Background

CABS was established on 6 July 1949 and is Zimbabwe's largest building society, wholly owned by Old Mutual Zimbabwe.

Source
Worth Knowing

SUPREMO, the tool at the centre of the case, is not custom-built malware. It is commercial remote-desktop software made by the Italian company Nanosystems, first released in 2013 and marketed for everyday IT support.

Source
Worth Knowing

ZIPIT, the payment rail the fraud allegedly ran through, was launched by Zimswitch in 2012 and lets any customer send money instantly to any other ZIPIT-ready bank or mobile wallet in Zimbabwe.

Source
Worth Knowing

Zimswitch, the switch the fraudulent ZIPIT transfers were allegedly injected into, was founded in 1994 by five banks and now connects roughly two dozen member institutions across the country.

Source

A final-year Computer Science student at Midlands State University is fighting a hacking charge over what prosecutors describe as one of the more brazen insider cyberattacks in Zimbabwean banking history, and the case has just taken a turn against him.

Sabelo Malunga, 24, was denied bail on 9 September by Harare regional magistrate Marehwanazvo Gofa, who cited the seriousness of the allegations and the risk that he could abscond. She also noted that some of his alleged accomplices are believed to still be in South Africa, a detail that reframes this from a lone-student story into something with a wider network attached. Malunga remains in custody and is due back in court on 21 September for routine remand.

What he's accused of doing

According to the National Prosecuting Authority, Malunga was working as an Information Technology intern at CABS between November 2025 and 23 February 2026. The State alleges that on 23 January, while on duty and using a CABS-issued laptop, he downloaded SUPREMO, a remote-access application, without authorisation, then hid it among the machine's system files to keep it from being noticed.

SUPREMO itself isn't exotic. It's ordinary, commercially available remote-desktop software built for IT support teams, the kind of tool help desks use every day to log into a colleague's machine and fix a problem remotely. The allegation isn't that Malunga built something sophisticated from scratch, it's that he repurposed an everyday support tool into a backdoor, and that CABS' laptop and access controls didn't stop him doing it.

Prosecutors say Malunga kept using that remote access after his internship formally ended, allegedly deploying malware that let him authorise transactions without permission, inject fraudulent ZIPIT transfers directly into the Zimswitch network, route fictitious transactions to Ecobank through a systems integration, and generate fake telegraphic transfers. A bank reconciliation is alleged to have turned up 1,911 fraudulent ZIPIT transactions worth US$925,679, sent out to EcoCash, InnBucks, CBZ and Ecobank. CABS' total alleged loss stands at US$1,136,179, and none of it has been recovered.

How it actually came to light

The detail that stands out most isn't the size of the alleged theft, it's who caught it first. CABS' own internal monitoring didn't flag the breach. VISA did, after spotting two suspicious international ATM transactions linked to CABS-issued debit cards on 27 March. That external flag is what triggered CABS' own investigation in March and April, well over a month after Malunga's internship had ended and, on the State's own account, well after the alleged fraud had been running.

Once CABS started digging, it brought in the South African digital forensics firm MWR to contain and remove the malware and reconstruct what had happened. It's that forensic report, prosecutors say, that links Malunga to the intrusion.

An inside job, not an outside hack

What separates this case from a typical "bank hacked" headline is that nobody broke in from outside. Malunga, on the State's version of events, was handed legitimate access as part of a normal internship, at a bank that runs mortgage loans, salary-based lending and corporate accounts for hundreds of thousands of Zimbabweans. The alleged crime isn't breaching a perimeter, it's what happened after his contract ended and, allegedly, nobody closed the door behind him.

That raises an uncomfortable question for CABS and for every financial institution that takes on IT interns and attachment students: what actually happens to a company laptop, its access credentials and any software installed on it, the day an intern's contract lapses? On the facts as alleged, whatever CABS' offboarding process looked like, it didn't stop remote access from continuing for weeks afterwards.

What happens next

Malunga has not yet been asked to plead, and the allegations remain exactly that: allegations, untested in court. His lawyer is representing him after an earlier appearance where he wasn't legally represented, and the State, led by prosecutors Blessed Songozo and Lawrence Gangarahwe at different hearings, has opposed bail throughout.

The case returns to court on 21 September for routine remand. Two threads are worth watching from here: whether the alleged accomplices reportedly in South Africa are ever brought back to face charges, and whether CABS recovers any of the US$1.1 million, none of which has surfaced so far despite the money allegedly being traceable to named mobile money and banking platforms.

Sources

Share
R
Written by

Rufaro