A 24-year-old Midlands State University final-year Computer Science student, Sabelo Malunga, has appeared in court accused of stealing more than US$1.1 million...
A 24-year-old Midlands State University final-year Computer Science student, Sabelo Malunga, has appeared in court accused of stealing more than US$1.1 million from CABS through an alleged malware attack on the bank’s computer systems.
Malunga is facing a hacking charge and was remanded in custody pending his bail application. The allegations against him have not yet been tested in court.
According to the State, Malunga gained access to CABS’ computer systems while working as an IT intern at the bank between November last year and February 23 this year.
Advertisement
Prosecutors allege that on January 23, while using a CABS-issued laptop, Malunga downloaded SUPREMO, a remote-access application, without authorisation. He allegedly concealed the application within system files in an attempt to prevent it from being detected.
The State alleges that the software subsequently provided access to CABS systems beyond what Malunga was authorised to use. Prosecutors further allege that he continued accessing the bank’s systems after his internship had ended.
According to the allegations, the malware enabled Malunga to bypass the bank’s internal controls and create fraudulent ZIPIT and VISA transactions. The alleged activity resulted in transactions being processed without the normal authorisation procedures.
The alleged cyberattack was discovered after VISA flagged two suspicious international ATM transactions on March 27. CABS responded by blocking the affected accounts, but the bank had allegedly already suffered a loss of US$210,500.
The investigation subsequently uncovered further alleged fraudulent transactions. On April 13, CABS’ IT team reportedly found multiple malware infections on the bank’s servers while investigating the security breach.
Investigators allegedly identified 1,911 fraudulent ZIPIT transactions with a combined value of US$925,679. According to the State, the funds were allegedly sent to accounts or platforms linked to EcoCash, InnBucks, CBZ and Ecobank.
The discovery prompted CABS to take further steps to establish how its systems had been compromised and to determine the extent of the alleged financial losses.
The bank later engaged South African digital forensics company MWR to investigate the incident and remove the malware from its systems. The forensic investigation allegedly linked Malunga to the cyberattack.
The State further alleges that the malware was used for several activities, including creating fraudulent transactions, bypassing authorisation systems and making fictitious transfers.
Prosecutors also allege that the system was used to generate fake telegraphic transfers as part of the fraudulent activity.
The alleged transactions involved different payment channels, including ZIPIT and VISA, with the State claiming that the malware provided a means of accessing systems and carrying out transactions without proper authorisation.
CABS is alleged to have suffered an actual financial loss of US$1,136,179 as a result of the alleged cyberattack.
The State further alleges that none of the money has been recovered so far. The alleged loss combines the amounts identified through the investigation, including the suspicious VISA transactions and the fraudulent ZIPIT transactions.
The case has brought attention to the risks faced by financial institutions from cybercrime and unauthorised access to computer systems. However, the allegations remain before the courts and no finding of guilt has been made against Malunga.
The State’s case centres on the period during which Malunga was working as an IT intern at CABS and the alleged continued access to the bank’s systems after his internship ended.
The prosecution will have to establish its allegations through the court process. Malunga remains an accused person and is presumed innocent unless proven guilty by a court of law.
The alleged use of a remote-access application is also central to the case. Prosecutors allege that SUPREMO was downloaded without authorisation and subsequently hidden within system files.
The State alleges that the application played a role in allowing access to CABS systems and facilitating the transactions under investigation.
The investigation also involved digital forensic analysis after CABS identified malware infections on its servers. The bank’s decision to engage MWR was part of efforts to investigate the source of the alleged attack and remove the malicious software.
The alleged financial loss of more than US$1.1 million makes the case significant, although the final amount and circumstances surrounding the transactions remain matters for the court to determine.
Malunga’s appearance before the court is the latest stage in the case. He was remanded in custody while awaiting his bail application.
The court will determine the next steps in the proceedings as the State presents its case and the accused exercises his rights through the legal process.
For now, the State alleges that Malunga exploited access obtained during his time as an IT intern, installed unauthorised remote-access software and later used the compromised systems to carry out fraudulent transactions.
CABS has reportedly recovered no money from the alleged US$1,136,179 loss at this stage.
The allegations will now be tested through the judicial process, with further proceedings expected to determine how the case proceeds.



