Zenith Bank Plc has confirmed that it experienced a cybersecurity incident that resulted in unauthorised access to limited customer contact information, making it one of the latest Nigerian financial institutions to publicly disclose a cyber-related security breach.
In a customer notification issued on Tuesday, August 4, 2026, the bank said the incident led to the exposure of customers’ email addresses and telephone numbers. It stressed, however, that no sensitive banking information was compromised.
According to the bank, passwords, Personal Identification Numbers (PINs), One-Time Passwords (OTPs), account balances, debit card details and transaction records were not accessed during the incident.
The lender said it activated its incident response procedures immediately after detecting the breach and implemented additional security measures to contain the incident and safeguard its systems.
“Following the detection of the incident, we promptly implemented our established incident response procedures and enhanced security measures to contain the breach and protect our systems,” the bank said in its notification to customers.
Zenith Bank also assured customers that its core banking infrastructure was not compromised and that all banking services remain fully operational.
The bank urged customers to remain vigilant against phishing attempts, warning that fraudsters could use the exposed contact information to send deceptive emails, text messages or make phone calls while impersonating the bank.
It reiterated that it would never request customers’ passwords, PINs, OTPs or other confidential security credentials through email, telephone calls or text messages. Customers were advised to report any suspicious communication through the bank’s official customer service channels.
The disclosure comes as organisations across the financial sector continue to strengthen cybersecurity measures in response to evolving digital threats. As more banking services migrate online, financial institutions face increasing pressure to protect customer data and maintain resilient digital infrastructure.
Zenith Bank did not disclose how many customers were affected or provide further details on the nature of the cyber incident, stating that investigations are ongoing. The lender said it would provide additional updates where necessary.
Cybersecurity specialists generally advise organisations to disclose confirmed security incidents promptly and encourage affected customers to remain alert for potential fraud, particularly phishing and social engineering attacks that may follow a data breach.
Zenith Bank maintained that its banking platforms remain secure and reaffirmed its commitment to protecting customers’ information while continuing its investigation into the incident.



