Home Technology How MSU student hacked the bank and stole a whooping US$1.1 million...

How MSU student hacked the bank and stole a whooping US$1.1 million from CABS, nothing was recovered!

0

MSU student accused of hacking CABS and moving US$1.1 million through fraudulent transactions

A final-year Computer Science student at Midlands State University has appeared before the Harare Magistrates Court accused of using malware and a remote-access application to move more than US$1.1 million from Central Africa Building Society through fraudulent VISA, ZIPIT and other transactions.

Sabelo Malunga, 24, appeared before regional magistrate Francis Mapfumo facing a charge of hacking. He was remanded in custody and was expected to return to court on August 31 for a bail hearing.

The case centres on the alleged misuse of access obtained during Malunga’s time as an Information Technology intern at CABS. The State alleges that he exploited the access between November 2025 and February 23, 2026, first planting a remote-access programme on a company laptop and later continuing to reach the bank’s systems after his internship had ended.

Prosecutors told the court that Malunga downloaded an application known as SUPREMO on January 23 while working during office hours and using a CABS-issued laptop. The application was allegedly installed without authorisation and concealed among system files to make it harder to detect.

SUPREMO is a remote-access tool. In the State’s account, its presence allowed Malunga to connect to CABS’ data systems from outside the bank’s normal working environment. The prosecution alleges that he retained this route into the bank after his attachment ended on February 23 and used it to interfere with transaction systems and servers.

The suspected breach was first identified after VISA flagged two suspicious international ATM transactions linked to CABS-issued debit cards on March 27. CABS blocked the affected accounts, but the bank had already suffered an actual prejudice of US$210,500. Nothing was recovered from those transactions.

The discovery prompted a wider internal investigation. On April 13, CABS’ Information Technology team allegedly found multiple malware infections on the bank’s servers. Further analysis showed that the malware was creating new ZIPIT transactions and injecting them directly into Zimswitch, bypassing the bank’s internal controls.

A subsequent reconciliation uncovered 1,911 fraudulent ZIPIT transactions worth US$925,679. The funds were allegedly sent through accounts and services linked to EcoCash, InnBucks, CBZ and Ecobank, creating a trail that crossed banking and mobile-money platforms.

The transactions formed the largest part of the alleged loss. The State says the malware did more than generate unauthorised transfers. It allegedly enabled unlawful authorisation of transactions, the creation of fictitious transfers through an Ecobank integration, fraudulent ZIPIT payments into Zimswitch and the generation of fake telegraphic transfers.

CABS then engaged MWR, a South African digital-forensic firm, to contain and eradicate the malware and investigate how the bank’s systems had been compromised. The forensic investigation allegedly linked Malunga to the intrusion. The State is relying on that investigation as it presents its case against the student.

The total alleged prejudice suffered by CABS has been put at US$1,136,179. The bank has not recovered any of the money so far.

The case has highlighted how access given for legitimate technical work can become a serious vulnerability when it is not fully removed or monitored after an employee or intern leaves. In this matter, the alleged method did not depend only on a single suspicious payment. It involved continued access, malicious software, payment instructions and links between several financial platforms.

The scale of the alleged ZIPIT activity is also clear from the transaction count. Spread across 1,911 transfers, the US$925,679 attributed to that part of the operation represents an average of about US$485 per transaction. The pattern described in court suggests a series of payments designed to move money repeatedly rather than one visible withdrawal that could immediately bring the account to a halt.

The initial VISA alerts nevertheless provided the first major warning sign. Two international ATM transactions were enough to trigger action and lead to the blocking of affected accounts. By the time that intervention took place, the alleged losses had already reached US$210,500, while the deeper server investigation later exposed the much larger ZIPIT operation.

The use of several destination platforms has added another layer to the investigation. EcoCash and InnBucks operate in Zimbabwe’s mobile-money and digital-payments space, while CBZ and Ecobank are banking institutions. The alleged movement of funds through these channels means that investigators had to follow transaction records across different systems while trying to determine where the money went.

The wider African cybercrime picture shows why attacks on digital payment systems have become a growing concern for financial institutions. A 2026 regional cyberthreat assessment found that mobile-money fraud was the most prevalent scam reported by 97 per cent of countries responding to an international law-enforcement survey. The assessment also said online scams had become increasingly organised, using mobile-money platforms, social media and artificial intelligence to reach targets across borders.

The same assessment described the growing use of synthetic identities and money-muling networks to move or disguise illicit funds. It said people were sometimes recruited through fake job adverts and presented with roles such as financial agents or remote transaction officers, while criminals used their accounts to transfer proceeds from wider fraud schemes. Those regional findings do not establish a link to the CABS case, but they underline the pressure facing banks and payment providers as more transactions move through connected digital systems.

In the CABS matter, the prosecution alleges that the key opening came from inside the bank’s working environment. Malunga is accused of downloading the remote-access application while he was still an intern, hiding it in the computer’s system files and then using it after his attachment ended. The alleged activity was eventually exposed through payment alerts, internal checks, server analysis and specialist forensic work.

The court is expected to consider Malunga’s bail application as the case proceeds. For CABS, the immediate outcome remains a reported loss of US$1,136,179, and nothing was recovered.


Breaking News via Email

Enter your email address to subscribe to our website and receive notifications of Breaking News by email.