
Zenith Bank has begun notifying customers about unauthorised access to limited customer information, including email addresses and phone numbers, in what the bank describes as part of a wider global cyberattack affecting multiple organisations across sectors.
The notice is important because it does not say customer funds, passwords, PINs, OTPs or banking credentials were exposed. But it does point to a different kind of risk that banks and their customers now face more often: attackers do not always need account passwords to start trouble. Sometimes an email address, a phone number and the name of a trusted institution are enough to launch convincing phishing attempts.
In the customer email seen by TechBooky, Zenith Bank said:
“Zenith Bank is investigating unauthorised access to limited customer information including email addresses and phone numbers. This incident is part of a broader, global cyber-attack targeting multiple international organizations across various sectors.”
“Our banking services and digital channels remain secure and fully operational.”
“As a precaution, we encourage our customers to remain vigilant against phishing emails, text messages, or phone calls, and to never disclose their password, PIN, One-Time Password (OTP), or other security credentials to anyone.”
That last line is the part customers should take most seriously. If names, phone numbers or email addresses are in the hands of criminals, the next move may not be an immediate attempt to break into the bank. It may be a fake Zenith Bank email, a WhatsApp message, a call from someone claiming to be from fraud monitoring, or a text message asking the customer to click a link to protect the account.
This is how many modern banking scams work. The criminal begins with just enough real information to sound credible. A customer hears the bank name, receives a message on the email address they actually use, or gets a call that seems to know their phone number, and the situation immediately feels more believable. From there, the attacker tries to collect the missing pieces: OTP, card details, PIN, password, mobile-app login or remote-access permission.
Zenith Bank says its incident response, cybersecurity actions and remediation efforts were activated after discovery of the incident. The bank also says its banking services and digital channels remain secure and fully operational. Until the bank releases a more detailed public technical update, the careful reading is that the disclosed exposure is limited customer contact information, not a confirmed compromise of customer bank accounts.
Still, limited data is not harmless data. Email addresses and phone numbers are useful raw materials for social engineering. They can be combined with leaked data from other sources, searched across social media, or used to send highly targeted messages at the exact time customers are nervous about a breach. That is why the period immediately after a breach notification can be dangerous.
Customers should therefore assume that any message claiming to help them secure their Zenith Bank account could be fake until verified through official channels. Do not click links in unexpected emails or SMS messages. Do not give out OTPs, PINs or passwords to anyone. Do not install an app because a caller says it is required for fraud protection. And if a message creates panic, slow down before responding.
Zenith Bank lists Zenith Direct contact details on its official customer service page, and customers who are unsure about a message should use official contact channels rather than replying to the suspicious message itself. Zenith Bank UK also warns on its fraud-mitigation page that customers should be cautious of scam emails and that legitimate bank staff will not ask for PINs or passwords by email.
For Nigerian banks, the bigger lesson is that cyber incidents are no longer only about whether core banking platforms stay online. The customer communication layer has become just as important. If attackers can harvest contact details and then impersonate a bank convincingly, the damage can move from a data incident into account-takeover attempts, fraud claims and reputational pressure.
This also fits a wider pattern we have been watching across security. Cybercriminals are using ordinary digital channels in more targeted ways, from ad-tech data being weaponised for tracking and attacks to malware campaigns targeting organisations across Africa and the Middle East. The attack surface is no longer just the bank app. It is email, SMS, call centres, third-party vendors, customer records and the human instinct to trust a familiar brand.
The most useful thing Zenith can do next is provide clear follow-up information without causing panic. Customers need to know what categories of data were accessed, whether affected customers are being notified individually, whether regulators have been informed, and whether there are any signs of phishing attempts connected to the incident. That kind of transparency helps customers respond properly instead of guessing.
For now, the customer response is straightforward. Keep using official banking channels, but treat every unsolicited Zenith-branded message with suspicion. If anyone asks for an OTP, PIN, password or card details, the answer should be no. A real bank does not need those secrets to secure your account.







