Zenith Bank has confirmed that a cyber breach involving customer information occurred after unauthorised actors gained access to limited customer data, including email addresses and phone numbers.
The disclosure was made in an email sent to customers on August 4, 2026, and obtained by TechMedia Africa.
While the bank said the affected information was limited to customer contact details, the incident adds to growing concerns about cyber security in Nigeria’s banking sector, where financial institutions are increasingly becoming targets of sophisticated digital attacks.
Zenith said its banking services and digital channels remain secure and fully operational, indicating that the breach did not disrupt customer transactions or core banking operations.
Zenith Bank says customer contact information was accessed
In the email, Zenith Bank said it is investigating unauthorised access to a limited set of customer information, specifically email addresses and phone numbers.
The bank linked the incident to a broader wave of cyber attacks affecting organisations across multiple countries and sectors.
According to the bank, it activated its cyber incident response mechanisms immediately after detecting the breach.
“Upon discovery, we promptly activated our incident response protocols, cybersecurity actions and remediation efforts.”
Zenith also stressed that its banking services and digital channels remain secure and fully operational.
Customers warned about phishing and identity-based attacks
Although the bank did not disclose how many customers were affected, it warned that exposed contact information could potentially be used for phishing campaigns, fraudulent phone calls, and other social engineering attacks.
Zenith advised customers to remain cautious of suspicious emails, SMS messages, and phone calls claiming to be from the bank.
The bank specifically urged customers not to share passwords, PINs, One-Time Passwords (OTPs), or other security credentials, noting that cybercriminals often exploit data breaches to impersonate trusted institutions.
The warning reflects a growing pattern in financial-sector cyber attacks, where attackers use stolen contact information to target customers directly rather than attempting to compromise banking systems themselves.
Also Check: CBN warns Nigerians of phishing attacks targeting bank accounts
Cyber attacks on African financial institutions are becoming more sophisticated
Zenith’s disclosure comes at a time when cyber threats across Africa are becoming increasingly organised and technologically advanced.
According to INTERPOL’s African Cyberthreat Assessment Report 2026, artificial intelligence is now enabling 55 percent of reported cybercrimes across the continent, making attacks faster, more scalable, and harder to detect.
The report found that cybercrime losses across Africa rose sharply from $192 million in 2024 to $484 million in 2025, with criminal networks increasingly using AI tools to automate phishing campaigns, identity theft, and financial fraud.
What makes this trend significant is that many attacks are no longer isolated incidents. They are part of coordinated, cross-border cyber operations targeting financial institutions, government agencies, telecommunications companies, and digital infrastructure providers.
Interestingly, Nigeria has recorded some improvement in payment fraud losses despite the worsening threat landscape. According to The Compliance Reckoning: Regulating Financial Services in the Age of AI, reported digital payment fraud losses fell by more than 50 percent to N25.85 billion in 2025 from N52.26 billion in 2024.
That suggests banks have strengthened fraud detection systems, but it also highlights a broader reality: cyber security is increasingly becoming a race between better defence systems and more sophisticated attackers.
Why this cyber breach matters for Nigeria’s banking sector
Zenith Bank is not the first Nigerian institution to report a cyber security incident in 2026.
In April, the Corporate Affairs Commission (CAC) disclosed a security breach involving unauthorised access to parts of its systems and advised users to update their login credentials. The agency also temporarily shut down its online portal for maintenance and security measures.
Earlier in the year, TechMedia Africa reported that a threat group known as ByteToBreach claimed responsibility for cyber attacks targeting Sterling Bank and Remita, prompting the Nigeria Data Protection Commission (NDPC) to launch formal investigations into both organisations.
Taken together, these incidents point to a broader challenge facing Nigeria’s digital economy.
