Cyberattack hits Zenith bank as customer details are compromised
Zenith Bank has confirmed that hackers gained access to some customers’ contact information during a cyberattack, including email addresses and telephone numbers. The bank said its banking services and digital channels remain secure, but customers should watch carefully for suspicious calls, emails and text messages that may attempt to obtain passwords, PINs or one-time passcodes.
The incident was confirmed in an email sent to customers on Tuesday, 4 August 2026. Zenith Bank described it as part of a wider global attack affecting organisations across several sectors.
The bank did not disclose how many customers were affected or identify the group responsible for the attack. It also did not say that account balances, passwords, PINs or transaction records had been stolen.
Customers should therefore avoid concluding that money has been removed from their accounts. However, they should take the warning seriously because stolen email addresses and telephone numbers can be used by fraudsters to make convincing contact with account holders.
Zenith Bank says digital services remain secure
According to the bank, the hackers accessed limited customer information, “including email addresses and phone numbers”.
Zenith said its banking operations, mobile applications and other digital channels remained secure and fully operational after the incident.
The bank said it activated its incident-response procedures and other cybersecurity measures immediately after discovering the breach. An investigation is continuing to determine the full scale of the attack and how access was gained.
An incident-response procedure is the process an organisation follows after discovering a security breach. It may involve blocking unauthorised access, securing affected systems, assessing what information was exposed and notifying people who may be at risk.
The bank has not suggested that customers must close their accounts or stop using its digital services. It has instead urged them to remain alert to possible fraud attempts.
Customers warned about phishing messages
Zenith Bank advised customers not to disclose their passwords, personal identification numbers, one-time passwords or other security details to anyone.
A one-time password, commonly called an OTP, is a temporary security code sent to a customer to approve a payment, transfer or login. Bank employees should not ask customers to disclose this code over the telephone, through social media or by text message.
Phishing is a form of fraud in which criminals pretend to represent a trusted organisation. They may send messages containing false warnings about an account, offer fake refunds or ask the recipient to click a link to prevent an alleged suspension.
The exposure of contact details could make such messages appear more convincing. A fraudster may know the customer’s bank, telephone number or email address, but that does not mean the person is a genuine bank employee.
Customers should open their banking application directly rather than using links sent through unsolicited messages. They should also contact Zenith Bank through verified channels if they receive an unexpected request concerning their account.
As an additional precaution, customers should review recent transactions, activate debit and credit alerts and use a strong password that is not shared with other online accounts. Anyone who notices an unfamiliar transaction should report it to the bank immediately.
Previous cyber threats targeted Nigerian banks
The incident is not the first cybersecurity concern involving a major Nigerian financial institution.
In August 2024, Guaranty Trust Bank reported attempts to compromise its website domain. The bank said at the time that customers’ information had not been affected.
The Central Bank of Nigeria has also warned about fraudulent emails and messages designed to gain access to Nigerians’ personal and financial information. Such communications often direct recipients to suspicious websites or make false claims about banking policies and account restrictions.
New Daily Prime previously reported that the CBN introduced multi-factor authentication for some foreign-card transactions to reduce fraud risks. Multi-factor authentication requires a customer to provide more than one form of verification before a transaction can proceed.
The wider risk is shown by a separate international email-fraud case in which more than 1,000 victims across 19 countries reportedly lost about $215 million. The operation involved criminals gaining unauthorised access to email accounts and sending payment instructions that appeared genuine.
What data-protection rules mean for customers
Nigeria’s Data Protection Act requires organisations handling personal information to protect it from unauthorised access, loss and other forms of data breach.
The Nigeria Data Protection Commission says individuals have rights that include being informed about the use of their information, requesting access or correction and reporting suspected privacy violations to the regulator.
The existence of the cyberattack does not, by itself, prove that Zenith Bank breached the law. Regulators would need to consider how the attack happened, what safeguards were in place, how quickly the bank responded and whether affected customers received adequate information.
Customers who believe their information has been misused should first report the matter to the bank. They can also submit a privacy complaint to the Nigeria Data Protection Commission, which provides a breach-reporting service.
Related news
Zenith Bank says the information exposed was limited to contact details and that its banking platforms remain secure. Customers should not panic, but they should be alert to callers or messages asking for passwords, PINs, OTPs or payments. Anyone who notices suspicious activity should contact the bank through its official channels and report unauthorised transactions without delay.
