US posts $10 million reward for accused Chinese ‘Hafnium’ hacker

LowThe Record·

At a glance

Severity
Low
Used in attacks
No flaws named
Reported by
1 outlet

The State Department is offering $10 million for information on the whereabouts of Zhang Yu, a Chinese national accused of being a key figure in the Hafnium hacking campaign. 

U.S. officials claimed Zhang, who serves as director of Shanghai Firetech Information Science and Technology, worked on behalf of the Chinese government as part of an effort that saw hackers breach thousands of computers and steal troves of documents and emails. 

Zhang allegedly worked alongside another Chinese official, Xu Zewei, and stole COVID-19 research from U.S.-based universities, immunologists and virologists. The State Department said Zhang violated the Computer Fraud and Abuse Act through his cyberattacks, which targeted at least one university and a law firm. 

While Zhang remains at large, Xu was arrested in July 2025 by Italian authorities while on vacation in Milan and was extradited to the U.S. in April. 

A nine-count indictment unveiled last year saw the the Justice Department accuse Zhang and Xu of being involved in “computer intrusions between February 2020 and June 2021, including the indiscriminate HAFNIUM computer intrusion campaign that compromised thousands of computers worldwide, including in the United States.”

Prosecutors said the men were ordered to conduct the hacks at the behest of the Ministry of State Security (MSS) and Shanghai State Security Bureau (SSSB) intelligence services. 

They allegedly reported back to supervising officers at the SSSB — including one instance where Xu confirmed that he “had compromised the network of a research university located in the Southern District of Texas.”

“Through HAFNIUM, the CCP targeted over 60,000 U.S. entities, successfully victimizing more than 12,700 in order to steal sensitive information,” Brett Leatherman, assistant director of the FBI’s cyber division, said last year.

Originally published by The Record. © The Record.

Read at therecord.media ↗Established Source

Fastnexa security experts

Dealing with this in your own company?

If this story touches software, suppliers or systems you use, a Fastnexa security expert can tell you what it means for you and what to do first.

Book a 30-min callWhatsApp us

Think you’ve already been hit? Don’t wait on a form: call or WhatsApp +1 (732) 454 2616. We reply within 1 hour, 24/7. Emergency help →

Coverage

One outlet has carried this so far.

  1. The Record ↗Established SourceFirst reported

    2026-10-07 19:50 UTC

Related stories