A university student has appeared before a Harare magistrate accused of using malware to steal more than US$1.1 million from CABS through fraudulent Visa and ZIPIT transactions.
Sabelo Malunga, 24, a final-year Computer Science student at Midlands State University (MSU), appeared before Harare regional magistrate Francis Mapfumo last week facing a charge of hacking.
He was remanded in custody to Monday, 31 August, for a bail hearing.
Prosecutor Blessed Songozo told the court that Malunga allegedly exploited access he gained while working as an information technology intern at CABS between November 2025 and 23 February 2026.
The alleged cyberattack was uncovered in March and April after CABS detected suspicious transactions involving its Visa and ZIPIT platforms.
The court heard that the matter first came to light on 27 March when Visa flagged two suspicious international ATM transactions linked to CABS-issued debit cards.
CABS subsequently blocked the affected accounts but had already suffered an actual loss of US$210,500. No money was recovered from those transactions.
On 13 April, during an internal investigation, CABS’ IT team allegedly detected multiple malware infections on its servers.
Further analysis reportedly showed that the malware was being used to create new ZIPIT transactions and inject them directly into Zimswitch, bypassing CABS’ internal controls.
A subsequent reconciliation exercise allegedly uncovered 1,911 fraudulent ZIPIT transactions worth US$925,679, which were sent to EcoCash, InnBucks, CBZ and Ecobank.
The State alleges that CABS then engaged South African digital forensics firm MWR to contain and remove the malware and investigate the breach.
According to the forensic report, Malunga was allegedly linked to the cyberattack.
The court heard that on 23 January, during working hours and while using a company-issued laptop, Malunga allegedly downloaded an application called SUPREMO without authorisation.
He allegedly concealed the application within system files to avoid detection.
SUPREMO is a remote-access tool which, according to the State, enabled Malunga to access CABS’ data and systems remotely.
The prosecution alleges that even after his internship ended on 23 February, Malunga continued using the application to gain unauthorised access to CABS’ banking systems and servers.
He is accused of installing malware that allegedly enabled the unlawful authorisation of transactions, fraudulent ZIPIT transfers to Zimswitch, fictitious transactions routed to Ecobank through an integration, and the generation of fake telegraphic transfers.
The State alleges that the combined fraudulent transactions resulted in CABS suffering an actual loss of US$1,136,179. No money has been recovered so far.
Follow the story