Zhang Yu Targeted by $10 Million US Reward Offer Over HAFNIUM Allegations

US offers up to $10M for information on Zhang Yu, charged over alleged Chinese intelligence-linked hacking including COVID research and Exchange activity.

Zhang Yu Targeted by $10 Million US Reward Offer Over HAFNIUM Allegations
APT

Illustrative image generated with AI

Reward seeks information that could identify or locate Zhang

The U.S. State Department’s Rewards for Justice program is offering up to $10 million for information about Zhang Yu, a Chinese national charged over alleged cyber operations against American targets.

The notice seeks information leading to Zhang’s identification or location. Although some coverage has described the objective as securing his arrest, that goes beyond the wording reproduced from the reward notice.

As of October 8, 2026, Zhang remains at large, according to U.S. authorities cited by The Hacker News. There is no indication in the cited reporting that the offer has resulted in his arrest or that qualifying information has been submitted.

The timing requires care. The amount and language correspond to a broader Rewards for Justice offer already operating in January 2025. That initiative covered information about people conducting malicious cyber activity against U.S. critical infrastructure under the direction of a foreign government.

The available accounts therefore do not establish that officials created a new, Zhang-specific reward recently. Instead, the current notice identifies him as a person covered by the wider offer.

Rewards for Justice says it has paid more than $250 million to over 125 people since 1984. The program is administered by the State Department’s Bureau of Diplomatic Security and covers threats including malicious cyber operations and foreign election interference, in addition to international terrorism.

Nine-count indictment alleges work for Chinese intelligence

U.S. authorities describe Zhang as a director of Shanghai Firetech Information Science and Technology Co., Ltd. Prosecutors allege that Firetech personnel performed hacking assignments for the Shanghai State Security Bureau, or SSSB, a branch of China’s Ministry of State Security.

According to the indictment, Zhang received tasks from the SSSB, supervised hacking performed by other Firetech employees and coordinated operations with co-defendant Xu Zewei.

Xu has been associated in the reporting with Shanghai Powerock Network. The Justice Department characterizes Powerock as one of several “enabling” companies allegedly used to support operations for the Chinese government. Security Affairs identifies Xu as a general manager at the company.

The federal indictment was filed in Houston, contains nine counts and is dated November 2023. It became public in July 2025. The Justice Department later requested public assistance in finding Zhang, although the cited material does not provide a date for that request.

These remain criminal allegations. Zhang’s charges have not been tested in court, and the indictment’s description of his role should not be treated as a judicial finding.

The reward notice frames the alleged conduct as malicious cyber activity against U.S. critical infrastructure, performed under the direction or control of a foreign government and in violation of the Computer Fraud and Abuse Act. It attributes that direction to the MSS and its Shanghai bureau.

Prosecutors describe research theft and Exchange exploitation

The case sets out two main categories of alleged intrusion activity during a broader hacking period reported as running from February 2020 to June 2021.

The first involved COVID-19 research. In early 2020, Zhang and Xu allegedly accessed work conducted by American universities and scientists on vaccines, treatments and testing. Security Affairs reports that the targets included prominent immunologists and virologists and that sensitive material was stolen.

The second category concerned vulnerabilities in Microsoft Exchange Server. Prosecutors allege that, beginning later in 2020, the defendants participated in activity subsequently associated with the campaign known as HAFNIUM.

Named victims in the reporting include two Texas universities and an international law firm with an office in Washington, D.C. On or about January 30, 2021, Xu allegedly informed Zhang that he had compromised the network of one of the Texas universities.

That communication is an allegation from the prosecution’s case. It does not, by itself, establish responsibility for every intrusion attributed to HAFNIUM or show that the defendants controlled the wider campaign.

Microsoft’s disclosure triggered a broader Exchange emergency

Microsoft publicly disclosed the Exchange attacks on March 2, 2021. The company released fixes for four zero-day vulnerabilities, including the flaw widely known as ProxyLogon.

Microsoft attributed the initial activity to HAFNIUM, which it assessed to be a state-sponsored group operating from China. The company now tracks the same actor as Silk Typhoon. Other groups reportedly began exploiting the Exchange vulnerabilities within days of Microsoft’s disclosure, expanding the threat beyond the activity Microsoft initially described.

The FBI says the HAFNIUM campaign compromised more than 12,700 U.S. organizations. Separate reporting also describes thousands of affected computers worldwide.

Those are campaign-level figures. They are not a count of organizations proven to have been compromised by Zhang, Xu or their respective companies. The spread of exploitation among additional groups makes that distinction especially significant.

In July 2021, the United States and partner governments attributed the campaign to hackers linked to the MSS. That government attribution concerned the broader operation. Zhang and Xu were named individually later through the U.S. indictment.

The reports cited here do not provide CVE identifiers, affected Exchange versions, patch numbers or indicators of compromise. Consequently, the historical release of Microsoft’s four fixes is the only concrete technical remediation identified in this reporting.

Xu’s arrest brought one defendant into US custody

The two defendants now have different legal statuses. Xu was arrested in Milan in July 2025 at the request of the United States and extradited to the country in April 2026.

Security Affairs provides a more precise account, reporting that Italian police detained him at Milan Malpensa Airport on July 3 after he arrived from China. The outlet also says he was travelling for a vacation. Those details appear in that report rather than across all the cited coverage.

FBI Cyber Division Assistant Director Brett Leatherman characterized Xu as one of the contractors allegedly used by the Chinese government to conceal its involvement in cyber operations. That description reflects the FBI’s position, not an independently established conclusion about the companies or defendants.

Zhang has not been apprehended. The reward initiative is intended to generate information that could narrow that gap by establishing his identity details or physical location.

What the notice changes—and what it does not

For investigators, the notice increases the financial incentive for people with relevant information to approach U.S. authorities. It also places Zhang within a program aimed at foreign-government-directed attacks on American critical infrastructure.

For potential victims, however, the recent attention does not introduce a new Exchange vulnerability or a new remediation procedure. Microsoft’s relevant fixes were issued on March 2, 2021, while the cited reports provide no current indicators, version-specific instructions or additional defensive measures.

Administrators should not interpret the reward announcement itself as evidence of a newly disclosed compromise. Nor does it show that every organization affected by the wider HAFNIUM campaign was targeted by the two charged men.

The case instead illustrates the structure alleged by U.S. prosecutors: a state security service assigning work through private technology companies and contractors, with targets spanning biomedical research, universities, legal services and Exchange infrastructure.

Whether prosecutors can prove Zhang’s role remains a matter for court proceedings if he is brought into custody. For now, the immediate objective is narrower: finding information that can identify or locate him.

Read next

Sources

This article is an original reworking based on the sources below.

Back to home

Latest Cybersecurity News

All cybersecurity news →