Ransomware victim disclosure
← All victimsZenith Bank Plc
Claimed by ExfilSquad · listed 3 days ago
Status timeline
- ListedJul 26, 2026
- Data leakeddate unknown
At a glance
- Group
- ExfilSquad
- Status
- Data leaked
- Country
- Nigeria
- Sector
- Financial Services
- Listed on leak site
- Jul 26, 2026
About the victim
AI dossier — public-source company profileZenith Bank Plc is a major Nigerian financial institution with annual revenue of approximately ₦2.3 trillion. The bank provides retail and commercial banking services across Nigeria.
- Industry
- Financial Services & Banking
Attack summary
Severity: critical — Confirmed exfiltration and publication of ~90 million customer records containing highly sensitive regulated financial data (PII, account information, government IDs) from a major bank. This represents massive-scale exposure of regulated financial and personal information.ExfilSquad claims to have exfiltrated approximately 90 million records from Zenith Bank Plc containing extensive personally identifiable information, banking relationships, account details, and financial data. The group has published the data.
Data the group says was taken
AI dossier — extracted from the leak post- personally identifiable information (PII)
- banking relationships
- account information
- financial data
- government identifiers
- customer contact information
- banking support case records
What the group claims
Revenue: ₦2.3T DATA SUMMARY: 90M~ records containing: extensive PII, banking relationships, account information, financial data, government identifiers, customer contact information, and banking support cases.
Sources
- Victim sitezenithbank.com
Source
Indexed 3 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

