Government

US Seeks Alleged Chinese Hafnium Hacker With $10 Million Reward

Zhang Yu was charged alongside Xu Zewei, who was extradited from Italy to the US in April 2026.

Chinese Hafnium hacker reward

The US Department of State is offering up to $10 million for information on Zhang Yu, a Chinese national accused of taking part in the Hafnium campaign against Microsoft Exchange servers.

The State Department’s Rewards for Justice (RFJ) program announced the reward on Wednesday. Zhang is charged alongside Xu Zewei, who was extradited from Italy to the US in April 2026.

According to RFJ, Zhang is a director at Shanghai Firetech Information Science and Technology Company. He allegedly worked on behalf of the Shanghai State Security Bureau (SSSB), part of China’s Ministry of State Security (MSS).

Zhang and Xu were named in a nine-count indictment unsealed in July 2025, days after Italian police arrested Xu in Milan at the request of the US. Xu has since appeared in federal court in Houston, while Zhang remains at large.

“Starting in early 2020, Zhang and his partner Xu Zewei, then a general manager at Shanghai Powerock Network Co. Ltd., gained unauthorized access to COVID-19 research conducted by US-based universities and leading immunologists and virologists to steal sensitive information,” RFJ said.

The following year, the two allegedly exploited vulnerabilities in Microsoft Exchange Server as part of Hafnium. RFJ says the campaign compromised thousands of computers worldwide, and its victims included a US university and a US law firm.

Advertisement. Scroll to continue reading.

Microsoft disclosed the Hafnium attacks in March 2021 and now tracks the threat actor as Silk Typhoon. When Xu was extradited, the FBI said the campaign had compromised more than 12,700 US organizations.

The reward falls under an RFJ offer for information on anyone who targets US critical infrastructure in violation of the Computer Fraud and Abuse Act while acting at the direction or under the control of a foreign government.

Related: US Charges 17 Iranian Hackers, Offers $10 Million Rewards for 5 of Them

Related: China’s Top Cybersecurity Firms Hit by Mounting Military Procurement Bans

Related: Report Links Chinese Companies to Tools Used by State-Sponsored Hackers

Related Content

Government

Flax Typhoon and other APTs used MicroScan and FishHub to scan and hack US and foreign critical infrastructure.

Government

SEC Consult has published technical details on vulnerabilities mentioned in a complaint filed by several US states.

Cybercrime

The individual was detained in May and has been extradited to Germany to face hacking charges.

Cybercrime

Amir Barati, an alleged member of the Mabna Institute, was indicted for targeting universities, private organizations, and government entities in the US and abroad.

Malware & Threats

The China-based hacking group has been exploiting SharePoint vulnerabilities since July 2025.

Hacker Conversations

Rob Juncker is chief product and technology officer at Mimecast. Is he a hacker? “Unequivocally yes,” he says.

Tracking & Law Enforcement

Pepijn van der Stap was convicted in 2023 for hacking multiple organizations, stealing their data, and extorting them.

Malware & Threats

The malware framework uses a modular architecture and a custom executable file format for long-term persistence.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version