September 12, 2026
Final Year MSU Student’s Cyber Heist Drains USD1.1m from Major Zim Bank

Final Year MSU Student’s Cyber Heist Drains USD1.1m from Major Zim Bank

0comments 2.44 mins read

-Year Student Allegedly Used Remote-Access Tool to Drain US$1.1m from Major Zimbabwean Bank

A Midlands State University Computer Science student has appeared in a Harare court, accused of orchestrating one of Zimbabwe’s most sophisticated cyber heists after allegedly using malware to steal more than US$1.1 million from one of the country’s largest financial institutions.

Sabelo Malunga, 24, appeared before regional magistrate Francis Mapfumo charged with hacking, and was remanded in custody pending a bail application scheduled for today.

The State, led by prosecutor Blessed Songozo, alleges that Malunga exploited privileged access gained during an IT internship at CABS between November last year and February this year to embed malicious code deep within the bank’s systems.

The breach only came to light in March, when VISA flagged two suspicious international ATM transactions linked to CABS-issued debit cards. By then, the bank had already suffered an actual prejudice of US$210,500, with nothing recovered from those transactions. But the true scale of the attack would only emerge weeks later.

On April 13, CABS’s internal IT team detected multiple malware infections on its servers during an ongoing investigation. Forensic analysis allegedly revealed that the malware was generating new ZIPIT transactions and injecting them directly into Zimswitch, the national payments switch, thereby bypassing the bank’s internal approval controls entirely.

A subsequent reconciliation exercise uncovered 1,911 fraudulent ZIPIT transactions worth US$925,679, routed to EcoCash, InnBucks, CBZ and Ecobank.

The combined prejudice from both the VISA and ZIPIT frauds stands at US$1,136,179, according to court documents. Nothing has been recovered to date.

The State alleges that Malunga’s digital fingerprints were identified after CABS engaged South African digital forensic firm MWR to contain the malware and investigate the breach.

The forensic report reportedly linked the student to the attack, pointing to a crucial piece of evidence: on January 23, while still employed and using a company-issued laptop, Malunga allegedly downloaded an application called SUPREMO without authorisation and concealed it within system files to evade detection.

SUPREMO is a remote-access tool that, according to prosecutors, gave Malunga persistent, surreptitious access to CABS’s data and core banking systems. Critically, the State alleges that even after his internship ended on February 23, Malunga continued using the application to maintain unauthorised access, installing malware that enabled the unlawful authorisation of transactions, fictitious ZIPIT transfers to Zimswitch, and the generation of fake telegraphic transfers.

The case has sent shockwaves through Zimbabwe’s banking sector, raising urgent questions about insider threats, intern access protocols, and the adequacy of endpoint monitoring in financial institutions.

For a student in his final year of study, the stakes could not be higher: if convicted, Malunga faces a lengthy prison sentence, and the US$1.1 million he allegedly siphoned remains unaccounted for.

Magistrate Mapfumo is expected to rule on bail today, but the broader industry conversation has already begun about how a single intern with a remote-access tool could bypass internal controls to the tune of over a million dollars—undetected for months.


Discover more from ZimCitizenNews

Subscribe to get the latest posts sent to your email.

Leave a Reply