U.S. Offers $10 Million Reward for Chinese Hacker Who Tried to Steal COVID-19 Research
The U.S. offers up to $10 million for Zhang Yu, accused of MSS-directed theft of COVID-19 research.
The U.S. State Department's Rewards for Justice program is offering up to $10 million for information on Zhang Yu, a Chinese national accused of supporting intrusions against American COVID-19 research. Prosecutors say Zhang worked for the Shanghai State Security Bureau, part of China's Ministry of State Security, and that alleged partner Xu Zewei obtained researcher mailbox contents after breaching a Texas-area university between February 2020 and June 2021. The case also ties both men to the HAFNIUM Microsoft Exchange campaign, which the FBI says compromised more than 12,700 U.S. organizations; attackers allegedly installed web shells and searched a law firm's mail for terms including "MSS" and "Hong Kong." Italian authorities arrested Xu in July 2025 and he was extradited in April 2026, while Zhang remains at large under a nine-count indictment.
- State Department offers up to $10 million for information on Zhang Yu.
- Alleged MSS-directed mailbox theft targeted COVID-19 researchers from February 2020 to June 2021.
- Zhang and Xu are linked to HAFNIUM Exchange intrusions affecting over 12,700 U.S. organizations.
- Xu Zewei was extradited from Italy in April 2026; Zhang remains wanted.
- Both face a nine-count indictment, which is not proof of guilt.
Full article590 words · extracted from cybersecuritynews.com · click to collapse
The U.S. Department of State is offering up to $10 million for information on Zhang Yu, a Chinese national accused of helping hackers target American COVID-19 research. The Rewards for Justice notice seeks details about Zhang, his associates, and their malicious cyber activities, with possible rewards and relocation for eligible sources.
U.S. authorities allege Zhang worked on behalf of the Shanghai State Security Bureau, part of China’s Ministry of State Security. The FBI Cyber Division highlighted the reward while pointing to the case against his alleged partner, Xu Zewei, who is now in U.S. custody.
Research Mailboxes Targeted
According to the Justice Department’s case summary, the alleged intrusions ran from February 2020 through June 2021. Early targets included U.S. universities, immunologists, and virologists working on COVID-19 vaccines, treatments, and testing. Investigators say intelligence officers directed the hacking and received reports about its progress.
The court documents describe a clear sequence. Around February 19, 2020, Xu allegedly told a Shanghai State Security Bureau officer that he had breached a research university in the Southern District of Texas. Three days later, the officer instructed him to access specific mailboxes belonging to researchers studying COVID-19.
Xu later reported that he had obtained the contents of those mailboxes, prosecutors say. This distinction matters: the case describes alleged data theft, not simply failed attempts to reach research systems. However, the public summary does not identify the university or detail every document taken.
The investigation also links Zhang and Xu to the HAFNIUM Microsoft Exchange Server hacking campaign. Beginning in late 2020, prosecutors allege, the group exploited Exchange vulnerabilities to break into email systems. Microsoft publicly disclosed the campaign in March 2021, prompting patches, detection tools, and government guidance.
After gaining access, the hackers allegedly installed web shells, scripts that let attackers control a server remotely. Such access allowed them to search and steal mailbox data. At a targeted law firm, investigators say the attackers searched for terms including “Chinese sources,” “MSS,” and “HongKong.”
The FBI says the wider HAFNIUM campaign compromised more than 12,700 U.S. organizations. That figure describes the broader campaign, not a confirmed count of COVID-19 research victims or organizations personally breached by Zhang.
Italian authorities arrested Xu in Milan on July 3, 2025, at Washington’s request. He was extradited on April 25, 2026, and appeared in federal court in Houston on April 27. Zhang remains wanted. Both face allegations in a nine-count indictment; the charges are not proof of guilt.
Cyber Security News previously examined Chinese companies linked to Xu and Zhang and their patents for data collection tools. That reporting identified Shanghai Powerock as Xu’s employer and Shanghai Firetech as Zhang’s, adding context to the alleged contractor network behind these operations. The patent findings do not establish which tools were used in these intrusions.
The Justice Department says China uses private companies to hide its role in hacking, while the resulting breaches can leave systems open to further attacks by unrelated, profit-driven threat actors.
Rewards for Justice directs sources to its official Tor-based reporting channel for information about foreign state-backed cyber activity. Its guidance says eligible sources may receive relocation support and cryptocurrency payments.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup into your SOC
Guru Baranhttps://cybersecuritynews.com
Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.