A new court filing in the United States has alleged that the Nigerian government pays $750,000 monthly to DCI Group AZ, LLC, an affiliate associated with American public affairs firm DCI Group.
The allegation was made by American transparency activist Aaron Greenspan in a request asking a federal court to take judicial notice of public records in his ongoing lawsuit seeking US government documents relating to President Bola Tinubu and an alleged federal investigation dating back to the early 1990s involving Tinubu and Abiodun Agbele.
Greenspan submitted the request on October 8, 2026, as part of his continuing effort to obtain permission to pursue limited discovery involving Tinubu, who joined the case in October 2023.
According to the filing, an online account managed by the DCI affiliate published a post criticising Greenspan on August 5, 2026.
The document stated: “DCI Group AZ, LLC is paid $750,000 per month by Intervenor’s government, and on August 5, 2026 an account it manages published a post attacking Plaintiff in writing.”
However, the filing does not establish that the Nigerian government financed or directed the alleged attack. It also does not identify the individuals responsible for the reported cyberattacks on Greenspan’s website, PlainSite.
Greenspan cited allegations by US federal prosecutors that a Washington-based public affairs and lobbying firm had engaged Israeli contractors whose operators allegedly hacked electronic accounts belonging to individuals connected to a project undertaken for the firm’s client.
The information obtained from the alleged hacking was subsequently supplied to the lobbying firm, according to the account referenced in the filing.
Greenspan said documents submitted by the US Department of Justice, statements from a defendant’s lawyer in the United Kingdom and media reports identified the firm as DCI Group.
His latest application seeks judicial recognition of the existence and contents of the public records attached to it. A separate proposed order accompanying the request contains language that would grant the application, but the copy has neither a date nor a judge’s signature.
Consequently, the documents provided do not establish that the court has approved the request. The application is also separate from Greenspan’s principal bid to conduct limited discovery in the case.
Tinubu joined the lawsuit in October 2023, citing privacy concerns involving confidential tax records and federal law-enforcement documents.
In April 2025, US District Judge Beryl A. Howell ruled that the Federal Bureau of Investigation and the Drug Enforcement Administration could not maintain blanket refusals to confirm or deny whether records responsive to Greenspan’s requests existed.
The judge, however, upheld the Central Intelligence Agency’s refusal to confirm or deny the existence of such records.
The ruling addressed the agencies’ responses to Greenspan’s information requests. It did not establish criminal wrongdoing by Tinubu or order the release of all the records being sought.
The latest development follows Greenspan’s September request for permission to ask Tinubu four questions concerning alleged denial-of-service attacks on PlainSite.
In a reply filed on September 28 in Greenspan v. Executive Office for U.S. Attorneys, Case No. 1:23-cv-01816-BAH, the activist argued that Tinubu, who intervened in the lawsuit, had not denied that he, his government or anyone acting on his behalf, including DCI Group AZ, was involved in the attacks.
“If that is so, the four requests for admission can be answered in minutes,” Greenspan wrote.
Nevertheless, the filings do not establish that Tinubu or DCI Group AZ carried out the attacks, and no evidence presented in the documents conclusively identifies those responsible.
Greenspan also challenged Tinubu’s opposition to his discovery request, which argued that “there is no independent verification” of the alleged cyberattacks.
In response, Greenspan referred to a technical mitigation report generated on May 29, 2025, by PlainSite’s internet service provider through its mitigation system.
According to the report cited by Greenspan, traffic directed at PlainSite’s protected address reached 941.9 megabits per second and 1.8 million packets per second. About half of the traffic was classified as hostile and dropped, while 110,700 source hosts were blocked.
Greenspan argued that Tinubu’s opposition neither addressed the report nor challenged its authenticity or provided contrary technical evidence.
He further told the court that the attacks resumed after he filed a motion on September 9.
In a supplemental declaration made under penalty of perjury, Greenspan said the number of individual addresses blocked by PlainSite’s firewall had declined to approximately 69,000 by September 7, following the end of the intense attacks in late August.
He alleged that the figure began rising sharply around September 18, reached about 500,000 on September 23 and stood at 390,957 on the morning of September 24.
Greenspan also highlighted the timing, noting that September 18 was the original deadline for the government to respond to his cross-motion for summary judgment before an extension moved the deadline to September 23.
That same day, Tinubu’s legal team and the Justice Department filed their respective submissions, according to the declaration.
However, the timing of the reported increase does not independently establish a connection between the court proceedings and the cyberattacks.
Greenspan maintained that the September incidents were less disruptive than those recorded in August. He said the earlier attacks pushed PlainSite’s server load average above 300, while the later incidents did not overwhelm the system because its adaptive firewall identified and blocked attacking networks.
According to his declaration, the server’s load average remained below 25 during the September attacks.
He also reported that the firewall dropped more than 200,000 packets per minute on September 23, while total web traffic exceeded 480,000 packets per minute.
Greenspan explained that some of the largest traffic spikes recorded on September 23 and 24 initially appeared under the category for ordinary visitor traffic because requests from attacking sources were counted in that category before the firewall identified and blocked them.
The court filing forms part of Greenspan’s continuing legal effort to obtain government records and secure permission to pursue limited discovery. The allegations concerning the monthly payment and the cyberattacks remain unproven by the documents described.
















