Zenith Bank has confirmed that hackers breached its database and accessed limited customer information, including email addresses and phone numbers, in a cyberattack that forms part of a broader global wave of attacks targeting organisations across multiple sectors.
The bank disclosed the incident in an email sent to customers on Tuesday, assuring them that the breach did not compromise its core banking systems or digital banking platforms.
According to the bank, only limited customer information was accessed during the attack, while banking services and digital channels remain secure and fully operational.
According to the Cable ,Zenith Bank said it immediately activated its incident response protocols and other cybersecurity measures upon discovering the breach and has launched a full investigation into the incident.
The bank also urged customers to remain alert to potential phishing attempts, warning them against responding to suspicious emails, text messages, or phone calls requesting sensitive banking information.
“As a precaution, we encourage our customers to remain vigilant against phishing emails, text messages, or phone calls, and to never disclose their password, PIN, One-Time Password (OTP), or other security credentials to anyone,” the bank said.
Reaffirming its commitment to safeguarding customer information, Zenith Bank thanked customers for their continued trust and assured them that investigations into the cyberattack are ongoing.
The incident is the latest in a series of cyber threats targeting Nigeria’s banking sector. In August 2024, Guaranty Trust Bank (GTBank) disclosed an attempted compromise of its website domain but stated that no customer data was affected.
The development also follows an earlier warning by the Central Bank of Nigeria (CBN), which alerted the public to cybercriminals circulating fraudulent emails and online messages falsely claiming to originate from the apex bank.
According to the CBN, the fake communications were designed to deceive members of the public into clicking malicious links or divulging personal information. The regulator noted that the messages often contained false claims relating to the bank’s leadership, licensing activities, and policy decisions in an attempt to mislead recipients.
Cybersecurity experts have consistently advised bank customers to verify the authenticity of communications from financial institutions and avoid sharing confidential banking credentials with anyone, regardless of the source of the request.