Victoria Falls A-Level Student Uses Cybersecurity Project to Warn Zimbabweans About Phishing

A Lower Sixth student from Mosi-Oa-Tunya High School in Victoria Falls has used an A-level cybersecurity project to demonstrate how easily people can be tricked into handing over sensitive financial information to fake websites and applications.

Takunda Makoni’s project focuses on phishing, a long-established form of cybercrime in which criminals impersonate legitimate organisations in an attempt to obtain information such as usernames, passwords and other account credentials.

Rather than uncovering a vulnerability in a particular bank or mobile-money service, the project demonstrates something arguably more useful for ordinary users: even a secure financial platform cannot protect someone who is persuaded to enter their credentials into a convincing imitation.

As part of the project, Takunda created a controlled demonstration showing how a fraudulent interface could imitate the appearance of a legitimate financial service. Testing was conducted with authorised participants who had agreed to take part in the exercise.

The demonstration illustrates how a victim might encounter what appears to be a familiar login page, enter their details and unknowingly provide those details to somebody else.

This type of attack is not new, nor is it unique to Zimbabwe. Phishing has been used around the world for years to target users of banks, mobile-money services, email accounts and social-media platforms. However, Takunda’s project provides a useful reminder of how the attack works and why awareness remains important.

The lesson is particularly relevant as Zimbabweans increasingly use mobile phones for banking, payments and other financial transactions.

Takunda also considered the potential effect of artificial intelligence on online fraud. AI tools can make it easier to produce convincing text, images and digital interfaces, potentially making fraudulent messages and websites more difficult for inexperienced users to recognise.

For consumers, the basic precautions remain important. Users should be suspicious of unexpected links requesting account information, check that they are using an organisation’s genuine website or official application, avoid installing applications from unknown sources, and never provide passwords or security information simply because a message appears urgent or convincing.

The most interesting aspect of Takunda’s work may therefore not be the discovery of a new cybersecurity threat, but the fact that a secondary-school student has taken an established problem and turned it into a practical demonstration of how social engineering works.

For an A-level project, that is a worthwhile exercise. It combines computing with a problem that affects ordinary people and, perhaps more importantly, encourages young Zimbabweans to think not simply as consumers of technology but as people capable of understanding how it works and where its risks lie.

Takunda says he hopes the project will encourage greater awareness of phishing and the importance of protecting personal and financial information online.

His demonstration leaves users with a simple message: sometimes the weakness criminals exploit is not the banking system itself, but the trust of the person sitting in front of the screen.