Zenith Bank has disclosed that hackers breached its database, gaining access to limited customer information in a cyberattack that targeted the financial institution.
Gatekeepers News reports that the bank confirmed the incident in an email sent to customers on Tuesday, stating that the breach exposed only restricted customer data, including email addresses and phone numbers.
According to the bank, the incident was part of a wider global cyber campaign affecting organisations across multiple sectors.
“The attackers accessed limited customer information, including email addresses and phone numbers, during a cyberattack that forms part of a broader global attack on organisations across different sectors,” the bank said.
Zenith Bank stressed that the breach did not compromise its banking services or digital platforms, assuring customers that both remain secure and fully operational.
The lender added that it immediately activated its incident response protocols and cybersecurity measures after detecting the breach and has launched an investigation into the attack.
“As a precaution, we encourage our customers to remain vigilant against phishing emails, text messages, or phone calls, and to never disclose their password, PIN, One-Time Password (OTP), or other security credentials to anyone,” the bank advised.
The bank reaffirmed its commitment to safeguarding customers’ information and thanked customers for their continued trust, noting that investigations into the cyberattack are still ongoing.
The incident follows a similar cybersecurity scare involving Guaranty Trust Bank (GTBank) in August 2024. At the time, the bank disclosed attempts to compromise its website domain but said customers’ data remained unaffected.
The latest breach also comes months after the Central Bank of Nigeria (CBN) warned Nigerians about rising cyber fraud attempts aimed at gaining access to personal and financial information.
The apex bank had cautioned that cybercriminals were circulating fraudulent emails and messages falsely claiming to originate from the CBN. It said the misleading communications were designed to deceive recipients into clicking suspicious links while spreading false claims about the bank’s leadership, licensing activities and policy decisions in an effort to steal sensitive information.
