MSU Final-Year Student Denied Bail Over US$1.1 Million CABS Cyber Fraud
A 24-year-old Midlands State University student has been denied bail over allegations that he helped siphon more than US$1.1 million from CABS.
Sabelo Malunga, a final-year Computer Science student, is facing cyber-related charges arising from an alleged attack on the bank’s systems.
According to H-Metro, Harare regional magistrate Marehwanazvo Gofa denied his bail application, citing the seriousness of the allegations and concerns that he could flee.
Also Read: MSU Student Arrested For US$1.1m Cybertheft After Hacking CABS
Court Raises Concerns Over Alleged Accomplices
The court also heard that some of Malunga’s alleged accomplices remain at large.
They are reportedly believed to be in South Africa.
The magistrate considered this when assessing the possibility of Malunga absconding if released on bail.
The State alleges that Malunga gained access to CABS systems during an Information Technology internship at the bank.
His internship reportedly ran from November 2025 until February 23, 2026.
Alleged Remote Access To Bank Systems
Prosecutors allege that Malunga used his position at CABS to facilitate unauthorised access to the bank’s infrastructure.
The State claims he downloaded SUPREMO onto a company laptop on January 23.
He allegedly installed the remote-access application without authorisation.
Prosecutors further allege that he hid the software within system files to avoid detection.
The State says SUPREMO enabled him to remotely access CABS systems and data.
According to the allegations, that access continued even after his internship ended.
Suspicious Transactions Trigger Investigation
The alleged breach came to light after CABS detected unusual activity involving its VISA and ZIPIT services.
On March 27, VISA reportedly identified two suspicious international ATM transactions involving CABS-issued debit cards.
The bank then blocked the affected accounts.
However, the State alleges that CABS had already suffered losses amounting to US$925,679.
Investigators later traced transactions through several financial platforms and institutions.
These allegedly included EcoCash, InnBucks, CBZ and Ecobank.
Forensic Investigation Links Student To Alleged Attack
CABS subsequently brought in South African digital forensics company MWR to investigate the breach.
The firm was tasked with containing the suspected malware and determining how the bank’s systems had been compromised.
The resulting forensic investigation allegedly linked Malunga to the cyberattack.
Prosecutors allege that he installed malware capable of facilitating fraudulent transactions.
The malware allegedly enabled unlawful transaction authorisations and fraudulent ZIPIT transfers to Zimswitch.
The State also alleges that fictitious transactions were routed through Ecobank.
Fake telegraphic transfers were allegedly generated as part of the scheme.
CABS Allegedly Lost More Than US$1.1 Million
According to the State, the various transactions caused CABS actual prejudice of US$1,136,179.
The alleged losses therefore extend beyond the US$925,679 initially identified after the suspicious VISA transactions.
The court heard that none of the money had been recovered.
Malunga remains in custody after the magistrate rejected his application for bail.
He is expected back in court on September 21 for routine remand.
The post MSU Final-Year Student Denied Bail Over US$1.1 Million CABS Cyber Fraud appeared first on iHarare News.








