Zenith Bank Plc has confirmed a cybersecurity incident involving unauthorised access to parts of its database, assuring customers that account balances, transaction records, and core banking systems remain secure.
The tier-1 Nigerian lender disclosed the incident in an electronic communication sent to customers on Tuesday, August 4, 2026, stating that threat actors gained access to its data environment as part of what it described as a broader global cyberattack targeting organisations across different sectors.
The bank said the compromised database was limited primarily to customer contact information, including email addresses and telephone numbers, while critical financial and authentication data remained unaffected.
Customer Funds, Credentials Unaffected
Zenith Bank said preliminary investigations showed that the breach did not affect its core banking infrastructure or payment processing systems.
The financial institution confirmed that the following sensitive customer information remained secure:
- Financial records and balances: Account details, transaction histories, and customers’ funds remain intact.
- Authentication credentials: Passwords, Personal Identification Numbers (PINs), and internet banking tokens were not accessed.
- One-Time Passwords (OTPs): Authentication and transaction authorisation systems remain unaffected.
The bank added that all its service channels, including automated teller machines (ATMs), USSD banking services, internet banking platforms, and mobile applications, continue to function normally without disruption.
“As a precaution, we encourage our customers to remain vigilant against phishing emails, text messages, or phone calls, and to never disclose their password, PIN, One-Time Password (OTP), or other security credentials to anyone,” the bank stated in its security dispatch to clients.
Zenith Bank Launches Investigation After Data Breach
Following the discovery of the unauthorised access, Zenith Bank said it immediately activated its cybersecurity incident response procedures.
The bank’s internal cybersecurity operations centre (CSOC), working alongside external digital forensics and incident response (DFIR) specialists, moved to isolate affected database segments, remove unauthorised access points, and reinforce existing security measures.
Zenith Bank said comprehensive technical assessments are ongoing to identify the source of the breach and determine the full extent of the incident.
The lender also confirmed that it has notified relevant authorities, including cybersecurity regulators and the Central Bank of Nigeria (CBN), in line with regulatory requirements for financial institutions.
Growing Cybersecurity Threats in Nigeria’s Banking Sector
The incident involving Zenith Bank comes amid rising cyber threats targeting financial institutions and fintech companies across Africa.
In recent months, regulators and cybersecurity organisations have warned banks and customers about increasingly sophisticated cybercrime techniques, including credential theft, social engineering attacks, and automated exploitation methods used by international threat groups.
Cybersecurity experts noted that while leaked phone numbers and email addresses may not provide direct access to bank accounts, such information can be exploited by fraudsters to launch targeted phishing, smishing (SMS phishing), and vishing (voice phishing) campaigns.
By impersonating bank officials, criminals often attempt to deceive customers into revealing confidential information such as login details, PINs, or transaction authorisation codes.
Financial analysts said the increasing adoption of digital banking services makes stronger database protection, zero-trust security frameworks, and continuous network monitoring essential for preventing future cyber incidents.
Zenith Bank Advises Customers to Stay Alert
Zenith Bank and cybersecurity professionals have advised customers to take additional precautions to protect themselves against possible follow-up scams.
Customers are encouraged to:
- Verify communications: Check the sender’s email address and ensure messages come from official Zenith Bank channels.
- Protect security details: Bank officials will never request passwords, debit card PINs, BVN details, or One-Time Passwords through calls, text messages, or emails.
- Avoid suspicious links: Do not click links in unsolicited messages requesting account verification or password updates.
- Report suspicious activity: Contact Zenith Bank through official customer support channels if contacted by individuals claiming to represent the bank.
Zenith Bank reiterated its commitment to protecting customer information, thanking clients for their patience as cybersecurity teams complete investigations and implement additional security measures to strengthen its digital infrastructure.
No comments:
Post a Comment