IT student denied bail in US$1,1m case

Yeukai Karengezeka-Chisepo-Court Correspondent

A MIDLANDS State University final-year Computer Science student accused of using malware to siphon over US$1,1 million from CABS through fraudulent VISA and ZIPIT transactions has been denied bail.

Sabelo Malunga (24), who is facing cyber-related charges, appeared before Harare regional magistrate Mrs Marehwanazvo Gofa, who denied him bail, citing the gravity of the allegations and the possibility that he could abscond.

The magistrate also noted that some of Malunga’s alleged accomplices were still at large and were reportedly in South Africa.

The matter was remanded to September 21 for routine remand. The State alleges that Malunga exploited access he obtained, while working as an Information Technology intern at CABS between November 2025 and February 23, 2026.

The alleged cyber breach was uncovered in March and April after CABS detected suspicious transactions involving its VISA and ZIPIT platforms.

The court heard that on March 27, VISA flagged two suspicious international ATM transactions linked to CABS-issued debit cards.

The bank subsequently blocked the affected accounts, but had already suffered actual prejudice of US$925 679.

The money was allegedly transferred through various platforms and financial institutions, including EcoCash, InnBucks, CBZ and Ecobank.

Following the discovery, CABS engaged South African digital forensic firm MWR to contain and eradicate the malware and investigate the breach.

According to the forensic report, Malunga was allegedly linked to the cyber attack. The State alleges that on January 23, while at work and using a company-issued laptop, Malunga downloaded an application known as SUPREMO without authorisation.

He allegedly concealed the application within system files to evade detection.

SUPREMO is a remote-access tool which prosecutors allege enabled Malunga to remotely access CABS’ data and computer systems.

The prosecution further alleges that after his intern-ship ended on February 23, Malunga continued using the application to gain unauthorised access to the bank’s systems and servers.

He is accused of installing malware that allegedly facilitated unlawful authorisation of transactions, fraudulent ZIPIT transfers to ZimSwitch, fictitious transactions routed to Ecobank and the generation of fake telegraphic transfers.

The State alleges that the combined fraudulent transactions resulted in CABS suffering actual prejudice of US$1 136 179.

The court heard that none of the money had been recovered.

Related Posts

MAPEZA WANTS MORE . . . Scottland coach says 1-0 lead leaves plenty of work ahead

Eddie Chikamhi-Zimpapers Sports Hub Scottland . . . . . . . . . . . . . . . . . . . . . (0) 1 Nsingizini Hotspurs…

World Bank proposes reforms to lift Zimbabwean growth, jobs

Michael Tome Business Reporter  The World Bank has proposed reforms to unlock Zimbabwe’s growth potential, urging the Government to ramp up investment in critical infrastructure and improve the business regulatory…

Leave a Reply

Your email address will not be published. Required fields are marked *