Hurumende

Midlands State University Student Accused of Siphoning US$1.1m From CABS

A 24-year-old Midlands State University final-year Computer Science student has appeared in court facing allegations of hacking into CABS systems and using malware to facilitate fraudulent VISA and ZIPIT transactions worth more than US$1.1 million.

Sabelo Malunga appeared before Harare regional magistrate Francis Mapfumo on allegations of hacking. He was remanded in custody to today for a bail hearing.

The State, led by Mr Blessed Songozo, alleges that Malunga gained access to CABS systems while working as an Information Technology intern at the bank between November last year and February 23 this year.

The alleged breach was uncovered in March and April after the bank detected unusual transactions involving its VISA and ZIPIT platforms.

According to the State, the matter first came to light on March 27 when VISA flagged two suspicious international ATM transactions involving CABS-issued debit cards.

CABS reportedly blocked the affected accounts, but the transactions had already resulted in a loss of US$210,500.

The money was allegedly not recovered.

Malware Discovered

The court heard that on April 13, CABS’ IT department discovered several malware infections on the bank’s computer servers during an internal investigation.

Further analysis allegedly showed that the malware was being used to generate ZIPIT transactions and inject them directly into Zimswitch, effectively bypassing the bank’s internal security controls.

A subsequent reconciliation reportedly identified 1,911 fraudulent ZIPIT transactions with a combined value of US$925,679.

The transactions were allegedly directed to EcoCash, InnBucks, CBZ and Ecobank.

The State said CABS subsequently engaged South African digital forensic company MWR to contain the suspected cyberattack, remove the malware and investigate how the breach occurred.

According to the forensic investigation, Malunga was allegedly connected to the attack.

Remote Access Tool Allegedly Used

The court heard that on January 23, while still working at CABS, Malunga allegedly used a company-issued laptop to download an application called SUPREMO without authorisation.

The prosecution alleges that he concealed the application within system files to prevent it from being detected.

SUPREMO is a remote-access tool which the State alleges gave Malunga the ability to access CABS’ systems and information remotely.

Investigators further allege that Malunga continued accessing the bank’s systems after his internship ended on February 23.

US$1.1m Alleged Loss

The prosecution alleges that Malunga installed malware that allowed fraudulent transactions to be authorised and processed without going through the bank’s normal controls.

He is also accused of facilitating unauthorised ZIPIT transfers through Zimswitch, creating fictitious transactions routed to Ecobank through an integration system and generating fraudulent telegraphic transfers.

According to the State, the various transactions resulted in CABS suffering an actual prejudice of US$1,136,179.

The money has reportedly not been recovered.

Malunga is yet to plead to the allegations, which remain before the court.

Exit mobile version