Student in court over US$1,1m cyber theft

Yeukai Karengezeka-Chisepo-Court Correspondent

A FINAL-year Computer Science student at Midlands State University has appeared in court facing allegations of using malware to siphon more than US$1,1 million from Central Africa Building Society through fraudulent VISA and ZIPIT transactions.

Sabelo Malunga (24) appeared before Harare regional magistrate Mr Francis Mapfumo charged with hacking.

He was remanded in custody to today for his bail application.

The State, led by Mr Blessed Songozo, alleges that Malunga exploited access he gained, while working as an Information Technology intern at CABS between November 2025 and February 23, 2026.

The alleged cyber breach was discovered in March and April this year after CABS detected suspicious transactions involving its VISA and ZIPIT platforms.

The court heard that the matter came to light on March 27 when VISA flagged two suspicious international ATM transactions linked to CABS-issued debit cards.

CABS subsequently blocked the affected accounts, but had already suffered an actual prejudice of US$210,500.

Nothing was recovered from the transactions.

On April 13, during an internal investigation, CABS’ IT team allegedly detected multiple malware infections on its servers.

Further analysis reportedly showed that the malware was creating new ZIPIT transactions and injecting them directly into Zimswitch, thereby bypassing CABS’ internal controls.

A subsequent reconciliation exercise allegedly uncovered 1 911 fraudulent ZIPIT transactions worth US$925 679, which were sent to EcoCash, InnBucks, CBZ and Ecobank.

The State alleges that CABS then engaged South African digital forensic firm MWR to contain and eradicate the malware and investigate the breach.

According to the forensic report, Malunga was allegedly linked to the cyberattack.

The court heard that on January 23, during working hours and while using a company-issued laptop, Malunga allegedly downloaded an application known as SUPREMO without authorisation.

He allegedly concealed the application in system files to avoid detection.

SUPREMO is a remote-access tool which, according to the State, enabled Malunga to access CABS’ data systems remotely.

The prosecution alleges that even after his internship ended on February 23, Malunga continued using the application to gain unauthorised access to CABS’ banking systems and servers.

He is accused of installing malware which allegedly enabled the unlawful authorisation of transactions, fraudulent ZIPIT transfers to Zimswitch, fictitious transactions routed to Ecobank through an integration, as well as the generation of fake telegraphic transfers.

The State alleges that the combined fraudulent transactions resulted in CABS suffering an actual prejudice of US$1 136 179.

Nothing has been recovered so far.

Related Posts

Young women push for economic transformation . . . highlight opportunities created under the Second Republic

Rumbidzayi Zinyuke-Senior Reporter President Mnangagwa will today preside over the second Young Women for ED Convention at the Harare International Conference Centre, where more than 8 500 women are expected…

Zim takes over African UNCCD Chair

Rumbidzayi Zinyuke-Senior Reporter ZIMBABWE has assumed the chairmanship of the African Group at the United Nations Convention to Combat Desertification Conference of the Parties, taking responsibility for steering the continent’s…

Leave a Reply

Your email address will not be published. Required fields are marked *