MSU Student Accused Of US$1.1 Million CABS Cyber Theft Denied Bail
A final-year Computer Science student at Midlands State University (MSU) accused of using malware to steal more than US$1.1 million from CABS through fraudulent VISA and ZIPIT transactions has been denied bail. Sabelo Malunga, 24, appeared before Harare regional magistrate Marehwanazvo Gofa facing cyber-related charges. He will remain in custody and return to court on […]
AI summary
A Zimbabwean computer science student accused of cyber theft involving $1.1 million from CABS has been denied bail by a Harare magistrate.
A final-year Computer Science student at Midlands State University (MSU) accused of using malware to steal more than US$1.1 million from CABS through fraudulent VISA and ZIPIT transactions has been denied bail.
Sabelo Malunga, 24, appeared before Harare regional magistrate Marehwanazvo Gofa facing cyber-related charges. He will remain in custody and return to court on 21 September for routine remand.
In denying bail, the magistrate cited the gravity of the allegations and the risk that Malunga could abscond. She also noted that some of his alleged accomplices are still at large and are reportedly in South Africa.
The State alleges that Malunga exploited access he obtained while working as an Information Technology intern at CABS between November 2025 and 23 February 2026.
Prosecutors say that on 23 January, while at work and using a company-issued laptop, he downloaded an application known as SUPREMO without authorisation and concealed it within system files to evade detection. SUPREMO is a remote-access tool which allegedly allowed him to remotely access the bank’s data and computer systems.
The court heard that even after his internship ended on 23 February, Malunga allegedly continued to use the application to gain unauthorised access to the bank’s systems and servers.
He is accused of installing malware that facilitated the unlawful authorisation of transactions, fraudulent ZIPIT transfers to ZimSwitch, fictitious transactions routed to Ecobank and the generation of fake telegraphic transfers.
The alleged breach was uncovered in March and April after CABS detected suspicious transactions on its VISA and ZIPIT platforms. On 27 March, VISA flagged two suspicious international ATM transactions linked to CABS-issued debit cards. The bank blocked the affected accounts but had already lost US$925,679.
The money was allegedly moved through various platforms and financial institutions, including EcoCash, InnBucks, CBZ and Ecobank.
Following the discovery, CABS engaged South African digital forensic firm MWR to contain and eradicate the malware and investigate the breach. According to the forensic report, Malunga was linked to the cyber attack.
The State alleges that the combined fraudulent transactions prejudiced CABS of US$1,136,179. The court heard that none of the money has been recovered.
More: The Herald
Follow the story
About this article
- Length
- 353 words · 2 min read
- Published
- September 9, 2026
- Byline
- Lovemore
- Source
- Pindula News