That's not a very responsible statement.
In Germany it is (incident was 15.05) - NEMO (Freiburg) - bwUniCluster 2.0 and ForHLR II (Karlsruhe) - Hawk (Stuttgart) - Leibniz Supercomputing Center (Munich) - JURECA, JUWELS und JUDAC (FZ Jülich) - Taurus (Dresden)
Switzerland shutdown access to all of CSCS (16.05).
1 - HPC centers in Europes are down.
2 - Those are useful resources to battle battle against COVID-19.
3 - HPC centers are down due to malware infections.
4 - FBI warned and Department of Homeland Security warns of possible cyberattacks targeting COVID-19 research.
"The attacks may have been perpetrated in order to mine cryptocurrency; investigations are ongoing."
I believe it's referred to as the "limited hangout" in spycraft jargon. You maintain the target's sense of security and ability to detect intrusion while you maintain the capability to reintrude at will.
1 - one of the two incidences reported (#EGI2020512) targeted academic data centers "for unknown purposes" (https://csirt.egi.eu/academic-data-centers-abused-for-crypto...) and not necessarily crypto currency mining.
2 - IP addresses associated with that second attack were all assigned to a Chinese University (Shanghai Jiaotong University), CSTNET and one Polish host known to be compromised by someone from China.
It's like trying to assign blame for a terrorist attack based on where the jacket dropped by a terrorist was made. Maybe it was made in their home country. Maybe it was imported. Or maybe they purposefully wore a jacket made in a different country and dropped it on the scene to confuse you.
That's not my reading of the article you linked. A bad actor compromised the credentials of multiple researchers with access to various supercomputers (over some unknown or at least unspecified period of time). They then simultaneously accessed the compromised machines and installed cryptocurrency mining software on them.
This could easily be profit motivated (as it appears). It could also be (as you suggest) a hostile act disguised as the former, but I don't see what the motivation to do that would be?
Seems more likely that more people are using/accessing these services, and people's guards are down, which made it easier for intruders to get in.
Decades ago I spent a bunch of time around fnal.gov with a buddy who worked there, and they were debating the requirement of every computer, including desktops, having a static, public IPv4 address. Nobody wanted to be behind a firewall in the name of open, collaborative research.
Incidentally, if attackers were looking for sensitive research results from this, I think it would have to be targeted with detailed knowledge about what specific researchers were doing; after all, it's difficult enough for a typical researcher to keep track of their own stuff, and it mostly won't have look-at-me names.