leak Credible Nigeria (NG) banking

Sterling Bank: customer and employee data claimed stolen

Sterling Bank

📅 27 March 2026
CompanySterling Bank
CountryNigeria (NG)
Sectorbanking
Breach date2026-03-27
People affectedNot disclosed
Data typesNot disclosed

Overview

In March 2026, a DarkForums user with GOD rank, ByteToBreach, posted claims of a data breach at Sterling Bank, a Nigerian commercial bank. The post alleges access to around 900,000 customer accounts, more than 3,000 employee records, and a separate database belonging to Cardinal Stone, a majority shareholder. The claim drew public attention, and the Nigeria Data Protection Commission (NDPC) announced an investigation into Remita and Sterling Bank in connection with related disclosures.

Screenshot of the Sterling Bank post on DarkForums

What was published

The post lists folders covering Kubernetes infrastructure, secret leaks, a decryption endpoint, employee data, a Temenos banking wrapper, KYC records and negotiation material. The poster claims the data includes:

  • Driver's licenses, passports, BVN and NIN identifiers
  • NUBAN account numbers and transaction histories
  • Loan records and credit scoring data
  • Records of executives, including the CEO and the chairman

Folder listing screenshot shared in the Sterling Bank thread

Risks for affected individuals

Banking customers face elevated risk of account takeover, fraud and identity theft if identifiers such as BVN, NIN and passport data were exposed. Employees named in the leak may be targeted with phishing using internal details. Transaction and loan records are sensitive financial data.

What remains unknown

The authenticity and extent of the claimed data are not independently confirmed. No full dataset has been released publicly. Sterling Bank has not published a confirmation, and the outcome of the NDPC investigation is pending.

What affected people should do

Sterling Bank customers should review account activity, change online banking credentials, and enable additional authentication. Anyone contacted with offers to buy or share their financial data should report it to the bank and to the NDPC.

Sources

  • https://darkforums.ru/Thread-DATABASE-NG-Sterling-Bank-Ltd