
A Midlands State University student allegedly exploited his internship at CABS to access the bank’s systems and facilitate fraudulent transactions worth more than US$1.1 million. The post MSU computer science student accused of hacking CABS and stealing US$1.1 million appeared first on Nehanda Radio .
A final-year computer science student at Midlands State University allegedly hacked CABS and siphoned more than US$1.1 million through fraudulent VISA, ZIPIT and other banking transactions, a Harare court has heard.
Sabelo Malunga, 24, appeared before regional magistrate Francis Mapfumo facing hacking charges. He was remanded in custody until Thursday, when his application for bail is expected to be heard.
The National Prosecuting Authority, represented by Blessed Songozo, alleges that Malunga gained access to the bank’s systems while completing an internship at CABS between November 2025 and February 23, 2026.
Suspicious ATM withdrawals expose alleged breach
The suspected cyberattack was uncovered in March after VISA alerted CABS to two suspicious international ATM withdrawals involving debit cards issued by the bank.
CABS immediately blocked the affected accounts, but prosecutors said the bank had already lost US$210,500. None of that money has been recovered.
An internal investigation conducted on April 13 allegedly uncovered several malware infections on the bank’s servers.
Further examination reportedly established that the malicious software was being used to create fraudulent ZIPIT transactions and inject them directly into the Zimswitch platform, bypassing CABS’ internal security controls.
A subsequent reconciliation identified 1,911 allegedly fraudulent ZIPIT transactions valued at US$925,679.
The money was reportedly transferred to accounts and wallets held with EcoCash, InnBucks, CBZ and Ecobank.
Forensic investigators allegedly link student to attack
CABS engaged South African digital forensics company MWR to remove the malware, contain the breach and investigate how its systems had been compromised.
According to prosecutors, the company’s forensic investigation linked Malunga to the cyberattack.
The State alleges that on January 23, while he was still an intern, Malunga used a laptop provided by CABS to download an unauthorised remote-access application known as SUPREMO.
He allegedly concealed the application among system files to prevent it from being detected.
Prosecutors claim the software enabled Malunga to access the bank’s computer systems and data remotely.
Access allegedly continued after internship
Malunga is accused of continuing to access CABS’ systems after his internship ended on February 23.
The State alleges that he installed malware capable of unlawfully authorising transactions, injecting fraudulent ZIPIT transfers into Zimswitch and routing fictitious payments to Ecobank through an integration between the institutions.
The malicious software was also allegedly used to generate fraudulent telegraphic transfers.
Prosecutors put CABS’ total loss from the different transactions at US$1,136,179. None of the money has been recovered.
Malunga has not yet been asked to plead and the allegations against him have not been proven in court.
Follow the story