Hackers have attacked the database of Zenith Bank, one of Nigeria’s largest financial institutions, stealing customers’ information.
Zenith Bank confirmed the attack in an email to customers on Tuesday.
According to the bank, the hackers accessed limited customer information, “including email addresses and phone numbers, during a cyberattack that forms part of a broader global attack on organisations across different sectors”.
It added that its banking services and digital channels remain secure and fully operational.
Zenith Bank said it is investigating the attack, pointing out that its “incident response protocols and other cybersecurity measures were immediately activated after the breach was discovered.
“As a precaution, we encourage our customers to remain vigilant against phishing emails, text messages, or phone calls, and to never disclose their password, PIN, One-Time Password (OTP), or other security credentials to anyone”.
The Bank expressed commitment to protecting customers’ information and thanked them for their continued trust, adding that investigations into the incident are ongoing.
In August 2024, Guaranty Trust Bank (GTB) reported experiencing a similar incident.
The commercial bank said there were attempts to compromise its website domain, but customers’ data was not affected.
The latest attack comes months after the Central Bank of Nigeria (CBN) warned the public of cyber hack attempts to gain access to personal accounts of Nigerians.
The CBN said the hackers were circulating fraudulent messages and emails falsely claiming to originate from the bank.
According to the financial regulator, there were misleading messages circulating, designed to deceive Nigerians and compromise their personal information.
The regulator said the fake communications, which include emails and online messages, often prompt recipients to click suspicious links while spreading false claims about the bank’s leadership, licensing activities, and policy decisions.
Customers were advised to remain vigilant and refuse to respond to inquiries from people claiming to be bank staff, asking for their personal information or a confirmation of such, but to approach the Customer Services desk at the nearest branch of the bank for clarification and resolution of issues, or they can use only official email addresses and telephone numbers.






