Home Technology No freedom for MSU student who hacked CABS and stole US$1.1 million,...

No freedom for MSU student who hacked CABS and stole US$1.1 million, magistrate rules as accomplices flee to South Africa

0

A final-year Midlands State University Computer Science student accused of using malware to siphon more than US$1.1 million from Central Africa Building Society has been denied bail, with the court citing the seriousness of the allegations and the risk that he could abscond.

Sabelo Malunga, 24, appeared before Harare regional magistrate Marehwanazvo Gofa facing cyber-related charges arising from an alleged attack on CABS’ banking systems. The magistrate also noted that some of the people believed to have worked with him were still at large and were thought to be in South Africa.

Malunga was remanded in custody, while the case was postponed to September 21 for routine remand proceedings.

The case centres on access that Malunga allegedly obtained during an Information Technology internship at CABS. The State alleges that he used that access between November 2025 and February 23, 2026, first compromising a company laptop and later continuing to reach the bank’s systems after his internship had ended.

Investigators began tracing the alleged breach after suspicious transactions were detected on CABS-linked payment systems. The first major warning came on March 27, when VISA flagged two unusual international ATM transactions involving debit cards issued by the bank.

CABS blocked the affected accounts, but the intervention came after money had already been moved. The alleged losses from the different transactions were placed at US$1,136,179, and none of the money had been recovered by the time the matter came before the court.

A wider investigation followed the initial alerts. On April 13, the bank’s Information Technology team allegedly found several malware infections on its servers. Further examination indicated that the malicious software had been used to create fraudulent ZIPIT transactions and inject them directly into the Zimswitch platform, bypassing normal internal controls.

A reconciliation identified 1,911 allegedly fraudulent ZIPIT transactions with a reported value of US$925,679. The money was allegedly moved through a network of financial institutions and mobile-money services, including EcoCash, InnBucks, CBZ and Ecobank.

The transactions did not follow a single route. Prosecutors allege that the malware facilitated the unlawful authorisation of payments, created fraudulent ZIPIT transfers to Zimswitch, generated fictitious transactions through an Ecobank integration and produced fake telegraphic transfers. The different methods allegedly allowed money to be shifted through several channels before the breach was detected.

The State’s case is that Malunga’s access began with an application installed on a CABS-issued laptop. On January 23, while he was still working at the bank, he allegedly downloaded a programme known as SUPREMO without authorisation.

SUPREMO is a remote-access application. Prosecutors allege that Malunga concealed it among the laptop’s system files in an attempt to prevent the software from being detected. The application allegedly gave him a way to connect remotely to CABS’ data and computer systems.

The alleged access did not end when the internship was completed. Prosecutors say Malunga continued using the application after February 23 and used the connection to interfere with the bank’s servers and transaction systems. The State further alleges that malware was installed to automate or assist the creation and approval of unauthorised payments.

CABS later engaged MWR, a South African digital-forensics company, to contain and remove the malware and investigate how the intrusion had taken place. The forensic work examined the affected systems, the suspicious transactions and the routes through which the money had allegedly been transferred.

The investigation allegedly linked Malunga to the attack. The State is relying on the forensic findings as it pursues the case against him, while the court has also been told that other suspected participants remain outside Zimbabwe.

The alleged accomplices’ whereabouts became a significant issue during the bail hearing. Some are believed to have fled to South Africa, and the court considered the possibility that Malunga could also leave the country if released. The court’s decision means he will remain in custody as investigators and prosecutors continue with the case.

The alleged scheme affected several layers of the banking and payments infrastructure. VISA’s warning concerned international ATM activity, while the later investigation focused on ZIPIT transactions and transfers injected into Zimswitch. Other transactions allegedly passed through mobile-money platforms and accounts connected to banks including CBZ and Ecobank.

The use of a remote-access application is central to the prosecution’s account of how the breach was carried out. Rather than relying only on a single unauthorised transfer, the alleged operation involved continued access, malware infections and the creation of transactions that appeared to move through established payment channels.

The reported ZIPIT figure of US$925,679 represents the largest identified portion of the alleged loss, covering the 1,911 transactions uncovered during the reconciliation. The wider total put before the court, however, was US$1,136,179 after the different categories of alleged fraudulent activity were considered.

The money has not been recovered. Investigators have instead been left to trace the movement of funds across bank accounts, mobile-money wallets and payment systems while assessing the full extent of the damage to CABS.

Malunga’s arrest has brought the alleged compromise of a major Zimbabwean financial institution into sharp focus. The case also highlights the risks created when an individual with temporary access to internal systems is accused of retaining that access after leaving an organisation.

For CABS, the immediate response involved blocking affected accounts, examining its servers, removing the malware and commissioning a specialist forensic investigation. For prosecutors, the case rests on the alleged installation of SUPREMO, the subsequent remote access to the bank’s systems and the transactions that followed.

The matter will return to court on September 21. Until then, Malunga will remain in custody while the State continues preparing its case and efforts to trace the missing funds and locate the other suspected participants continue.

The alleged losses, the number of transactions and the involvement of several payment channels have made the case one of the largest reported cyber-related theft matters involving a Zimbabwean bank. At the centre of it is a university student who prosecutors say used knowledge gained during an internship to gain access to CABS’ systems, install malware and move money through a series of fraudulent transactions.


Breaking News via Email

Enter your email address to subscribe to our website and receive notifications of Breaking News by email.