South Africa’s flagship supercomputer hacked
The CSIR’s Centre for High Performance Computing (CHPC) has notified users of a serious security breach on its Lengau compute cluster, with user credentials and private keys likely compromised.
Emails sent to users stated that the Lengau high-performance computing (HPC) cluster was taken offline after threat actors gained access and infected it with crypto mining malware.
Lengau, which is Setswana for Cheetah, is a petascale system which was launched on 7 June 2016 and debuted 121st on the Top500 list of supercomputers.
South Africa’s flagship supercomputer consists of Dell servers powered by Intel processors, using FDR InfiniBand by Mellanox, and is managed by the Bright Cluster Manager.
The cluster is capable of over a quadrillion (1,000 trillion) floating-point operations per second (FLOPS), also called a petaflop.
The supercomputer has been upgraded substantially over the past 10 years, and while it achieved petaflop performance, it did not meet the CSIR’s goal of expanding to 40,000 cores.
It consists of 1,368 compute nodes with 32,832 cores, 5 large memory “fat” nodes, 9 GPU nodes, and 4 petabytes of storage using the Lustre parallel file system.
Each standard node has 64GB or 128GB of memory and runs on a 24-core 2.6GHz Intel Xeon processor, while the fat nodes have 1TB of RAM with a 56-core 2.2GHz processor.
The 9 GPU nodes feature a 36-core 2.2GHz Intel Xeon processor, 32GB of system memory, and an Nvidia V100 graphics card with 16GB or 32GB of video RAM.
Lengau has a total memory capacity of 148.5TB, plus the additional 5TB from the fat nodes. It has a theoretical peak performance of 1.307 petaflops and achieved an Rmax of 1.029 petaflops in Linpack.
NiceHash’s profitability calculator indicated that although the 9 GPU nodes would only earn a modest R51 per day, the 1,368 compute cores could generate thousands of rands in Monero (XMR) per day.
Monero is a cryptocurrency designed to be private and untraceable, making it a perfect option for hackers stealing computer time on South Africa’s premier supercomputer.
Lengau hacked twice in one week

This is the second time in a week that Lengau was hacked. Users first noticed problems on 25 May 2026, when there were performance issues across the cluster.
“An immediate shutdown of the nodes was performed, and all nodes were re-imaged to its original state before releasing to users again,” the CHPC told users two days after the incident.
“The CHPC is investigating the cause of the suspected compromise and will report further on this once more information is confirmed.”
However, another attack on Saturday, 30 May, forced the CHPC to take the supercomputer offline again. It initially estimated that it would take up to two days to investigate the breach.
“This is to allow the CHPC to investigate the incident, secure the environment, and implement additional hardening measures to better protect the platform and user data,” it said.
That same day, the organisation told users that the Lengau HPC cluster remained isolated from incoming and outgoing Internet access to contain the breach.
From its preliminary investigations, the CHPC said it could confirm that user cluster information, including usernames, passwords, private keys, and data stored on the filesystem, was likely compromised.
“This thus represents a serious security breach, and the CHPC is focused on investigating this properly and to follow all regulatory processes required for such incidents,” it said.
“That includes reporting this to relevant privacy and POPIA entities within the CSIR and externally.”
The CHPC said the investigation to determine the cause and the steps needed to prevent another breach required the Lengau cluster to remain offline significantly longer than initially anticipated.
“At the very least, it will remain offline for several days, but it can also be for a week or two,” the CHPC said.
As of Tuesday, 2 June 2026, Lengau remained offline, including the Lustre parallel file system, which meant user data was unavailable.
“Access will only be restored once the file system has been fully restarted and reopened to users,” the CHPC said.
“Based on current estimates, Lengau is expected to remain unavailable for the next 7 days until at least 8 June 2026, although this date may change depending on the progress of the recovery process.”
MyBroadband contacted the CSIR for comment on the security breach, but it had not provided feedback by the deadline.
Following publication, the CSIR provided a statement assuring that there was no evidence that user research data had been compromised.
“Mitigation measures were implemented without delay to address the unauthorised access, and additional security controls are being deployed to strengthen the environment,” it said.
“We plan to complete the investigation into this incident soon so that we can restore high-performance computing services to users as quickly and safely as possible.”
The CSIR also assured that the CHPC Lengau computing cluster was separate from the rest of the institution’s Information and Communication Technology infrastructure.
“Therefore, the CSIR’s own research data and business information systems were not affected by this breach.”
Photo of one of Lengau’s racks
