U.S. Offers Up to $10 Million for Tips on Zhang Yu, Charged in HAFNIUM Hacks
The U.S. State Department is offering up to $10 million for information leading to the identification or location of Zhang Yu, a Chinese national charged in the United States in connection with the 2021 Microsoft Exchange Server attacks known as HAFNIUM.
The reward is for information leading to his identification or location, the news outlet NTD reported this week, citing a notice from the department's Rewards for Justice program.
Zhang remains at large, U.S. authorities say, meaning he has not been arrested. The charges against him have not been tested in court.
Rewards for Justice is the State Department's national security rewards program. It says it has paid more than $250 million to over 125 people since 1984.
Zhang is wanted for his alleged role in "malicious cyber activities against U.S. critical infrastructure," NTD quoted the notice as saying.
The amount and that wording match an offer the program was already making in January 2025. That offer was for information on anyone who hacks U.S. critical infrastructure at the direction of a foreign government.
Zhang and a second man, Xu Zewei, are charged together in federal court in Houston. The indictment, the document that sets out the charges, has nine counts.
It dates from November 2023 and was made public in July 2025. Since then, the Justice Department has asked the public for information about Zhang's whereabouts.
The alleged hacking took place between February 2020 and June 2021.
Xu was arrested in Milan in July 2025 at the request of the United States, and Italy extradited him to the United States in April 2026.
Xu "is one of many contractors the Chinese government uses to obscure its hand in cyber operations, and others who do the same face the same risk," Brett Leatherman, assistant director of the FBI's Cyber Division, said at the time.
What Zhang Is Accused Of
U.S. authorities describe Zhang as a director at Shanghai Firetech Information Science and Technology, a Shanghai company.
According to the indictment, he worked on tasks assigned by the Shanghai State Security Bureau, supervised hacking by other Firetech staff, and coordinated the hacking with Xu. The bureau is a branch of China's Ministry of State Security (MSS), an intelligence service.
Xu allegedly worked for a second Shanghai company, Shanghai Powerock Network. The Justice Department calls Powerock one of many "enabling" companies that hacked for the Chinese government, and says China uses private companies and contractors to hide its role.
The indictment alleges two sets of intrusions. The first, in early 2020, targeted U.S. universities and scientists working on COVID-19 vaccines, treatment, and testing. The second, from late 2020, exploited flaws in Microsoft Exchange Server in the campaign later called HAFNIUM.
On or about January 30, 2021, Xu allegedly told Zhang he had compromised a Texas university's network.
The alleged victims include two Texas universities and an international law firm with an office in Washington, D.C.
The HAFNIUM Campaign
Microsoft disclosed the Exchange attacks on March 2, 2021, and released fixes for four zero-day flaws, including the one known as ProxyLogon.
It blamed HAFNIUM, which it described as "a group assessed to be state-sponsored and operating out of China." Microsoft now tracks the group as Silk Typhoon.
Within days, Microsoft saw other hacking groups using the same flaws.
The FBI says the HAFNIUM campaign as a whole compromised more than 12,700 U.S. organizations.
In July 2021, the United States and partner governments said hackers linked to the MSS carried out the campaign. Microsoft's 2021 report named a group and a country. The names Xu Zewei and Zhang Yu come from the U.S. indictment.
Originally published by The Hacker News. © The Hacker News. Written by info@thehackernews.com (The Hacker News).
Fastnexa security experts
Dealing with this in your own company?
If this story touches software, suppliers or systems you use, a Fastnexa security expert can tell you what it means for you and what to do first.
Think you’ve already been hit? Don’t wait on a form: call or WhatsApp +1 (732) 454 2616. We reply within 1 hour, 24/7. Emergency help →
Coverage
One outlet has carried this so far.
2026-10-08 07:42 UTC
Related stories
- [Virtual Event] Cybersecurity Outlook 2027
Dark Reading · 2026-12-03
- [Virtual Event] What Every Enterprise Should Know About Securing Cloud Assets in the Age of AI
Dark Reading · 2026-11-12
- [Virtual Event] Building a Secure AI Strategy for the Enterprise
Dark Reading · 2026-10-08
- FBI and Secret Service Warn of FortiBleed Lockout Threat
Infosecurity Magazine · 2026-10-08
- FBI: Ongoing FortiBleed attacks lock out FortiGate VPN admins
BleepingComputer · 2026-10-07