MSU Final-Year Student in Alleged US$1.1 Million Cyber Theft
He installed remote-access software and malware during his internship and later used it to generate fraudulent electronic transactions.
Harare — A 24-year-old Zimbabwe final-year Computer Science student at Midlands State University (MSU) has appeared in the Harare Magistrates Court accused of using malware to hack into Central Africa Building Society (CABS) computer systems and steal more than US$1.1 million.
Reports from local media say Sabelo Malunga faces a charge of hacking after prosecutors alleged that he installed remote-access software and malware during his internship and later used it to generate fraudulent electronic transactions.
According to the State, Malunga worked as an Information Technology intern at CABS from November 2025 until 23 February 2026.
The court was told that on 23 January 2026, while using a company-issued laptop, he allegedly downloaded, without authorisation, a remote-access application known as SUPREMO and concealed it within system files to avoid detection.
Prosecutors say this software, combined with malware he is accused of planting, allowed him to maintain unauthorised remote access to CABS servers even after his internship ended.
The breach was discovered on 27 March 2026 when VISA flagged two suspicious international Automated Teller Machine (ATM) transactions.
Although CABS quickly blocked the affected accounts, the bank had already lost US$210,500.
Further investigation on 13 April 2026 revealed multiple malware infections on the institution’s servers.
A reconciliation exercise allegedly uncovered 1,911 fraudulent ZIPIT transactions worth US$925,679.
The funds were reportedly transferred to accounts linked to EcoCash, InnBucks, CBZ and Ecobank.
The malware is said to have created new ZIPIT transactions and injected them directly into the Zimswitch platform, thereby bypassing CABS’s internal security and authorisation controls.
It is also alleged to have enabled fictitious transfers through an Ecobank integration system and the generation of fake telegraphic transfers.
CABS engaged a South African digital-forensics company, MWR to eradicate the malware and investigate the intrusion.
The forensic report is what prosecutors claim linked Malunga to the cyberattack.
The combined fraudulent activity is alleged to have caused CABS a loss of US$1,136,179.
No money has been recovered so far.
Malunga appeared before Regional Magistrate, Francis Mapfumo.
Prosecutor, Blessed Songozo, presented the State’s outline of the case, and Malunga was remanded in custody pending bail application.

