LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surface
Recent BreachesData breach tracker

Recent Breaches › Zenith Bank Plc Listed by ExfilSquad Ransomware Group

HIGH severity claimedUnverified claimHow we verify

Zenith Bank Plc Listed by ExfilSquad Ransomware Group: What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·July 26, 2026
Zenith Bank Plc Listed by ExfilSquad Ransomware Group

Reported July 26, 2026.

HIGH
Severity
1
Data types exposed
July 26, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Zenith Bank Plc has been listed by the ExfilSquad ransomware group, with internal files reportedly exfiltrated in an attack whose occurrence date has not been established. The listing came to light on July 26, 2026; affected individuals should review any communications from the bank and monitor their accounts for unusual activity.

Severity & verification
HIGH severity claimedUnverified claim
Exposes government-ID data.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Was your email in the Zenith Bank Plc Listed by ExfilSquad Ransomware Group breach?
See every leak tied to your email — not just this one. 15-second check, no card, no account.

Zenith Bank Plc, a major Nigerian financial institution, was listed by the ransomware group ExfilSquad on or around July 26, 2026. Public reporting indicates the group claims to have exfiltrated internal files in a ransomware attack. The number of people affected remains unknown, and independent confirmation of the full scope has not been established in available details.

For customers, employees, and partners of a large bank, any such listing raises immediate questions about the security of personal and financial information. What is known so far is limited to the group's claim and a high-level description of internal files; further verified particulars have not been disclosed.

Breaking down the breach

According to the available record, Zenith Bank Plc appeared on ExfilSquad's listings with a report date of July 26, 2026. The incident is described as a ransomware attack in which internal files were exfiltrated. No public figure has been given for the number of individuals affected, and specifics on the initial access method, duration of unauthorized access, or precise timeline of the intrusion remain undisclosed.

The record notes the organization's revenue figure of ₦2.3T in summary context, but does not provide Reported Details on ransom demands, negotiation status, or whether any data has been released beyond the listing itself. As with many ransomware claims, the listing constitutes an assertion by the group rather than a fully independently verified account of every element. Exact file volumes, systems impacted, and containment steps taken by the bank are not detailed in the public facts provided.

Who is ExfilSquad?

ExfilSquad is known publicly as a ransomware operation that engages in double-extortion tactics: encrypting systems where possible while also stealing data and threatening to publish or sell it if demands are unmet. Like other groups in this category, it typically maintains a leak site or similar channel on which it names victims and, in some cases, posts samples or larger data sets to increase pressure.

Established patterns associated with such actors include opportunistic or targeted intrusion, data staging and exfiltration prior to or alongside encryption, and public listing of organizations to amplify reputational and regulatory impact. Notable prior activity by groups operating in this style has involved financial services, professional firms, and other data-rich sectors, though specific claims made by ExfilSquad about Zenith Bank Plc beyond the listing and the description of internal-file exfiltration are not elaborated in the given facts. Any assertions on the group's site should be treated as claims pending corroboration.

Who is Zenith Bank Plc?

Zenith Bank Plc is a prominent commercial bank headquartered in Nigeria and active across retail, corporate, and related financial services. Institutions of this type routinely manage large volumes of customer accounts, transaction records, identity documentation, and internal operational files. They sit at the center of everyday economic activity for individuals, businesses, and sometimes government-linked entities.

A breach or claimed breach at a bank of this scale is consequential because of the sensitivity and longevity of the data involved. Financial institutions are attractive targets precisely because successful compromise can yield information useful for fraud, identity misuse, or further social-engineering attacks. The bank's size and the breadth of its customer base mean that even a partial exposure of internal files can carry wide practical implications, regardless of whether every claimed detail is later confirmed.

What data was at risk

The facts name the exposed material as internal files exfiltrated in a ransomware attack. A related data summary associated with the record indicates approximately 90 million records said to contain extensive personally identifiable information, banking relationships, account information, financial data, government identifiers, customer contact information, and banking support cases. The number of people affected is listed as unknown.

Because independent public confirmation of the exact contents and completeness of any stolen set is limited, these descriptions should be understood as what has been reported or claimed rather than as a fully audited inventory. Organizations in the banking sector typically hold precisely the categories noted—customer identities, account and transaction details, contact data, and support records—along with internal operational documents. Until more verified disclosure occurs, the precise composition and whether every listed category was in fact taken remain unconfirmed beyond the high-level characterization of internal files.

What's at stake

For individuals, the real-world risks center on fraud and misuse. Exposure of account information, government identifiers, and contact details can enable targeted phishing, account-takeover attempts, unauthorized applications for credit or services, and social engineering that references genuine banking relationships or support cases. Financial data and banking relationships, if misused, may facilitate more convincing scams or attempts to move funds.

For the organization, stakes include operational disruption from the ransomware event itself, potential regulatory scrutiny, customer notification and support costs, and longer-term trust effects. Even when encryption is limited or systems are restored, the exfiltration component creates ongoing exposure because stolen data can circulate or be monetized independently of any ransom payment. The absence of a confirmed affected-person count does not reduce the need for vigilance among those who bank with or work for the institution.

If your data was in this breach

If you hold accounts or have other relationships with Zenith Bank Plc, treat the situation as a prompt for heightened caution rather than confirmed personal compromise. Monitor account statements and credit activity for unfamiliar transactions or inquiries. Be alert to unsolicited contacts that reference your banking details, support history, or personal identifiers; verify any such contact through official channels you initiate yourself. Consider updating passwords and enabling stronger authentication on financial and email accounts. Where available, freeze or alert credit files according to local procedures.

You can also run a free exposure scan of your email address to check whether your information has already surfaced in known breach data sets. Remaining calm, verifying sources, and acting on concrete warning signs remain the most practical first steps while fuller details, if any, emerge.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyZenith Bank Plc security record
64/100
DoxxScan™ · Moderate doxx risk
B- 76Above-average record

1 reported incident on record.

See Zenith Bank Plc’s full breach history →

More recent breaches

Allstate Listed by ExfilSquad Ransomware GroupJuly 26, 2026Wesco International Listed by ExfilSquad Ransomware GroupJuly 26, 2026City of Houston Listed by ExfilSquad Ransomware GroupJuly 26, 2026Police National Legal Database Listed by ExfilSquad Ransomware GroupJuly 26, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the Zenith Bank Plc Listed by ExfilSquad Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by exfilsquad — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram