Search TorWire

Find cybersecurity guides and research articles

Home > News > Cybersecurity > Threat Actor Claims Breach of Nigeria’s Zenith Bank, Alleges Theft of 90 Million Records

Threat Actor Claims Breach of Nigeria’s Zenith Bank, Alleges Theft of 90 Million Records

By: Jordan Vector Cybersecurity Expert

Last updated: July 27, 2026

Human Written
Threat Actor Claims Breach of Nigeria’s Zenith Bank, Alleges Theft of 90 Million Records
  • ExfilSquad claims it breached Nigeria’s Zenith Bank and stole about 90 million records.

  • The alleged dataset reportedly contains 874 GB of personal, financial and customer information.

  • The claim includes account details, government IDs, contact information and banking support records.

A threat actor called ExfilSquad has claimed it breached Nigerian bank Zenith Bank Plc. The actor allegedly obtained about 90 million records from the financial institution.

The claimed dataset reportedly contains around 874 GB of data. The alleged attack appeared on July 26, 2026. ExfilSquad reportedly included Zenith Bank among several organisations it claimed to have targeted.

The alleged dataset contains several types of sensitive information. These reportedly include personal details, account information and financial records. The data also allegedly contains government identifiers and customer contact information.

Banking support cases reportedly form part of the claimed dataset. The alleged records could give attackers access to detailed information about affected customers. However, no independent evidence has confirmed that the data belongs to Zenith Bank.

ExfilSquad Names Zenith Bank Among Alleged Victims

Cybersecurity publication SecNews reported the Zenith Bank claim on July 26. The report listed the bank among 14 organisations ExfilSquad allegedly claimed to have breached. The report also mentioned the alleged 90 million records linked to the bank.

It further stated that the claimed dataset reportedly totals about 874 GB. However, questions have emerged about some of ExfilSquad’s recent breach claims. Security researchers have previously questioned or described other claims linked to the actor as potentially fabricated.

That history makes independent checks important when assessing the Zenith Bank allegation. Threat actors sometimes make breach claims without providing enough evidence to prove them. The same caution applies to other Nigerian banking claims; a hacker has alleged a data breach of one million Sterling Bank customers.

The reported data volume also remains part of the actor’s claim. Researchers have not independently confirmed the 90 million records or the 874 GB figure. The alleged information includes several categories that could be valuable to cybercriminals.

Personal details, financial records and government identifiers can expose customers to different forms of fraud. Contact information could also help attackers target victims with convincing messages.

Criminals could use known details to make phishing attempts appear more believable. However, the available information does not confirm that attackers have successfully used any of the alleged data.

Alleged Data Includes Customer and Banking Information

The claimed dataset reportedly contains personally identifiable information, often called PII. It also allegedly includes customer and account information. Financial records reportedly form another part of the alleged data. Government identifiers and contact details are also included in the reported dataset.

The claim further mentions banking support cases. These records could contain information linked to customer interactions with the bank. According to the available report, the alleged dataset covers a large amount of information. However, the exact contents and quality of the records remain unclear.

The claim also comes after other alleged ExfilSquad attacks received attention from cybersecurity researchers. One recent claim involving Microsoft reportedly faced similar questions about its authenticity.

CyPro reportedly described that Microsoft-related claim as unverified. The analysis also noted that no independent evidence or public samples had confirmed the alleged breach. The concerns surrounding those earlier claims do not prove that the Zenith Bank claim is false.

They show why researchers need evidence before confirming a reported cyberattack. A genuine breach involving such information could create serious risks for affected customers. Criminals could use personal data for phishing, impersonation, and other fraud attempts. Attackers could also combine different pieces of information to build detailed profiles of victims. Such profiles could make targeted scams more convincing.

Zenith Bank’s 2025 annual report provides additional background about its data protection efforts. The report stated that the bank recorded no customer data breaches, leaks, thefts or losses during that period.

The bank also described cybersecurity measures designed to protect its systems and customer information. However, that report covered an earlier period and does not confirm or reject the latest allegation.

Zenith Bank Breach Claim Remains Unconfirmed

The alleged breach currently remains an unconfirmed claim attributed to ExfilSquad. No independent evidence has established that the threat actor accessed Zenith Bank systems. Researchers have also not confirmed the authenticity of the alleged 90 million records.

The reported 874 GB dataset also requires further validation. Security researchers would need to examine any leaked samples before confirming the claim. They would also need to establish whether the records genuinely came from Zenith Bank.

An official response from the bank could provide further information about the allegation. Such a response could also help clarify whether any customer data was affected.

For now, the available information supports describing the incident as an alleged breach claim. It does not support presenting the incident as a confirmed compromise. The alleged size of the dataset has nevertheless drawn attention because of the number of records involved.

The reported information also covers several sensitive categories linked to customers and banking services. Further investigation will determine whether the claimed records are genuine. Until then, the Zenith Bank allegation remains an unconfirmed cyberattack claim linked to ExfilSquad.

Share this article

About the Author

Jordan Vector

Jordan Vector

Cybersecurity Expert

Jordan is a security researcher and advocate who focuses on making privacy practical. Whether he's explaining how to harden a browser or reporting on the latest surveillance disclosures, his goal is to equip readers with knowledge they can use immediately. Jordan believes that true security begins with understanding the digital landscape.

Comments (0)

No comments.