Monday, 7 September 2026PREMIUM EDITORIAL
MSU Student Accused of US$1.1m CABS Fraud Denied Bail

MSU Student Accused of US$1.1m CABS Fraud Denied Bail

ZN
ZimCelebs News·September 7, 2026·2 min read

A Midlands State University final-year Computer Science student accused of using malware to facilitate more than US$1.1 million in fraudulent transactions invo...

BREAKING:

A Midlands State University final-year Computer Science student accused of using malware to facilitate more than US$1.1 million in fraudulent transactions involving CABS has been denied bail.

Sabelo Malunga, 24, appeared before Harare regional magistrate Marehwanazvo Gofa facing cyber-related charges. The magistrate denied him bail, citing the seriousness of the allegations and the possibility that he could abscond.

The court also heard that some of Malunga’s alleged accomplices were still at large and were believed to be in South Africa.

Advertisement

The matter was remanded to September 21 for routine remand.

The State alleges that Malunga gained access to CABS systems while working as an Information Technology intern at the bank between November 2025 and February 23, 2026.

According to the prosecution, the alleged cyber breach was discovered in March and April after CABS detected suspicious transactions involving its VISA and ZIPIT platforms.

The court heard that on March 27, VISA flagged two suspicious international ATM transactions linked to CABS-issued debit cards. CABS subsequently blocked the affected accounts, but the bank had already suffered actual prejudice of US$925 679, according to the State.

The prosecution alleges that the money was transferred through several platforms and financial institutions, including EcoCash, InnBucks, CBZ and Ecobank.

Following the discovery, CABS engaged South African digital forensic company MWR to contain and eradicate the alleged malware and investigate the breach.

The forensic investigation allegedly linked Malunga to the cyberattack. The State alleges that on January 23, while at work and using a company-issued laptop, he downloaded an application called SUPREMO without authorisation.

He allegedly concealed the application within system files in an attempt to avoid detection.

Prosecutors allege that SUPREMO, a remote-access tool, enabled Malunga to gain remote access to CABS data and computer systems.

The State further alleges that after Malunga’s internship ended on February 23, he continued using the application to obtain unauthorised access to the bank’s systems and servers.

He is accused of installing malware that allegedly facilitated the unlawful authorisation of transactions, fraudulent ZIPIT transfers to Zimswitch, fictitious transactions routed to Ecobank and the generation of fake telegraphic transfers.

According to the prosecution, the combined transactions resulted in CABS suffering actual prejudice of US$1,136,179.

The court heard that none of the money had been recovered.

Malunga remains in custody following the denial of bail, with the matter set to return to court on September 21 for routine remand.

Advertisement

Comments

Leave a comment

Comments are moderated before appearing.

Advertisement

Next for you

Hand-picked stories you might have missed