US Offers $10 Million for Accused HAFNIUM Hacker Zhang Yu
The US State Department has announced a $10 million reward, through its Rewards for Justice program, for information leading to the location of Zhang Yu, a 44-year-old Chinese national accused of being a central figure in the HAFNIUM hacking campaign — the 2021 mass-exploitation of Microsoft Exchange Server that compromised tens of thousands of organizations worldwide. US officials say Zhang, identified as a director at Shanghai Firetech Information Science and Technology, acted on behalf of Chinese intelligence services and helped steal troves of documents and emails, including COVID-19 research from US universities, immunologists, and virologists. Zhang remains at large; a co-defendant, Xu Zewei, was arrested in Italy in July 2025 and extradited to the United States in April 2026, where he has pleaded not guilty.
Case Details
| Attribute | Value |
|---|---|
| Wanted individual | Zhang Yu (张宇), 44, Chinese national |
| Alleged role | Director, Shanghai Firetech Information Science and Technology Company |
| Reward | $10 million via the State Department's Rewards for Justice program |
| Co-defendant | Xu Zewei, 34, general manager of Shanghai Powerock — extradited from Italy, April 2026, pleaded not guilty |
| Indictment | Nine-count indictment unsealed in 2025, US District Court, Southern District of Texas (Houston) |
| Alleged sponsor | China's Ministry of State Security (MSS) and Shanghai State Security Bureau (SSSB) |
| Campaign window | February 2020 – June 2021 |
| Named campaign | HAFNIUM — mass exploitation of Microsoft Exchange Server (publicly disclosed by Microsoft, March 2021) |
| Current threat-group name | Silk Typhoon (Microsoft's rebranded tracking name for the same actor) |
| Scale | Over 60,000 US entities targeted; more than 12,700 confirmed victimized, per FBI Cyber Division |
| Charges | Wire fraud, computer intrusion, and identity theft |
| Legal basis for charges | Violations of the Computer Fraud and Abuse Act |
How the HAFNIUM Campaign Worked
The 2021 Exchange Server exploitation
HAFNIUM — the name Microsoft assigned to the threat actor before later rebranding it Silk Typhoon — exploited a chain of zero-day vulnerabilities in on-premises Microsoft Exchange Server, most notably CVE-2021-26855 (the server-side request forgery flaw known as ProxyLogon), alongside companion bugs that enabled authentication bypass and remote code execution. Attackers used the flaws to plant web shells on compromised Exchange servers, giving them persistent remote access that survived patching unless the web shells themselves were also removed. Microsoft disclosed the campaign publicly in March 2021 after observing indiscriminate, large-scale exploitation against organizations with internet-facing Exchange servers.
Targeting and data theft
Once inside, the attackers used their web shell access to search Exchange mailboxes for material of intelligence value. Prosecutors allege Zhang and Xu conducted intrusions between February 2020 and June 2021 at the direction of MSS and SSSB officers, targeting a global law firm with offices in Washington, DC for information on US policymakers and government agencies, and separately targeting US-based universities, immunologists, and virologists to steal COVID-19 research data during the height of the pandemic. Both men are described in the indictment as operating through Shanghai-based commercial entities — Xu through Shanghai Powerock and Zhang through Shanghai Firetech — that prosecutors say functioned as part of a broader network used to obscure Beijing's involvement in state-directed hacking operations.
From indictment to international arrest
The nine-count indictment against Zhang and Xu was unsealed in US federal court in 2025. Xu Zewei was arrested in Milan, Italy, in July 2025 with the assistance of Italy's cyber police (Polizia Postale), acting on a US arrest warrant. Following an Italian court's approval of the transfer, Xu was extradited to the United States and appeared in the Southern District of Texas in April 2026, where he pleaded not guilty to all charges; his US attorney has argued Xu is a victim of mistaken identity. Zhang Yu has not been located, prompting this week's $10 million Rewards for Justice announcement aimed at generating tips on his whereabouts.
Impact Assessment
| Impact Area | Description |
|---|---|
| Scale of original campaign | HAFNIUM's 2021 Exchange exploitation targeted over 60,000 US entities and confirmed-compromised more than 12,700, among tens of thousands more worldwide — one of the largest mass-hacking events tied to a single actor |
| Sensitive data exposure | COVID-19 vaccine and treatment research, plus intelligence on US policymakers and government agencies pulled from a Washington law firm's email systems |
| Ongoing threat | The same actor, now tracked as Silk Typhoon, remains active and was linked to the 2024 breach of the US Treasury Department and continued targeting of the global IT supply chain |
| Deterrence value | A $10 million bounty signals continued US pressure on state-linked contractor hackers, but Zhang's protection inside China makes actual capture unlikely absent travel to a cooperating jurisdiction |
| Precedent set by Xu's case | Xu's arrest in Italy and extradition demonstrates that Chinese contract hackers who travel abroad remain exposed to arrest, even years after an alleged campaign |
| Reputational/diplomatic impact | Continues to strain US-China relations over state-sponsored cyber-espionage and reinforces the "hacker-for-hire" model Western agencies say Beijing uses to maintain deniability |
Recommendations
For enterprise IT and security teams
- Verify Exchange Server patching status, even years after the original ProxyLogon disclosure — legacy on-premises Exchange deployments that were never fully remediated may still carry residual web shells or backdoors from 2021.
- Hunt for historical indicators of compromise tied to HAFNIUM/Silk Typhoon (known web shell paths, suspicious IIS worker-process activity, and anomalous mailbox export/search activity) if your organization ran internet-facing Exchange in 2021 and has not conducted a full forensic review since.
- Treat Silk Typhoon as an active, evolving threat, not a closed 2021 incident — the group has been tied to more recent intrusions, including the 2024 US Treasury breach and IT supply-chain targeting.
- Harden identity and mail infrastructure with multi-factor authentication, conditional access, and strict monitoring of administrative actions on mail servers, since mailbox access remains a primary objective for this actor.
For universities and research institutions
- Audit access logs for research data repositories, especially those tied to sensitive public-health or biomedical research, given this actor's demonstrated interest in COVID-19-era research theft.
- Review third-party and cloud storage permissions on collaborative research platforms, which are common lateral-movement targets once an initial foothold is established.
For the broader security community
- Report credible location information on Zhang Yu through the Rewards for Justice program if encountered through legitimate investigative or intelligence channels — the reward is specifically for actionable location data, not technical attribution.
- Expect continued extraditions and indictments tied to Chinese state-linked contract hacking firms as US law enforcement expands international cooperation with jurisdictions willing to detain and extradite suspects who travel.
Key Takeaways
- The State Department is offering a $10 million reward for information on the location of Zhang Yu, accused of directing operations in the 2021 HAFNIUM Microsoft Exchange Server campaign.
- HAFNIUM — now tracked as Silk Typhoon — targeted over 60,000 US entities and successfully compromised more than 12,700, using zero-day Exchange vulnerabilities including CVE-2021-26855 (ProxyLogon).
- Zhang Yu and co-defendant Xu Zewei were charged in a nine-count indictment alleging intrusions from February 2020 to June 2021 directed by China's Ministry of State Security and Shanghai State Security Bureau.
- Xu Zewei was arrested in Italy in July 2025 and extradited to the US in April 2026, where he has pleaded not guilty; Zhang Yu remains at large.
- Stolen data reportedly included COVID-19 research from US universities and virologists, plus intelligence on US policymakers obtained from a Washington law firm.
- The same threat actor, rebranded Silk Typhoon, has been linked to more recent intrusions, including the 2024 US Treasury Department breach, underscoring that this is an active, ongoing threat rather than a closed historical case.
Sources
- The Record — US posts $10 million reward for accused Chinese 'Hafnium' hacker
- US Department of Justice, Southern District of Texas — Prolific Chinese State-Sponsored Contract Hacker Extradited from Italy
- TechCrunch — Hacker who allegedly carried out cyberattacks for China is extradited to US
- CyberScoop — Chinese national extradited to US for pandemic-era Silk Typhoon attacks