A routine investigation into suspicious cash withdrawals has opened the door to one of the most serious alleged cyber breaches involving a Zimbabwean financial institution, with a South African digital-forensics firm eventually brought in to help uncover what happened inside Central Africa Building Society (CABS).
At the centre of the case is Sabelo Malunga, a 24-year-old Midlands State University final-year computer science student, who appeared before the Harare Magistrates’ Court facing allegations of hacking the bank’s systems and stealing more than US$1.1 million.
Malunga was remanded in custody until Thursday for a bail hearing. He was not required to enter a plea.
The alleged breach began quietly, prosecutors say, while Malunga was completing an internship at CABS between November last year and February 23 this year. On January 23, he allegedly installed SUPREMO, a remote-access application, on a laptop issued to him by the bank.
The software was allegedly concealed among ordinary system files, allowing continued access to the bank’s internal network even after Malunga’s attachment had ended.
For weeks, the alleged intrusion went undetected. The first warning came in March, when VISA flagged two suspicious international ATM transactions involving CABS-issued debit cards. The transactions left the bank facing an immediate loss of US$210,500, with the money yet to be recovered.
What followed reportedly revealed a far wider compromise.
An internal investigation launched on April 13 uncovered multiple malware infections on CABS servers. The malicious programs were allegedly used to evade internal safeguards, inject fraudulent transactions into the Zimswitch system and create unauthorised telegraphic transfers and Ecobank integrations.
The scale of the suspected operation only became clear after a detailed audit. Investigators identified 1,911 fraudulent ZIPIT transactions worth US$925,679, with funds allegedly sent to a network of mobile wallets and bank accounts, including EcoCash, InnBucks, CBZ and Ecobank.
As the trail grew colder and the extent of the intrusion became more difficult to establish, CABS turned to MWR, a South African digital-forensics firm, for help containing the breach and tracing the person behind it.
The decision to bring in specialists from across the border marked a dramatic escalation in the bank’s response. Their forensic examination allegedly connected Malunga to the remote-access software and the wider attack, prosecutors said.
By the time the investigation was completed, the bank’s actual loss had been placed at US$1,136,179. No money had been recovered by the time Malunga appeared in court.
The case remains before the courts, and the allegations have not yet been tested at trial.
For comments, Feedback and Opinions do get in touch with our editor on WhatsApp: +44 7949 297606 or Email: editor@thezimbabwetimes.co.zw.