Zenith Bank has officially confirmed that hackers gained unauthorized access to part of its database, exposing limited customer information as part of a broader global cyberattack campaign targeting organizations across multiple industries. The bank, however, moved swiftly to reassure customers that their funds remain safe, emphasizing that its core banking systems, digital channels, and financial services were not compromised.
The disclosure, made in an email to customers on Tuesday, comes amid escalating concerns over cybercrime targeting financial institutions in Nigeria and worldwide. Zenith Bank clarified that the attackers accessed a limited amount of customer information, including email addresses and phone numbers, but found no evidence that account passwords, PINs, One-Time Passwords (OTPs), or funds were exposed.
Bank Activates Cybersecurity Response
Upon detecting the breach, Zenith Bank said it immediately activated its incident response protocols and cybersecurity safeguards. The financial institution disclosed that investigations are ongoing, with security teams working to determine the full scope of the incident and strengthen protections against future threats. The bank reiterated its commitment to safeguarding customer information and ensuring its security infrastructure meets industry standards.
According to the bank, the incident forms part of a coordinated wave of cyberattacks affecting organizations across different sectors globally. Despite the breach, Zenith Bank maintained that all banking services, including mobile and internet banking platforms, ATMs, and other digital channels, remain secure and fully operational.
Customers Warned to Watch for Scammers
Following the cyberattack, Zenith Bank urged customers to remain vigilant against phishing attempts that often follow data breaches. The lender warned customers to ignore suspicious emails, text messages, and phone calls requesting sensitive banking information. It also reminded customers never to disclose passwords, PINs, OTPs, card details, or other security credentials to anyone, regardless of claims that the request comes from the bank.
Cybersecurity experts have long warned that hackers frequently use stolen contact details to launch targeted phishing campaigns aimed at tricking victims into revealing confidential financial information. The bank's warning aligns with this broader concern, as customers are advised to verify all communications claiming to originate from financial institutions.
Cyber Threats Continue to Target Nigerian Banks
The latest incident highlights the growing cybersecurity risks facing Nigeria's banking sector. In August 2024, Guaranty Trust Bank (GTBank) disclosed that cybercriminals attempted to compromise its website domain, though the bank assured customers that no personal or financial data had been affected at that time.
The development also follows warnings from the Central Bank of Nigeria (CBN) about an increase in cyber fraud involving fake emails, online messages, and fraudulent communications falsely claiming to originate from the apex bank. According to Leadership, the regulator said scammers were circulating misleading messages designed to deceive the public into clicking malicious links or divulging sensitive personal information. Some fake communications also contained false claims relating to the CBN's leadership, licensing activities, and policy decisions.
Zenith Reassures Customers
While investigations into the latest cyberattack continue, Zenith Bank has assured customers that their deposits and banking operations remain protected. The bank thanked customers for their continued confidence and reiterated its commitment to protecting customer information while working with relevant experts to address the incident and reinforce its cybersecurity defenses.
The incident serves as another reminder for bank customers to remain cautious online, verify every communication claiming to come from financial institutions, and never share confidential banking credentials with anyone.
Broader Context: CBN Exposes 13,117 Fraud-Linked BVNs
Nigeria's banking sector has intensified its fight against financial fraud, with the number of Bank Verification Numbers (BVNs) linked to fraudulent activities surging to 13,117 in 2025. The latest figures, released by the Central Bank of Nigeria (CBN) in its 2025 Annual Report and Statement of Accounts, show that commercial banks, including Access Bank, Zenith Bank, United Bank for Africa (UBA), and other financial institutions, significantly expanded fraud monitoring during the year.
This data underscores the persistent threat of cybercrime and financial fraud in the Nigerian banking landscape, making the need for robust security measures and customer vigilance more critical than ever.



