Msu Student In Court Over Alleged Us$1.1 Million Cabs Cyber Heist
A 24-year-old final-year Computer Science student at Midlands State University (MSU) has appeared before the Harare Magistrates’ Court facing allegations of hacking into Central Africa Building Society (CABS) systems and facilitating fraudulent transactions amounting to more than US$1.1 million.
The accused, Sabelo Malunga, appeared before Harare Regional Magistrate Francis Mapfumo facing a charge of hacking. He was remanded in custody pending his bail application. As of September 1, 2026, the State was opposing his release on bail, with a ruling expected later this week.
According to the prosecution, Malunga allegedly gained access to CABS’ computer systems while working as an Information Technology intern at the bank between November 2025 and February 23, 2026.
The State alleges that on January 23, 2026, while still working at CABS, Malunga used a company-issued laptop to download a remote-access application known as SUPREMO without authorisation. Prosecutors further allege that he concealed the software within system files to prevent it from being detected.
The prosecution claims that the remote-access software enabled Malunga to continue accessing the bank’s systems even after his internship had ended.
The alleged cyberattack was discovered in March after VISA flagged two suspicious international ATM transactions involving CABS-issued debit cards. Although the bank blocked the affected accounts, the State told the court that CABS had already suffered a loss of US$210,500 from the transactions.
Investigations into the incident reportedly uncovered malware infections on CABS servers. The State alleges that the malware was used to generate fraudulent ZIPIT transactions and inject them into the banking system.
Further investigations reportedly identified 1,911 fraudulent ZIPIT transactions valued at approximately US$925,679. The transactions were allegedly directed to various accounts and platforms, including EcoCash, InnBucks, CBZ and Ecobank.
A forensic investigation was subsequently conducted with the assistance of South African digital-forensics firm MWR. According to the prosecution, the investigation linked Malunga to the alleged cyberattack.
The State alleges that the fraudulent VISA, ZIPIT and other transactions resulted in an actual loss of US$1,136,179 to CABS, with the money reportedly not recovered at the time of the court proceedings.
The case has raised concerns about the security of financial institutions and the potential risks associated with insider access to banking systems.
However, the allegations against Malunga have not yet been tested in court. He remains presumed innocent unless and until he is found guilty by a competent court.