Zenith Bank has issued a formal alert to its customers following a cyber incident that exposed certain contact details. The bank, one of Nigeria's largest financial institutions, confirmed that the breach affected a limited set of customer data, primarily phone numbers and email addresses. In a statement released on Tuesday, Zenith Bank urged customers to remain vigilant against potential phishing attempts and fraudulent communications that may exploit the leaked information.
What Happened: The Breach and Its Scope
The cyber incident, which came to light earlier this week, involved unauthorized access to a database containing customer contact information. According to the bank, the exposed data does not include sensitive financial details such as account numbers, passwords, or transaction history. However, the bank acknowledged that the compromise could still pose risks, as cybercriminals often use such information to craft convincing social engineering attacks.
In its official communication, Zenith Bank stated: "We are aware of a cyber incident that has exposed some of our customers' contact details. Our technical team, in collaboration with cybersecurity experts, is working diligently to contain the situation and enhance our security protocols." The bank did not disclose the exact number of affected customers, but industry analysts estimate that the breach could impact thousands of account holders, given the bank's extensive customer base.
Immediate Response and Security Measures
Zenith Bank has activated its incident response plan, which includes notifying relevant regulatory authorities and law enforcement agencies. The bank has also implemented additional security layers to prevent further unauthorized access. Customers are advised to change their online banking passwords and enable two-factor authentication where available.
"We assure our customers that their funds remain safe, and our core banking systems were not compromised," the statement added. The bank emphasized that it is conducting a thorough forensic investigation to determine the root cause and extent of the breach. This incident underscores the growing threat of cyberattacks in Nigeria's financial sector, which has seen a surge in phishing and ransomware cases over the past year.
What Customers Should Do
Zenith Bank has provided clear guidance for customers to protect themselves. The bank advises customers to:
- Ignore unsolicited messages or calls requesting personal or financial information.
- Never click on links or download attachments from unknown sources.
- Regularly monitor their account statements for any unauthorized transactions.
- Report any suspicious activity immediately to the bank's official customer service channels.
The bank reiterated that it will never ask customers for their PIN, password, or one-time passwords via phone calls, SMS, or email. Customers are encouraged to verify any communication claiming to be from Zenith Bank by contacting the bank directly through verified channels.
Broader Implications for the Banking Sector
This incident highlights the increasing sophistication of cybercriminals targeting financial institutions in Nigeria. According to the Nigeria Inter-Bank Settlement System (NIBSS), fraud attempts in the banking sector rose by 15% in the first half of 2026 compared to the previous year. Cybersecurity experts have called for enhanced data protection measures and stricter regulatory enforcement to safeguard customer information.
Zenith Bank, which serves over 30 million customers across Nigeria and other African countries, has a reputation for robust digital banking services. However, this breach serves as a reminder that even the most secure institutions are vulnerable. The bank's swift response and transparent communication are commendable, but the long-term impact on customer trust remains to be seen.
As investigations continue, Zenith Bank has promised to provide regular updates to customers and stakeholders. The bank's management expressed regret over the incident and reaffirmed its commitment to protecting customer data. "We deeply regret this incident and apologize for any inconvenience caused. Our priority is the security and trust of our customers," the statement concluded.



