Crime

MSU fraudster student who siphoned US$1,1 mln denied bail

By Courts Reporter

Sabelo Malunga, a 24-year-old final-year Computer Science student at Midlands State University, has been denied bail over allegations of using malware to steal over US$1.1 million from Central Africa Building Society (CABS).

The alleged theft occurred during and after his internship at CABS, where he reportedly installed the remote-access tool SUPREMO to access and manipulate the bank’s systems.

Investigations began after unusual international ATM transactions were flagged by VISA in March 2026. Forensic analysis uncovered nearly 1,911 fraudulent ZIPIT transactions totaling about US$925,679, with funds moved through various banks and mobile money platforms.

The court cited the seriousness of the charges and the risk of flight, especially since some alleged accomplices remain at large, possibly in South Africa.

Malunga remains in custody as the case proceeds, with the next hearing set for September 21. The stolen money has not been recovered, highlighting significant cyber risks in banking systems.

The State’s case is that Malunga’s access began with an application installed on a CABS-issued laptop. On January 23, while he was still working at the bank, he allegedly downloaded a programme known as SUPREMO without authorisation.

SUPREMO is a remote-access application. Prosecutors allege that Malunga concealed it among the laptop’s system files in an attempt to prevent the software from being detected. The application allegedly gave him a way to connect remotely to CABS’ data and computer systems.

The alleged access did not end when the internship was completed. Prosecutors say Malunga continued using the application after February 23 and used the connection to interfere with the bank’s servers and transaction systems. The State further alleges that malware was installed to automate or assist the creation and approval of unauthorised payments.

CABS later engaged MWR, a South African digital-forensics company, to contain and remove the malware and investigate how the intrusion had taken place. The forensic work examined the affected systems, the suspicious transactions and the routes through which the money had allegedly been transferred.

The investigation allegedly linked Malunga to the attack. The State is relying on the forensic findings as it pursues the case against him, while the court has also been told that other suspected participants remain outside Zimbabwe.

The alleged accomplices’ whereabouts became a significant issue during the bail hearing. Some are believed to have fled to South Africa, and the court considered the possibility that Malunga could also leave the country if released. The court’s decision means he will remain in custody as investigators and prosecutors continue with the case.

The alleged scheme affected several layers of the banking and payments infrastructure. VISA’s warning concerned international ATM activity, while the later investigation focused on ZIPIT transactions and transfers injected into Zimswitch. Other transactions allegedly passed through mobile-money platforms and accounts connected to banks including CBZ and Ecobank.

Related Articles

Leave a Reply

Back to top button