Zenith Bank is investigating unauthorised access to a limited amount of customer contact information, including email addresses and phone numbers.
The bank says the incident is connected to a wider cyberattack affecting organisations across several sectors globally. It also says its banking services and digital platforms remain operational.
That distinction matters. No disruption to banking services has been reported, but exposed contact details could still create a new risk: targeted phishing and impersonation attempts.
What Zenith Bank says happened
In a customer advisory, Zenith Bank disclosed that an unauthorised party gained access to limited customer information.
So far, the bank has identified:
- Email addresses
- Phone numbers
The bank has not publicly stated how many customers were affected. It has also not disclosed the specific system involved, how the unauthorised access occurred or whether additional information was accessed.
Zenith Bank said it activated its incident-response processes as soon as it detected the issue and began cybersecurity and remediation measures.
The bank has also emphasised that its banking services and digital channels remain secure and fully operational.
For customers, that means the immediate concern is not a reported interruption to banking services. It is what criminals might do with the contact information.
The bigger risk may come after the breach
An email address or phone number may not provide direct access to a bank account.
But it can become useful to a scammer when combined with information gathered elsewhere.
A criminal could use exposed contact details to make a fraudulent message look more convincing. A text could appear to come from a bank. A caller could pose as a customer-service representative. An email could create a false sense of urgency around an account or transaction.
The objective would be simple: persuade the victim to hand over the information the attacker does not already have.
That could include a password, PIN, one-time password or other authentication credential.
This is why a breach does not have to involve stolen funds to create meaningful customer risk.
Zenith Bank warns customers about phishing
Zenith Bank has urged customers to be particularly cautious about unsolicited communications following the incident.
Customers should be suspicious of unexpected:
- Emails claiming to be from the bank
- Text messages asking them to take immediate action
- Phone calls requesting account or security information
- Links directing them to unfamiliar login pages
- Requests for passwords, PINs or one-time passwords
Never provide your password, PIN, OTP or other security credentials to someone who contacts you unexpectedly.
Even if a message contains your name, phone number or details that appear to relate to your banking relationship, that does not prove the sender is legitimate.
Scammers increasingly rely on personal information to make social-engineering attacks appear authentic.

How customers can reduce the risk
The safest response is to slow down.
If you receive an unexpected message or call claiming to be from Zenith Bank:
- Do not click links or open unexpected attachments.
- Do not disclose your password, PIN or OTP.
- Do not rely on contact details provided in the suspicious message.
- End the conversation if the caller pressures you to act immediately.
- Contact the bank independently through its official customer-service channels.
- Monitor your accounts and remain alert for unusual activity.
The key principle is simple: verify first, act second.
A legitimate request should withstand a few minutes of independent verification.
Why this incident matters beyond Zenith Bank
The incident highlights a broader challenge facing Nigeria’s increasingly digital financial system.
Customers now depend heavily on mobile banking, internet banking, electronic payments and other online services. That shift creates convenience, but it also increases the amount of sensitive information moving through digital systems.
Banks remain attractive targets because they manage large amounts of valuable personal and financial data while operating infrastructure that supports high volumes of transactions.
That makes cybersecurity more than a technical issue. It is also a customer-protection issue.
A compromised contact database, for example, can potentially become the starting point for a later fraud campaign even when account credentials and transaction records were not exposed.
Nigeria’s cyber-resilience challenge
The incident also comes against a regulatory backdrop in which Nigerian financial institutions face requirements designed to strengthen cybersecurity, risk management and incident response.
The Central Bank of Nigeria has established cybersecurity risk-management requirements for regulated financial institutions. These frameworks are intended to help institutions identify cyber risks, strengthen security controls, monitor threats and maintain the ability to respond to incidents.
Nigeria has also continued to strengthen its legal framework for addressing cybercrime, including through amendments to its Cybercrimes legislation.
For financial institutions, the expectation is therefore broader than simply preventing every attack. Detecting incidents quickly, containing them, responding effectively and communicating with customers are all part of cyber resilience.
Zenith Bank’s disclosure illustrates that process in action: the bank identified an incident, initiated its response measures and notified customers while stating that its core banking channels remained operational.
What remains unknown
Several important details have not yet been made public.
Zenith Bank has not disclosed:
- The number of customers potentially affected
- The exact systems or database involved
- How the unauthorised access occurred
- Whether information beyond contact details was accessed
- The identity or origin of the attackers
- The final scope of the incident
Those questions may become clearer as the investigation progresses.
For now, the bank’s public position is that the incident involved limited customer contact information and did not disrupt its banking services or digital channels.
The takeaway for customers
There is one practical lesson customers should remember.
A bank will never become more legitimate simply because a message knows your name, phone number or email address.
Following a cybersecurity incident, criminals may try to turn exposed contact information into a convincing impersonation attempt. The strongest defence is to refuse to give unexpected callers or messages the information they need to complete the scam.
Treat requests for passwords, PINs and OTPs as sensitive. Verify suspicious communications independently. And when something feels urgent, slow down rather than rush.
Zenith Bank’s investigation is ongoing. Until the bank provides more information, customers should remain alert while continuing to use its banking services through trusted, official channels.