Staff Reporter
HARARE – A 24-year-old Midlands State University (MSU) Computer Science student has appeared in court, facing allegations of hacking into CABS systems and facilitating fraudulent transactions worth more than US$1.1 million.
Sabelo Malunga, a final-year student, appeared before Harare regional magistrate Francis Mapfumo and was remanded in custody until today for a bail hearing. He pleaded not guilty.
The State alleges that Malunga exploited access he obtained during an information technology internship at CABS between November 2025 and February 23, 2026.
Prosecutor Blessed Songozo told the court that investigations began after Visa flagged suspicious international ATM transactions involving CABS-issued cards on March 27, 2026.
The bank reportedly lost US$210,500 from the transactions.
Further investigations allegedly uncovered malware on CABS servers, which was reportedly used to generate fraudulent ZIPIT transactions and inject them directly into Zimswitch, bypassing internal controls.
A reconciliation exercise allegedly identified 1,911 fraudulent ZIPIT transactions valued at US$925,679, with funds sent to EcoCash, InnBucks, CBZ, and Ecobank.
The State alleges that a forensic investigation by South African digital forensics firm MWR linked Malunga to the cyberattack.
Malunga is accused of downloading SUPREMO, a remote-access application, onto a company laptop on January 23, 2026, and concealing it within system files.
The prosecution alleges that he continued accessing CABS systems remotely even after his internship ended.
The State further alleges that malware installed on the bank’s systems enabled unauthorised transactions, fraudulent ZIPIT transfers, fictitious Ecobank transactions, and fake telegraphic transfers.
The alleged transactions resulted in an estimated actual loss of US$1,136,179, with no recovery made so far.
The matter is before the courts.












