Zenith Bank Plc has confirmed that hackers gained unauthorised access to a limited set of customer information, including email addresses and phone numbers, in an incident the lender says forms part of a broader global cyberattack targeting organisations across multiple sectors.
The bank disclosed the breach in a notice sent to customers on Tuesday, August 4, 2026, stating that its database had been accessed by attackers. Zenith Bank was quick to reassure customers that no sensitive banking information was compromised, adding that its banking services, digital channels and core systems remain secure and fully operational.
Part of a Wider Pattern in Nigerian Banking
Zenith Bank’s disclosure adds to a growing list of cybersecurity incidents affecting Nigerian financial institutions this year. In March 2026, hackers gained unauthorised access to customer data belonging to Sterling Bank, Providus Bank and other lenders, prompting the federal government to pledge an investigation. No public findings from that probe have been released so far. Separately, reports have also pointed to a breach affecting the website of Guaranty Trust Bank, one of the country’s Tier-1 lenders.
The frequency of these incidents has intensified scrutiny of how Nigerian banks secure customer data. The Central Bank of Nigeria has issued 17 regulatory actions within the past 14 months covering cybersecurity, anti-money laundering and data protection, with six compliance deadlines running between March 2026 and March 2028.
Why “Limited” Data Still Carries Risk
Security analysts have cautioned that even data described as limited, such as email addresses and phone numbers, can carry outsized risk. This category of information is often enough to fuel convincing phishing and social engineering campaigns, particularly when attackers combine it with other details already circulating from earlier breaches.
The recurrence of attacks on Nigerian banks within a single year suggests that financial institutions may be contending with more sophisticated or persistent threat actors than in previous cycles, raising questions about whether existing cybersecurity investments are keeping pace with the risk.
What Customers Should Do
Zenith Bank has not indicated whether affected customers will receive individual notifications beyond the general notice. In the interim, customers are advised to treat unsolicited emails, calls or text messages referencing account details with caution, avoid clicking on unfamiliar links, and verify any request for personal or financial information directly through official Zenith Bank channels rather than responding to inbound contact.
The bank said it remains committed to protecting customer data and will provide updates as its investigation progresses.





