THE US$1.1 MILLION CABS HEIST: How an MSU Intern Allegedly Used a Hidden Backdoor to Steal Millions

THE US$1.1 MILLION INSIDE JOB: How a 24-Year-Old MSU Intern Allegedly Hacked CABS in Massive Cybertheft Scandal

Editorial Overview: It is arguably one of the most sophisticated and brazen digital bank heists in recent Zimbabwean history. Central Africa Building Society (CABS) has been rocked by a staggering US$1.1 million cybertheft. The alleged mastermind? A 24-year-old final-year Computer Science student from Midlands State University (MSU). Sabelo Malunga is accused of exploiting his IT internship to embed deep-cover malware into the bank's servers, allowing him to remotely siphon millions into various mobile wallets and rival banks long after his contract ended. As Malunga fights for bail today, Sona Headlines unpacks the anatomy of the ultimate inside job.

In the digital age, bank robbers no longer wear ski masks or carry shotguns—they wear lanyards, sit in cubicles, and weaponize lines of code. This is the chilling reality facing the Central Africa Building Society (CABS) following the discovery of a catastrophic security breach that hemorrhaged over US$1.1 million (roughly R18.7 million).

Hacker typing on a laptop with green binary code representing the CABS cybertheft
THE DIGITAL HEIST: A 24-year-old IT intern allegedly weaponized his access to the CABS banking system, deploying concealed remote-access tools to authorize thousands of fraudulent transactions.

The suspect, Sabelo Malunga, appeared before Harare regional magistrate Francis Mapfumo facing severe hacking and fraud charges. Remanded in custody, Malunga is scheduled to make his highly anticipated bail application today, Monday, 31 August 2026. The State, led by prosecutor Blessed Songozo, alleges that the young IT intern systematically compromised the bank's digital fortress, maintaining illegal remote access to orchestrate a staggering wave of fraudulent ZIPIT transfers and international ATM withdrawals.

1. The Trojan Horse: Planting the Seed

The most dangerous threats to corporate cybersecurity are often those who already possess the keys to the building. Malunga’s internship provided the perfect cover.


Sabelo Malunga was engaged as an Information Technology intern at CABS from November 2025 to February 23, 2026. According to the State, he used this privileged position to lay the groundwork for a massive cyberattack.

Installing "SUPREMO" The prosecution alleges that on January 23, 2026—a month before his internship ended—Malunga unlawfully downloaded a remote-access application called SUPREMO onto a company-issued laptop. Knowing the bank's security protocols would flag unauthorized software, he allegedly concealed the program deep within the system files to evade detection.
The Backdoor Kept Open SUPREMO provided Malunga with unrestricted, remote capabilities. The State contends that even after his internship formally concluded on February 23, the concealed backdoor allowed him to quietly access CABS’ banking systems from the outside, bypassing firewalls and authentication measures.

2. Visa Sounds the Alarm

For weeks, the cybertheft went entirely undetected by local systems. It took an international payment giant to spot the anomaly.

The heist first surfaced on the radar of investigators on March 27, 2026, when Visa flagged highly suspicious international ATM transactions involving CABS-issued debit cards.

US$210,500 Gone While CABS rushed to block the affected accounts immediately upon receiving Visa's alert, the damage had already been done. The bank had suffered an actual prejudice of US$210,500 (approximately R3.4 million) from these specific ATM transactions alone. The court heard that none of this initial stolen sum has been recovered.

3. Injecting Ghosts into Zimswitch

Following the Visa alert, CABS launched a deeper internal investigation on April 13, uncovering the true, terrifying scope of the malware infection.

The internal audit discovered that the SUPREMO backdoor was just the beginning. The malware was actively being used to manipulate the local interbank transfer system.

Direct Injection into Zimswitch The State alleges that the malware was programmed to create fraudulent ZIPIT transactions and inject them directly into Zimswitch. By doing so, the malicious code completely bypassed CABS’ internal controls and authorization protocols, making the transfers appear legitimate to receiving banks.
1,911 Fraudulent Transactions A subsequent, painstaking reconciliation revealed the magnitude of the theft. The system had processed 1,911 fraudulent ZIPIT transactions, valued at a staggering US$925,679 (about R15 million). These stolen funds were systematically scattered across multiple financial platforms, heavily targeting EcoCash, InnBucks, CBZ, and Ecobank to launder the money quickly.

4. The South African Forensics and The Court Battle

Realizing the local system was entirely compromised, CABS engaged international digital mercenaries to hunt down the source of the breach.

CABS hired MWR, a prominent South African digital forensics company, to contain the suspected malware, halt the financial bleeding, and determine the origin of the compromise.

Connecting the Digital Footprints During the forensic examination, investigators allegedly found undeniable digital evidence directly linking the 24-year-old Malunga to the cyberattack. The timeline of the SUPREMO installation, the nature of the malware injection, and the fictitious transactions routed through Ecobank integrations all pointed back to the former intern.
Awaiting Bail Today Malunga remains in custody following his initial appearance before Harare regional magistrate Francis Mapfumo. As of today, Monday, 31 August 2026, he is set to make his formal bail application. The State will likely heavily oppose bail, citing the vast amount of unrecovered funds—a total actual prejudice of US$1,136,179.
SONA HEADLINES EDITORIAL VERDICT

The Ultimate Wake-Up Call for Zimbabwean Banks

The staggering US$1.1 million cybertheft at CABS is a terrifying indictment of the vulnerabilities lurking within Zimbabwe's financial institutions. When a 24-year-old university intern can allegedly embed remote-access software into a national bank's servers, hide it in plain sight, and siphon over a million dollars into mobile wallets like EcoCash and InnBucks without triggering immediate local alarms, the entire sector needs to urgently re-evaluate its internal threat protocols.

Banks spend millions fortifying their external firewalls against international hackers, but this heist proves that the most devastating breaches often come from the inside. The fact that the initial detection came from Visa—not CABS' own internal monitoring systems—highlights a lethal blind spot in the real-time tracking of Zimswitch and ZIPIT injections.

As Sabelo Malunga fights for bail today, the whereabouts of the US$1,136,179 remains a mystery. With zero funds recovered so far, this case is no longer just about prosecuting a rogue student; it is a glaring warning to every bank in the country. The call is coming from inside the house, and the cost of ignoring it is in the millions.

© Sona Headlines | National News & Cyber Crime Desk

Sona Headlines Community

What Do You Think? Join the Conversation

Have an opinion on this Zimbabwe News story, Breaking News, Politics, Business, Entertainment, Sport, or Community Affairs? Share your thoughts, ask questions or add your perspective below and join the Sona Headlines community.

Zimbabwe News Latest Stories Public Opinion Share Your Views Community Voices Join the Discussion

Latest Stories from Sona Headlines

Loading latest stories...

#buttons=(Ok, Go it!) #days=(20)

Our website uses cookies to enhance your experience. Check Now
Ok, Go it!
Chat With An Expert:
WhatsApp David (Solar Sales) WhatsApp Ropafadzo (Solar Sales) WhatsApp Shaun (Solar Technician) WhatsApp Misheck (Solar Technician)
Solar & Borehole Contacts
ADVERTISEMENT