US Offers Reward for Zhang Yu in Alleged Hafnium Hacks
The US Rewards for Justice program is offering up to $10 million for Zhang Yu, accused in alleged Hafnium hacks the FBI says hit more than 12,700 US organizations.
The U.S. State Department's Rewards for Justice program is offering a reward for information identifying or locating Zhang Yu, charged in Houston federal court on nine counts over alleged Hafnium intrusions from February 2020 to June 2021. Sources disagree on the amount—The Record says $10 million, while later reports say up to $10 million—and on his role: a Shanghai Firetech director who helped run the campaign for China's Ministry of State Security and the Shanghai State Security Bureau, someone working bureau tasks, or a director who directed employees including Xu Zewei. Alleged targets include U.S. COVID-19 research at universities and a law firm; one account says Xu obtained researcher mailbox contents at a Texas-area university, another says attackers installed web shells and searched law-firm mail for the terms MSS and Hong Kong, and another refers to COVID-19 vaccine researchers. FBI figures also diverge: The Record says Hafnium targeted more than 60,000 U.S. entities and victimized more than 12,700, whereas the others say the HAFNIUM Microsoft Exchange campaign compromised more than 12,700 U.S. organizations. Microsoft disclosed those attacks on March 2, 2021, patched four zero-days including ProxyLogon, and attributes the activity to the China-sponsored group it now tracks as Silk Typhoon. Co-defendant Xu Zewei, identified as being of Shanghai Powerock, was arrested at Milan Malpensa Airport on July 3, 2025, extradited in April 2026, and appeared in Houston on April 27, 2026; the indictment was unsealed in July 2025, Zhang remains at large, and the charges are only allegations.
- The State Department's Rewards for Justice program is offering a reward for information on Zhang Yu; The Record says $10 million and five later reports say up to $10 million.
- A nine-count Houston indictment, which SecurityWeek says was unsealed in July 2025, covers alleged intrusions from February 2020 to June 2021; the charges are unproven.
- Zhang, described as a Shanghai Firetech director, is accused of acting for China's Ministry of State Security and the Shanghai State Security Bureau and remains at large.
- Alleged activity includes theft of U.S. COVID-19 research from universities and a law firm, plus the Hafnium Microsoft Exchange campaign.
- FBI figures differ: The Record says more than 60,000 U.S. entities were targeted and more than 12,700 victimized; other reports say more than 12,700 U.S. organizations were compromised.
- Microsoft disclosed the Exchange attacks on March 2, 2021, patched four zero-days including ProxyLogon, and tracks Hafnium as Silk Typhoon.
- Co-defendant Xu Zewei of Shanghai Powerock was arrested at Milan Malpensa Airport on July 3, 2025, extradited in April 2026, and appeared in Houston federal court on April 27, 2026.
Coverage timelineoldest first · each row is one article
- · 1d agoUS posts $10 million reward for accused Chinese ‘Hafnium’ hacker
The Record· 64
The US offers $10 million for Zhang Yu, accused of leading Hafnium intrusions for China.
- · 20h agoU.S. Offers $10 Million Reward for Chinese Hacker Who Tried to Steal COVID-19 Research
Cyber Security News· 66
The U.S. offers up to $10 million for Zhang Yu, accused of MSS-directed theft of COVID-19 research.
- · 15h ago