About
Subscribe
  • Home
  • /
  • Malware
  • /
  • Cause of breach on SA’s supercomputer revealed

Cause of breach on SA’s supercomputer revealed

Simnikiwe Mzekandaba
By Simnikiwe Mzekandaba, IT in government editor
Johannesburg, 24 Aug 2026
The Centre of High Performance Computing’s Lengau supercomputer suffered a cyber security incident in late-May. (Image source: iStock)
The Centre of High Performance Computing’s Lengau supercomputer suffered a cyber security incident in late-May. (Image source: iStock)

The cyber breach on South Africa’s Lengau supercomputer was caused by “vulnerabilities associated with the legacy high-performance computing system”.

This is based on insights contained in a written Parliamentary reply by the Department of Science, Technology and Innovation (DSTI) minister, following the late-May cyber security incident on the Centre for High Performance Computing’s (CHPC’s) Lengau supercomputer.

The CHPC is national strategic research that advances high-performance computing in South Africa. It forms part of the pillars of the National Integrated Cyber Infrastructure System (NICIS) at the Council for Scientific and Industrial Research (CSIR).

In the written Parliamentary reply, DSTI minister professor Blade Nzimande said the CSIR, through the NICIS, confirmed that a cyber security incident affected parts of the Lengau high-performance computing environment at the end of May.

Nzimande was responding to MK MP Thembinkosi Mjadu, who enquired about the technical and failures that enabled the breach, accountability measures, as well as if independently audited cyber security upgrades have been implemented.

According to the minister, due to the legacy environment, some components are ageing, technically constrained, or are no longer fully supported by original vendors.

“Going forward, the existing escalation, reporting and cyber risk oversight arrangements will be strengthened to ensure faster response and executive visibility of cyber security incidents affecting strategic research infrastructure,” he replied.

Unveiled in 2016, the Lengau (‘cheetah’ in Setswana) is a petascale cluster supercomputer located at the CHPC. It features over 32 000 central processing unit cores, delivering peak petascale performance for local scientific and industrial research, and supports advanced workloads, like bioinformatics.

The cyber security breach on the national strategic research asset involved unauthorised access to certain components of the environment and the deployment of crypto-currency mining malware, according to the response.

“Immediately upon confirmation of the incident, containment measures were implemented, specialist technical support was engaged, and internal governance processes were initiated to determine the cause, extent, impact and appropriate remedial actions.

“It should be noted that the incident did not amount to a compromise of the entire national cyber infrastructure environment. The incident was confined to affected components within the high-performance computing environment and steps were taken to contain the unauthorised activity and protect the integrity of the broader service.”

The minister noted the CSIR has instituted an internal review and accountability process in accordance with applicable organisational policies, governance procedures and labour-related due processes.

He added that the NICIS has implemented a cyber security remediation and resilience programme for the CHPC environment, which includes immediate containment actions, as well as longer-term improvements to security architecture, monitoring, governance and assurance.

“The remedial measures include strengthened access controls, enhanced privileged-access management, account reviews, improved network segmentation, hardening of affected systems, improved vulnerability and patch-management processes and enhanced monitoring to detect abnormal compute workloads, suspicious authentication activity and other indicators of compromise.

“An independent team from the CSIR defence and security cluster’s cyber security specialists was engaged to support forensic analysis and technical remediation. The NICIS is also subjecting the implemented measures to independent cyber security assurance so that the effectiveness of the remediation actions can be validated and any residual risks can be addressed through a structured improvement plan.

“While no cyber security environment can be guaranteed to be immune from future cyber threats, we can advise that the measures implemented are intended to strengthen the resilience, integrity and security posture of the Lengau supercomputing environment as a strategic national asset.”

The Lengau supercomputer security breach occurred during a period that has been characterised by cyber breaches affecting South African organisations, underscoring an increasingly hostile digital threat landscape.

Businesses across sectors are facing a growing volume of ransomware attacks, phishing campaigns and data leaks, driven by more sophisticated cyber criminal tactics and expanding digital footprints.

Standard Bank, Liberty, Statistics South Africa, South African Police Service medical aid scheme Polmed and Wits University have disclosed their systems have been compromised by hackers in recent months.

Cyber security company Surfshark’s quarterly analysis of global data breaches shows South Africa ranks as the 42nd most breached country in the first quarter of this year.

Since 2004, South Africa has been ranked as the second most breached country in Africa, with 45.7 million compromised user accounts.

Share