
Sabelo Malunga: Charged in US$1.1M CABS Cyber Fraud
Summary
- Sabelo Malunga, a 24-year-old Computer Science student, is accused of orchestrating a US$1.1 million cyber fraud against CABS bank.
- The alleged scheme involved using malware and a remote-access tool, SUPREMO, to execute fraudulent VISA and ZIPIT transactions.
- Malunga reportedly gained access during his IT internship at CABS, continuing to exploit systems after his employment ended.
- The fraud led to an actual prejudice of US$1,136,179 for CABS, with funds allegedly diverted to various mobile money and bank accounts.
- A forensic report by South African firm MWR linked Malunga to the cyberattack, leading to his appearance before a Harare magistrate on hacking charges.
Allegations of Major Cyber Fraud at CABS
The prosecution, led by Mr Blessed Songozo, contends that Malunga exploited access privileges gained during his tenure as an Information Technology intern at CABS.
A final-year Computer Science student from Midlands State University, Sabelo Malunga, aged 24, has been brought before Harare regional magistrate Francis Mapfumo. He faces charges of hacking in connection with an alleged cyber fraud scheme that reportedly siphoned more than US$1.1 million from CABS bank through fraudulent VISA and ZIPIT transactions. Malunga has been remanded in custody, awaiting the ruling on his bail application to determine his temporary release.
The prosecution, led by Mr Blessed Songozo, contends that Malunga exploited access privileges gained during his tenure as an Information Technology intern at CABS. His internship reportedly ran from November of the previous year until February 23 of the current year. The alleged cyber breach came to light in March and April when the bank's systems flagged suspicious activity across its VISA and ZIPIT platforms, initiating an internal investigation into the significant financial discrepancies. This Sabelo Malunga CABS cyber fraud case highlights potential vulnerabilities in financial institution security protocols.
Unraveling the Modus Operandi
The State's case details how the alleged fraud unfolded, beginning with two suspicious international ATM transactions flagged by VISA on March 27, involving CABS-issued debit cards. Although CABS promptly blocked the affected accounts, the bank had already incurred an actual loss of US$210,500 from these transactions, with no funds recovered to date. Further investigation by the CABS IT team on April 13 allegedly uncovered multiple malware infections on the bank's servers, indicating a more systemic compromise.
Analysis of the malware revealed its sophisticated use: it was reportedly employed to generate ZIPIT transactions and directly inject them into Zimswitch, effectively bypassing CABS' internal control mechanisms. A subsequent reconciliation effort identified 1,911 fraudulent ZIPIT transactions, totaling US$925,679. These funds were allegedly directed to various accounts held at EcoCash, InnBucks, CBZ, and Ecobank. To address the breach, CABS engaged MWR, a South African digital forensics firm, tasked with containing and removing the malware and conducting a thorough investigation. The forensic report subsequently linked Malunga to the cyberattack, providing crucial evidence for the prosecution.
Remote Access and Legal Ramifications
A key element of the prosecution's argument centers on the alleged unauthorized use of a remote-access tool. On January 23, while still an intern at CABS, Malunga is accused of downloading an application called SUPREMO onto a company-issued laptop without authorization. He allegedly concealed this application within system files to evade detection. Prosecutors assert that SUPREMO, a remote-access tool, enabled Malunga to remotely access CABS' data and computer systems. The allegations further state that Malunga continued to utilize this application to gain unauthorized entry into the bank's systems and servers even after his internship concluded on February 23.
Malunga is accused of installing malware that facilitated several illicit activities, including the unauthorized approval of transactions, fraudulent ZIPIT transfers via Zimswitch, fictitious transactions routed to Ecobank through an integration system, and the creation of fake telegraphic transfers. The cumulative effect of these alleged actions resulted in CABS suffering an actual prejudice amounting to US$1,136,179. This case, involving a Midlands State University student and sophisticated CABS bank hacking in Zimbabwe, underscores the significant financial and reputational risks posed by insider-enabled cyber threats.
Practical Implications
Financial institutions and compliance officers should assess their internal IT security, access controls for former employees, and malware detection capabilities, particularly regarding remote access tools and payment platform integrations, to prevent similar insider-enabled cyber fraud.
Source
Source: Original reporting via 263Chat
How does this affect you?
Get an AI analysis of this article grounded in your jurisdictions, practice areas, and any policy documents you've uploaded to Wansom.
Finish Reading the Full Story and the Expert Analysis.
Wansom is AI and can make mistakes.
