Search TorNews

Find cybersecurity news, guides, and research articles

Popular searches:

Home » News » Government & Policy » US Offers $10 Million Reward for China-Linked Hacker Zhang Yu

US Offers $10 Million Reward for China-Linked Hacker Zhang Yu

By:
Last updated:October 9, 2026
Human Written
  • The U.S. State Department wants information on Zhang Yu, a Chinese national linked to the HAFNIUM hacking campaign.

  • Prosecutors say Zhang helped target U.S. universities, COVID-19 researchers, and Microsoft Exchange servers.

  • Zhang remains missing. His alleged partner, Xu Zewei, was sent to the U.S. from Italy in April 2026.

US Offers $10 Million Reward for Information on HAFNIUM Hacker Zhang Yu

The U.S. Department of State wants help finding Zhang Yu. He is a Chinese national tied to major cyberattacks. The department now offers up to $10 million for information on him.

Officials say Zhang worked with people linked to China’s government. They allegedly attacked U.S. universities, COVID-19 researchers, and Microsoft email servers. These attacks became known as the HAFNIUM campaign. Zhang has not been caught. He stays free somewhere, according to U.S. authorities. His case is still open.

This reward comes from the Rewards for Justice program. The U.S. State Department runs this program. The official page names Zhang as a director at Shanghai Firetech Information Science and Technology Company.

Officials say they want information that leads to Zhang’s location. They link him to harmful cyber activity against U.S. critical systems. Zhang has not faced trial. The charges against him are only allegations for now. U.S. law treats him as innocent until proven guilty.

This case connects to years of digital break-ins. Hackers reportedly targeted American research groups. They also broke into Microsoft Exchange Server software. Thousands of organizations worldwide felt the effects of this wider HAFNIUM campaign.

Inside the Charges Against Zhang Yu

The U.S. Department of Justice shared new details in July 2025. Prosecutors charged Zhang and another man, Xu Zewei, with nine criminal counts. These charges cover hacking activity between February 2020 and June 2021. A grand jury filed the indictment in November 2023. Courts kept it sealed until July 2025.

According to prosecutors, Zhang followed orders from the Shanghai State Security Bureau. This bureau works under China’s Ministry of State Security. Officials also say Zhang oversaw hacking by staff at Shanghai Firetech. He allegedly worked closely with Xu, who reportedly worked for Shanghai Powerock Network.

The alleged hacking started in early 2020. Prosecutors say the group targeted U.S. universities and researchers. These researchers were studying COVID-19 vaccines and treatments. The attackers reportedly broke into researchers’ email accounts. They allegedly pulled private information out of these accounts.

The charges also link the pair to a second wave of attacks. These attacks hit Microsoft Exchange Server software in late 2020. Victims reportedly included two universities in Texas. An international law firm with a Washington, D.C. office was also affected, officials say.

Italian police arrested Xu in Milan in July 2025. U.S. authorities had requested his arrest. Italy sent Xu to the United States in April 2026. He appeared before a federal court in Houston. Zhang, however, remains missing.

How the HAFNIUM Attack Hit Microsoft Users

Microsoft first revealed the HAFNIUM attacks on March 2, 2021. The company had spotted attacks on on-site Microsoft Exchange Server systems. Microsoft blamed a state-backed hacking group from China. The company said it held high confidence in that claim.

The hackers reportedly used four unknown security flaws. Experts call these flaws zero-day vulnerabilities. Each flaw carried its own code: CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065. Microsoft quickly released updates to close these gaps.

Once inside a system, hackers planted hidden tools called web shells. These tools let hackers return to a hacked system anytime they wanted. Hackers could read emails and run more harmful actions from there.

The attack soon grew far bigger than HAFNIUM alone. Other hacking groups learned about the same flaws. They launched their own attacks using these same gaps. The FBI later said more than 12,700 U.S. organizations got hit by this wider wave.

Microsoft now calls this hacking group Silk Typhoon, not HAFNIUM. In July 2021, the United States and its allies pointed to China’s Ministry of State Security as the group behind the attacks.

A Reward That Isn’t Entirely New

This new $10 million reward gives the U.S. another way to find Zhang. Law enforcement agencies have also used financial rewards to seek information on ransomware groups, including a $22,000 reward for information on the INC ransomware gang.

But the reward itself is not brand new. Its size and wording match an older offer. The State Department first announced this type of reward in January 2025. That earlier announcement covered cyberattacks against U.S. critical systems backed by foreign governments.

So while Zhang’s name appears on the list now, the reward program behind it has existed for months. His case remains open. Investigators still do not know where he is hiding.

Security outlets have also covered this story. SecurityWeek reported on the reward and the claims against Zhang. The Hacker News shared similar details about the case.

Independent sources back up the main claims in this report. The reward offer and Zhang’s wanted status appear on the official Rewards for Justice page. The Justice Department confirms the nine-count indictment and the alleged China ties. Microsoft’s own blog post explains the exploited flaws in full detail.

An indictment, though, is not proof of guilt. Courts have not convicted Zhang of any crime. He remains free, and the search for him continues.

Share this article

About the Author

Joahn G

Joahn G

Cyber Threat Journalist

Joahn is a cyber threat journalist dedicated to tracking the evolving landscape of digital risks. His reporting focuses on ransomware gangs, data breach incidents, and state-sponsored cyber operations. By analyzing threat actor motives and tactics, he provides timely intelligence that helps readers understand and anticipate the security challenges of tomorrow.

View all posts by Joahn G >
Comments (0)

No comments.