U.S. Offers Up to $10 Million for Tips on Zhang Yu, Charged in HAFNIUM Hacks
US State Department offers up to $10 million for tips locating Zhang Yu, Chinese national charged in HAFNIUM Microsoft Exchange hacks.
The State Department's Rewards for Justice program is offering up to $10 million for information identifying or locating Zhang Yu, charged in Houston federal court on nine counts for 2020-2021 intrusions including the HAFNIUM Microsoft Exchange campaign that compromised more than 12,700 US organizations. Zhang, allegedly a director at Shanghai Firetech working on tasks from the Shanghai State Security Bureau, remains at large; co-defendant Xu Zewei of Shanghai Powerock was arrested in Milan in July 2025 and extradited from Italy in April 2026. Microsoft disclosed the Exchange attacks on March 2, 2021, patched four zero-day flaws including ProxyLogon, and attributed them to the China-sponsored group it now tracks as Silk Typhoon. Earlier intrusions targeted US universities and COVID-19 vaccine researchers.
- $10M Rewards for Justice offer for Zhang Yu's identification or location
- Nine-count Houston indictment covers 2020-2021 hacking including HAFNIUM Exchange campaign
- HAFNIUM compromised 12,700+ US organizations via four Exchange zero-days including ProxyLogon
- Co-defendant Xu Zewei extradited from Italy to the US in April 2026
- Zhang allegedly directed hacking for Shanghai State Security Bureau via Shanghai Firetech
Full article636 words · extracted from thehackernews.com · click to collapse
Swati KhandelwalOct 08, 2026Cybercrime / Cyber Espionage
The U.S. State Department is offering up to $10 million for information leading to the identification or location of Zhang Yu, a Chinese national charged in the United States in connection with the 2021 Microsoft Exchange Server attacks known as HAFNIUM.
The reward is for information leading to his identification or location, the news outlet NTD reported this week, citing a notice from the department's Rewards for Justice program.
Zhang remains at large, U.S. authorities say, meaning he has not been arrested. The charges against him have not been tested in court.
Rewards for Justice is the State Department's national security rewards program. It says it has paid more than $250 million to over 125 people since 1984.
Zhang is wanted for his alleged role in "malicious cyber activities against U.S. critical infrastructure," NTD quoted the notice as saying.
The amount and that wording match an offer the program was already making in January 2025. That offer was for information on anyone who hacks U.S. critical infrastructure at the direction of a foreign government.
Zhang and a second man, Xu Zewei, are charged together in federal court in Houston. The indictment, the document that sets out the charges, has nine counts.
It dates from November 2023 and was made public in July 2025. Since then, the Justice Department has asked the public for information about Zhang's whereabouts.
The alleged hacking took place between February 2020 and June 2021.
Xu was arrested in Milan in July 2025 at the request of the United States, and Italy extradited him to the United States in April 2026.
Xu "is one of many contractors the Chinese government uses to obscure its hand in cyber operations, and others who do the same face the same risk," Brett Leatherman, assistant director of the FBI's Cyber Division, said at the time.
What Zhang Is Accused Of
U.S. authorities describe Zhang as a director at Shanghai Firetech Information Science and Technology, a Shanghai company.
According to the indictment, he worked on tasks assigned by the Shanghai State Security Bureau, supervised hacking by other Firetech staff, and coordinated the hacking with Xu. The bureau is a branch of China's Ministry of State Security (MSS), an intelligence service.
Xu allegedly worked for a second Shanghai company, Shanghai Powerock Network. The Justice Department calls Powerock one of many "enabling" companies that hacked for the Chinese government, and says China uses private companies and contractors to hide its role.
The indictment alleges two sets of intrusions. The first, in early 2020, targeted U.S. universities and scientists working on COVID-19 vaccines, treatment, and testing. The second, from late 2020, exploited flaws in Microsoft Exchange Server in the campaign later called HAFNIUM.
On or about January 30, 2021, Xu allegedly told Zhang he had compromised a Texas university's network.
The alleged victims include two Texas universities and an international law firm with an office in Washington, D.C.
The HAFNIUM Campaign
Microsoft disclosed the Exchange attacks on March 2, 2021, and released fixes for four zero-day flaws, including the one known as ProxyLogon.
It blamed HAFNIUM, which it described as "a group assessed to be state-sponsored and operating out of China." Microsoft now tracks the group as Silk Typhoon.
Within days, Microsoft saw other hacking groups using the same flaws.
The FBI says the HAFNIUM campaign as a whole compromised more than 12,700 U.S. organizations.
In July 2021, the United States and partner governments said hackers linked to the MSS carried out the campaign. Microsoft's 2021 report named a group and a country. The names Xu Zewei and Zhang Yu come from the U.S. indictment.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.