CABS Cybertheft Case: MSU Student Faces US$1.1m Hacking Allegations
A Midlands State University (MSU) final-year Computer Science student has appeared in court over allegations that he used malware and remote-access software to siphon more than US$1.1 million (about R18.4 million) from Central Africa Building Society (CABS).
Sabelo Malunga, 24, appeared before Harare regional magistrate Francis Mapfumo facing a hacking charge. He was remanded in custody until Monday, 31 August 2026, for his bail application.
The allegations stem from the period when Malunga was working as an Information Technology intern at CABS between November 2025 and 23 February 2026.
The State, led by Blessed Songozo, alleges that Malunga exploited access obtained during his internship to interfere with CABS banking systems and facilitate fraudulent transactions.
CABS Cyberattack Allegedly Started With Remote-Access Software
The Herald reports that CABS began investigating suspicious activity after Visa flagged two international ATM transactions involving CABS-issued debit cards on 27 March 2026.
The bank allegedly blocked the affected accounts, but had already suffered actual prejudice of US$210,500 (about R3.4 million). The court heard that none of the money from those transactions had been recovered.
A deeper internal investigation on 13 April allegedly uncovered multiple malware infections on CABS servers.
The State alleges that the malware was being used to create fraudulent ZIPIT transactions and inject them directly into Zimswitch, allowing the transactions to bypass CABS’ internal controls.
“The malware was creating new ZIPIT transactions and injecting them directly into Zimswitch.”
A subsequent reconciliation allegedly identified 1,911 fraudulent ZIPIT transactions valued at US$925,679 (about R15 million).
The transactions were allegedly sent to several financial platforms and institutions, including EcoCash, InnBucks, CBZ and Ecobank.
CABS subsequently engaged South African digital forensics company MWR to contain the suspected malware, investigate the breach and determine how the systems had been compromised.
Student Allegedly Maintained Access After Internship
The prosecution alleges that Malunga downloaded an application called SUPREMO onto a company-issued laptop on 23 January 2026 without authorisation.
According to the State, he allegedly concealed the programme within system files to prevent it from being detected.
SUPREMO is a remote-access tool. Prosecutors allege it gave Malunga the ability to access CABS systems remotely.
The State further alleges that the access continued after his internship ended on 23 February.
Investigators allegedly found evidence linking Malunga to the cyberattack during the subsequent forensic examination.
He is accused of installing malware that allegedly facilitated unlawful transaction authorisations, fraudulent ZIPIT transfers into Zimswitch, fictitious transactions routed through an Ecobank integration and the creation of fake telegraphic transfers.
The State alleges that the combined fraudulent activity resulted in CABS suffering actual prejudice of US$1,136,179 (about R18.7 million).
No money has been recovered so far.
The post MSU Student Arrested For US$1.1m Cybertheft After Hacking CABS appeared first on iHarare News.








