South Africa’s Supercomputer Got Hacked. The Funding to Protect It Is Being Cut.

That is not a hypothetical risk scenario. It is what happened between May and August 2026, and the full picture only became clear this week when the Minister of Science, Technology and Innovation, Blade Nzimande, answered questions in Parliament.

The story starts with a performance dip.

What Happened to Lengau

On 25 May 2026, users of the Lengau high-performance computing cluster at the CSIR’s Centre for High-Performance Computing began noticing that the system felt slow. Processing speeds had dropped. The cause was not a software glitch or hardware failure. Attackers had gained unauthorised access to the system and were quietly using its considerable computing power to mine cryptocurrency.

Lengau is not a routine server. It is South Africa’s flagship supercomputer: a petascale machine with 1,368 compute nodes, nearly 150 terabytes of memory, and the capacity to perform over a quadrillion calculations per second. Around 1,500 registered researchers, scientists, and engineers across South Africa and neighbouring African countries rely on its power for research spanning climate and weather modelling, drug discovery, seismic analysis, and genomic research. During the Covid-19 pandemic, it supported SARS-CoV-2 sequencing work across the continent.

The CHPC detected the compromise, shut down affected nodes, and re-imaged them. Users were told the situation was under control.

It was not. A second attack on Saturday 30 May forced the CHPC to take the supercomputer offline entirely. This time the shutdown lasted weeks. User credentials and private keys were confirmed compromised. The Lustre parallel file system, which holds user research data, remained inaccessible throughout. The breach occurred because of vulnerabilities associated with the decade-old high-performance computing system.

The Funding Problem Nzimande Confirmed in Parliament

Here is where the story becomes more than a technical incident.

This week, in a written parliamentary response, Minister Nzimande confirmed what many in the sector have suspected for some time: the current allocations are inadequate to sustain both operations and planned expansion targets. The R292 million ring-fenced for the National Integrated Cyberinfrastructure System in the 2026/27 financial year is under pressure from Treasury budget cuts, escalating operational costs, and shifting exchange rates.

In other words, South Africa’s flagship national computing infrastructure was breached twice in a single week on a decade-old system, and the funding meant to replace and protect it is being squeezed before the replacement is even online.

The minister noted that due to the legacy environment, some components are ageing, technically constrained, or no longer fully supported by original vendors. That is a description of a system that has outrun its security support. Vendors stop patching software they no longer sell. Attackers know this. They scan for exactly these environments.

The CSIR is conducting an internal review to determine whether staff errors or wrongdoing contributed to the incident. That review is ongoing.

Why This Matters Beyond the CSIR

The instinct when reading a story like this is to treat it as a public sector problem, contained within government infrastructure, separate from the private sector.

That instinct is wrong for two reasons.

First, Lengau supports researchers across the private sector, universities, and neighbouring African countries. A breach that compromises user credentials and private keys does not stay within the CSIR’s perimeter. Those credentials authenticate researchers across multiple systems and institutions. The blast radius of a credential compromise on shared infrastructure is wider than the incident reports suggest.

Second, the structural conditions that made Lengau vulnerable are not unique to government. Legacy systems running beyond vendor support, underfunded security budgets, and infrastructure that expands faster than the security maturity needed to protect it are patterns visible across South African enterprise, municipal government, and state-owned entities alike.

South Africa is bleeding data, crippled by a severe human capital deficit where only one in three dedicated public sector cybersecurity positions are filled. That statistic does not improve on its own while budgets are being cut.

The New System Is Not a Security Strategy

The government is replacing Lengau. Phase one of the new four-petaflop system is expected to be live by the end of November 2026, with the completed upgrade expected by the end of March 2027. The new system will be significantly more powerful. It will also be new, which means it will not immediately carry the same legacy vulnerabilities that made Lengau an easy target.

But faster hardware is not a security posture. The question that Parliament has not yet received a satisfying answer to is what the security architecture of the new system looks like, how credentials and access will be managed differently, and whether the funding pressures Nzimande described will compromise the security investment that should accompany any major infrastructure transition.

A new supercomputer running on an underfunded security model is a more powerful version of the same problem.

What the Lengau Incident Should Prompt

For South African organisations watching this story, the practical questions are closer to home than they might appear:

  • Which systems in your environment are running on software or hardware that vendors no longer fully support?
  • Do you have visibility into performance anomalies that might indicate cryptojacking or unauthorised resource use? The first sign of the Lengau breach was a slowdown, not a security alert
  • Are credentials and private keys rotated on a schedule, or only after an incident forces it?
  • If a shared system your organisation relies on were compromised, would you know which of your own credentials were at risk?

South Africa has the technical capability to build and operate world-class computing infrastructure. The Lengau breach is not evidence to the contrary. It is evidence that capability without sustained investment in security and maintenance creates exactly the kind of exposure that attackers look for.

The attackers who found Lengau were not sophisticated state actors running novel zero-days. They were opportunists who found a decade-old system with known vulnerabilities and walked in.

That is the most uncomfortable part of this story.