{"id":651536,"date":"2026-06-02T17:02:56","date_gmt":"2026-06-02T15:02:56","guid":{"rendered":"https:\/\/mybroadband.co.za\/news\/?p=651536"},"modified":"2026-06-04T12:46:58","modified_gmt":"2026-06-04T10:46:58","slug":"south-africas-flagship-supercomputer-hacked","status":"publish","type":"post","link":"https:\/\/mybroadband.co.za\/news\/hardware\/651536-south-africas-flagship-supercomputer-hacked.html","title":{"rendered":"South Africa&#8217;s flagship supercomputer hacked"},"content":{"rendered":"\n<p>The CSIR\u2019s Centre for High Performance Computing (CHPC) has notified users of a serious security breach on its Lengau compute cluster, with user credentials and private keys likely compromised.<\/p>\n\n\n\n<p>Emails sent to users stated that the Lengau high-performance computing (HPC) cluster was taken offline after threat actors gained access and infected it with crypto mining malware.<\/p>\n\n\n\n<p>Lengau, which is Setswana for Cheetah, is a petascale system which was launched on 7 June 2016 and debuted 121<sup>st<\/sup> on the <a href=\"https:\/\/top500.org\/\">Top500<\/a> list of supercomputers.<\/p>\n\n\n\n<p>South Africa\u2019s flagship supercomputer consists of Dell servers powered by Intel processors, using FDR InfiniBand by Mellanox, and is managed by the Bright Cluster Manager.<\/p>\n\n\n\n<p>The cluster is capable of over a quadrillion (1,000 trillion) floating-point operations per second (FLOPS), also called a petaflop.<\/p>\n\n\n\n<p>The supercomputer has been upgraded substantially over the past 10 years, and while it achieved petaflop performance, it did not meet the CSIR\u2019s goal of expanding to 40,000 cores.<\/p>\n\n\n\n<p>It consists of 1,368 compute nodes with 32,832 cores, 5 large memory \u201cfat\u201d nodes, 9 GPU nodes, and 4 petabytes of storage using the Lustre parallel file system.<\/p>\n\n\n\n<p>Each standard node has 64GB or 128GB of memory and runs on a 24-core 2.6GHz Intel Xeon processor, while the fat nodes have 1TB of RAM with a 56-core 2.2GHz processor.<\/p>\n\n\n\n<p>The 9 GPU nodes feature a 36-core 2.2GHz Intel Xeon processor, 32GB of system memory, and an Nvidia V100 graphics card with 16GB or 32GB of video RAM.<\/p>\n\n\n\n<p>Lengau has a total memory capacity of 148.5TB, plus the additional 5TB from the fat nodes. It has a theoretical peak performance of 1.307 petaflops and achieved an Rmax of 1.029 petaflops in Linpack.<\/p>\n\n\n\n<p>NiceHash\u2019s profitability calculator indicated that although the 9 GPU nodes would only earn a modest R51 per day, the 1,368 compute cores could generate thousands of rands in Monero (XMR) per day.<\/p>\n\n\n\n<p>Monero is a cryptocurrency designed to be private and untraceable, making it a perfect option for hackers stealing computer time on South Africa\u2019s premier supercomputer.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Lengau hacked twice in one week<\/h2>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1200\" height=\"675\" src=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2026\/06\/Lengau-HPC-cluster-supercomputer-CSIR-CHPC-1200x675.jpg\" alt=\"\" class=\"wp-image-651544\" srcset=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2026\/06\/Lengau-HPC-cluster-supercomputer-CSIR-CHPC-1200x675.jpg 1200w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2026\/06\/Lengau-HPC-cluster-supercomputer-CSIR-CHPC-600x338.jpg 600w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2026\/06\/Lengau-HPC-cluster-supercomputer-CSIR-CHPC-768x432.jpg 768w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2026\/06\/Lengau-HPC-cluster-supercomputer-CSIR-CHPC-1536x864.jpg 1536w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2026\/06\/Lengau-HPC-cluster-supercomputer-CSIR-CHPC.jpg 1600w\" sizes=\"(max-width: 1200px) 100vw, 1200px\" \/><\/figure>\n\n\n\n<p>This is the second time in a week that Lengau was hacked. Users first noticed problems on 25 May 2026, when there were performance issues across the cluster.<\/p>\n\n\n\n<p>\u201cAn immediate shutdown of the nodes was performed, and all nodes were re-imaged to its original state before releasing to users again,\u201d the CHPC told users two days after the incident.<\/p>\n\n\n\n<p>\u201cThe CHPC is investigating the cause of the suspected compromise and will report further on this once more information is confirmed.\u201d<\/p>\n\n\n\n<p>However, another attack on Saturday, 30 May, forced the CHPC to take the supercomputer offline again. It initially estimated that it would take up to two days to investigate the breach.<\/p>\n\n\n\n<p>\u201cThis is to allow the CHPC to investigate the incident, secure the environment, and implement additional hardening measures to better protect the platform and user data,\u201d it said.<\/p>\n\n\n\n<p>That same day, the organisation told users that the Lengau HPC cluster remained isolated from incoming and outgoing Internet access to contain the breach.<\/p>\n\n\n\n<p>From its preliminary investigations, the CHPC said it could confirm that user cluster information, including usernames, passwords, private keys, and data stored on the filesystem, was likely compromised.<\/p>\n\n\n\n<p>\u201cThis thus represents a serious security breach, and the CHPC is focused on investigating this properly and to follow all regulatory processes required for such incidents,\u201d it said.<\/p>\n\n\n\n<p>\u201cThat includes reporting this to relevant privacy and POPIA entities within the CSIR and externally.\u201d<\/p>\n\n\n\n<p>The CHPC said the investigation to determine the cause and the steps needed to prevent another breach required the Lengau cluster to remain offline significantly longer than initially anticipated.<\/p>\n\n\n\n<p>\u201cAt the very least, it will remain offline for several days, but it can also be for a week or two,\u201d the CHPC said.<\/p>\n\n\n\n<p>As of Tuesday, 2 June 2026, Lengau remained offline, including the Lustre parallel file system, which meant user data was unavailable.<\/p>\n\n\n\n<p>\u201cAccess will only be restored once the file system has been fully restarted and reopened to users,\u201d the CHPC said.<\/p>\n\n\n\n<p>\u201cBased on current estimates, Lengau is expected to remain unavailable for the next 7 days until at least 8 June 2026, although this date may change depending on the progress of the recovery process.\u201d<\/p>\n\n\n\n<p>MyBroadband contacted the CSIR for comment on the security breach, but it had not provided feedback by the deadline.<\/p>\n\n\n\n<p>Following publication, the CSIR provided a statement assuring that there was no evidence that user research data had been compromised.<\/p>\n\n\n\n<p>\u201cMitigation measures were implemented without delay to address the unauthorised access, and additional security controls are being deployed to strengthen the environment,\u201d it said.<\/p>\n\n\n\n<p>\u201cWe plan to complete the investigation into this incident soon so that we can restore high-performance computing services to users as quickly and safely as possible.\u201d<\/p>\n\n\n\n<p>The CSIR also assured that the CHPC Lengau computing cluster was separate from the rest of the institution\u2019s Information and Communication Technology infrastructure.<\/p>\n\n\n\n<p>\u201cTherefore, the CSIR\u2019s own research data and business information systems were not affected by this breach.\u201d<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">Photo of one of Lengau\u2019s racks<\/h2>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"600\" height=\"800\" src=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2026\/06\/Lengau-full-rack-600x800.jpg\" alt=\"\" class=\"wp-image-651546\" srcset=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2026\/06\/Lengau-full-rack-600x800.jpg 600w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2026\/06\/Lengau-full-rack-300x400.jpg 300w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2026\/06\/Lengau-full-rack-768x1024.jpg 768w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2026\/06\/Lengau-full-rack-1152x1536.jpg 1152w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2026\/06\/Lengau-full-rack-1536x2048.jpg 1536w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2026\/06\/Lengau-full-rack.jpg 1600w\" sizes=\"(max-width: 600px) 100vw, 600px\" \/><\/figure>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n","protected":false},"excerpt":{"rendered":"<p>Hackers infiltrated South Africa&#8217;s top supercomputer and used it to mine cryptocurrency, the Centre for High Performance Computing has told users.<\/p>\n","protected":false},"author":15,"featured_media":651543,"comment_status":"open","ping_status":"closed","sticky":true,"template":"","format":"standard","meta":{"footnotes":""},"categories":[15,27],"tags":[20103,20101,37541],"class_list":["post-651536","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-hardware","category-security","tag-centre-for-high-performance-computing-chpc","tag-council-for-scientific-and-industrial-research-csir","tag-lengau-cluster"],"_links":{"self":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/651536"}],"collection":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/users\/15"}],"replies":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/comments?post=651536"}],"version-history":[{"count":8,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/651536\/revisions"}],"predecessor-version":[{"id":652019,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/651536\/revisions\/652019"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media\/651543"}],"wp:attachment":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media?parent=651536"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/categories?post=651536"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/tags?post=651536"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}