Centre for High Performance Computer
Incident posture
Linked entities
- Victim
- Centre for High Performance Computer
- Threat actors
- 0 actors
- Sources
- 1 source
Timeline
Summary
The Lengau supercomputer, hosted by the Centre for High Performance Computer in Cape Town, was compromised and used to run cryptocurrency‑mining malware, causing significant downtime and exposing user data. Following the breach, the centre implemented a remediation and resilience programme that tightened access controls, improved network segmentation and added monitoring for abnormal workloads, while the Council of Scientific and Industrial Research began an internal review to assess possible staff involvement. The incident highlighted budget pressures on the national high‑performance computing infrastructure, with the science minister noting that current allocations are insufficient to sustain operations and planned expansions.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
In May, the Lengau supercomputer hosted by the Centre for High Performance Computer in Cape Town was hacked and used to run cryptocurrency-mining malware. The incident caused significant system downtime and placed user data at risk. The Department of Science, Technology and Innovation had ring-fenced over 292 million rand for the National Integrated Cyber Infrastructure System (NICIS) for the 2026-27 financial year. Treasury budget cuts, escalating operational costs and shifting exchange rates placed this budget under pressure, as admitted by Minister Blade Nzimande in a written parliamentary response dated 19 August 2026. He stated that the current allocations were inadequate to sustain both operations and planned expansion targets.
Following the attack, NICIS implemented a remediation and resilience programme that included strengthening access controls, improving network segmentation and enhanced monitoring of abnormal computing workloads. The Council of Scientific and Industrial Research, which hosts and implements NICIS, commenced an internal review to determine whether staff errors or wrongdoing contributed to the incident. The minister noted that it would not be appropriate at that stage to disclose or pre‑empt findings against specific individuals. To address longer‑term vulnerabilities, the department confirmed investment in renewing ageing supercomputing infrastructure to maintain South Africa’s scientific competitiveness and respond to increasing demand from the research and innovation community. The CSIR had already acquired and taken delivery of a new four‑petaflop high‑performance computing system. The first phase is expected to go live by the end of November and the completed system upgrade expected by the end of March the following year. The phased deployment aims to maintain continuity of national research‑computing services while the new platform is commissioned and to reduce reliance on the legacy Lengau environment.
The hack caused significant system downtime and placed user data at risk. Cybercrime is a growing problem across Africa, with financial losses from such activities more than doubling since 2024, according to Interpol. Outdated systems, underfunded cybersecurity units and a pattern of underreporting contribute to making digital infrastructure vulnerable, with South Africa identified as an emerging crime hotspot. The minister’s admission that allocations are inadequate reflects the broader pressure on the national high‑performance computing infrastructure.
Sources
Sources available to members: 1 source.