the increase. September 18 was the original deadline for the government to reply to his cross-motion for summary judgment before the deadline was extended to September 23.

That was the same day Tinubu’s legal team and the Justice Department filed their respective submissions.

However, the timing cited in the declaration does not, on its own, establish a link between the court filings and the website attacks.

Greenspan’s declaration indicated that the September attacks were less disruptive than those recorded in August.

He said the August attacks pushed the server’s load average above 300, while the September attacks did not overwhelm the server because PlainSite’s adaptive firewall automatically identified and blocked attacking networks.

According to him, the server’s load average remained below 25 during the later attacks.

Greenspan also reported that the firewall dropped more than 200,000 packets per minute on September 23, while total web traffic exceeded 480,000 packets per minute.

He explained that some of the largest traffic spikes recorded on September 23 and 24 appeared in the category classified by the firewall as ordinary visitor traffic.

According to Greenspan, this happened because traffic from attacking sources was initially counted in that category before the firewall identified and blocked those sources.

Recommended For You

About the Author: Gists9ja

Leave a Reply

Your email address will not be published. Required fields are marked *


Notice: ob_end_flush(): Failed to send buffer of zlib output compression (1) in /home/gistsjac/public_html/wp-includes/functions.php on line 5581

Notice: ob_end_flush(): Failed to send buffer of zlib output compression (1) in /home/gistsjac/public_html/wp-includes/functions.php on line 5581