US Seeks Alleged Chinese Hafnium Hacker With $10 Million Reward
The US offers up to $10 million for alleged Hafnium hacker Zhang Yu, still at large.
The US State Department’s Rewards for Justice program is offering up to $10 million for information on Zhang Yu, a Chinese national accused of participating in the Hafnium campaign against Microsoft Exchange. Zhang, described as a director at Shanghai Firetech, and Xu Zewei were charged in a nine-count indictment unsealed in July 2025; Xu was extradited from Italy in April 2026. Authorities say they stole US COVID-19 research in 2020 and later exploited Exchange flaws, with the FBI stating the campaign compromised more than 12,700 US organizations. Microsoft tracks Hafnium as Silk Typhoon.
- Rewards for Justice offers up to $10 million for Zhang Yu.
- Zhang and Xu Zewei were named in a July 2025 indictment.
- Xu was extradited from Italy; Zhang remains at large.
- Alleged Hafnium activity compromised more than 12,700 US organizations.
Full article479 words · extracted from securityweek.com · click to collapse
The US Department of State is offering up to $10 million for information on Zhang Yu, a Chinese national accused of taking part in the Hafnium campaign against Microsoft Exchange servers.
The State Department’s Rewards for Justice (RFJ) program announced the reward on Wednesday. Zhang is charged alongside Xu Zewei, who was extradited from Italy to the US in April 2026.
According to RFJ, Zhang is a director at Shanghai Firetech Information Science and Technology Company. He allegedly worked on behalf of the Shanghai State Security Bureau (SSSB), part of China’s Ministry of State Security (MSS).
Zhang and Xu were named in a nine-count indictment unsealed in July 2025, days after Italian police arrested Xu in Milan at the request of the US. Xu has since appeared in federal court in Houston, while Zhang remains at large.
“Starting in early 2020, Zhang and his partner Xu Zewei, then a general manager at Shanghai Powerock Network Co. Ltd., gained unauthorized access to COVID-19 research conducted by US-based universities and leading immunologists and virologists to steal sensitive information,” RFJ said.
The following year, the two allegedly exploited vulnerabilities in Microsoft Exchange Server as part of Hafnium. RFJ says the campaign compromised thousands of computers worldwide, and its victims included a US university and a US law firm.
Advertisement. Scroll to continue reading.
Microsoft disclosed the Hafnium attacks in March 2021 and now tracks the threat actor as Silk Typhoon. When Xu was extradited, the FBI said the campaign had compromised more than 12,700 US organizations.
The reward falls under an RFJ offer for information on anyone who targets US critical infrastructure in violation of the Computer Fraud and Abuse Act while acting at the direction or under the control of a foreign government.
Related: US Charges 17 Iranian Hackers, Offers $10 Million Rewards for 5 of Them
Related: China’s Top Cybersecurity Firms Hit by Mounting Military Procurement Bans
Related: Report Links Chinese Companies to Tools Used by State-Sponsored Hackers
Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.
Daily Briefing Newsletter
Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.
Daily Briefing Newsletter
Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.
Learn how to address potential risks and not restrict AI adoption in your organization. See what a centralized AI gateway is and how it works in practice.
Join as we decipher the world of zero trust and share war stories on securing an organization by eliminating implicit trust and continuously validating every stage of a digital interaction.