South Africa's flagship supercomputer was hacked twice in one week. This is what that means for your business.

By Ubuntu Guard Cyber | 3 June 2026

South Africa's most powerful supercomputer, the CSIR's Lengau system, was compromised twice in five days and taken offline indefinitely on 2 June 2026 after threat actors installed crypto mining malware and exfiltrated thousands of researcher credentials. If your business contracts research work, uses academic partners, or relies on any government research outputs, your supply chain just became a question mark.

What happened, and how it works

The Centre for High Performance Computing (CHPC), which operates Lengau for the CSIR, notified users on 27 May that the supercomputer had been taken offline after a suspected breach on 25 May. The CHPC reimaged all nodes and released the system back to researchers. Four days later, on 30 May, threat actors breached the system again. This time the CHPC confirmed what they suspected: usernames, passwords, private keys, and data stored on the filesystem had been compromised. Lengau went offline and did not come back online.

Lengau is a petascale system with 1,368 compute nodes, 32,832 cores, and 5 petabytes of storage. It runs research workloads for universities, government departments, and private companies across the country. Threat actors infected it with Monero mining malware, a cryptocurrency designed to be private and untraceable. The 1,368 standard compute cores alone could generate thousands of rands per day in mining revenue, according to NiceHash calculations cited by MyBroadband. The attackers were farming processing time on state infrastructure while the CHPC worked to understand how they had gotten in.

The CHPC has not yet identified the initial entry vector. The preliminary assessment is that user credentials stored on the system, or exposed through it, were the likely compromise point. That means every researcher, developer, and systems administrator with credentials on Lengau now has to assume those credentials are in the hands of threat actors.

Why this hits harder for South African businesses

On the surface, the Lengau breach is a CSIR problem. In reality, it is a supply chain problem for anyone in South Africa whose research or software depends on work done through that supercomputer. Universities use Lengau for postgraduate research. Companies outsource computational work to researchers who use Lengau. Government departments run climate modelling, materials science, and engineering simulations on Lengau. Every organisation whose people or partners had accounts on that system now has credential exposure to manage.

The POPIA (Protection of Personal Information Act) angle is what most organisations miss. The CHPC has stated that it is reporting the breach to relevant privacy and POPIA entities within the CSIR and externally. That notification obligation runs both ways. If your organisation contracts work to a researcher or partner who had credentials on Lengau, and that researcher held your business information on the system, or held information about your clients, then your organisation may have a POPIA reporting obligation too. The responsible party for personal information is the organisation that collected it, not the supercomputer operator.

Beyond POPIA, there is a credential cascade problem. A researcher who used the same password on Lengau as they use for email, GitHub, or your internal systems is now a compromised endpoint. A developer who stored API keys in their home directory on Lengau has now handed those keys to someone mining Monero on your dime. If that developer works with your company, or worked with your company, the key may grant access to your systems. Threat actors know this. They trade credentials across forums and sell access to the highest bidder. The credentials are not just for Lengau any more.

The timeline compounds the risk. The CHPC has estimated that Lengau will remain offline for at least seven days from 2 June, potentially longer. As of the last public statement, the filesystem containing all user data remained isolated. That data will not be available for seven days at least, possibly two weeks. If your business depends on Lengau output or relies on researchers who do, your project timelines have just shifted, and your recovery costs have gone up.

What to do this week

  1. Contact every partner, contractor, or researcher who had credentials on Lengau and ask them directly whether they stored anything related to your business on the system. Ask specifically whether they stored your data, your clients' data, API keys, credentials, or source code. Do not wait for the CHPC's forensics report. Do that forensics conversation with your partner now.
  2. If the answer is yes to any of the above, assume those items are compromised. Rotate any API keys, SSH keys, or credentials the researcher held. Rotate passwords on any accounts the researcher accessed from the system. Issue a notice to any of your clients whose data was on the system that a third party's systems were compromised and you are taking precautions. POPIA requires that you notify affected individuals as soon as reasonably possible after you become aware of a personal information breach.
  3. Map your research supply chain and document it. Who are your research partners? Which universities do you contract work to? Which of those institutions use Lengau? The answers matter for incident response and for regulatory reporting if something does go wrong.
  4. Check whether your organisation has a breach response protocol, and whether it names who contacts the Information Regulator, who notifies clients, and by when. If you do not have a protocol, write one now before you need it. The CHPC took four days to confirm the breach was real. You will not have four days to decide who talks to whom.
  5. If your organisation is small enough that you cannot tell who might have what credentials where, reach out. That is the work we do. We walk through your setup, tell you where the gaps are, and give you a defensible response plan.

Where Ubuntu Guard fits

If you are not sure whether your organisation has exposure from the Lengau breach, or whether your research partners used the system, our incident response service is built for exactly this. We treat the credential compromise as confirmed, work from a clean environment, and give you a plain-language report covering what POPIA requires you to do and by when. The report is a conversation, not a compliance checkbox. You get clarity on your actual exposure and a next-step plan.

Had a breach or think you might be exposed? WhatsApp us now. We respond fast: wa.me/27791595040. Or email [email protected].

Cybersecurity Made Simple.


© 2026 Ubuntu Guard Cybersecurity | Durban, South Africa
ubuntuguard.co.za

Sources

Not sure if your organisation has exposure?

Ubuntu Guard's incident response service handles credential compromise from the Lengau breach, POPIA notification work, and research supply chain exposure. We respond fast.

Get incident response help

Questions? Reach us at [email protected]