Breaking
Cyber CrimeDeveloping Story

US Puts $10M Bounty on Hafnium Hacker

The State Department is offering up to $10 million for information on Zhang Yu, accused of COVID-19 research theft and the Hafnium Exchange campaign.

··1 day ago·5 min read
a person holding a business card in front of a pile of coins
Photo by rc.xyz NFT gallery on Unsplash

The US Department of State is offering up to $10 million for information on a Chinese national accused of participating in the Hafnium campaign against Microsoft Exchange servers. The reward was announced Wednesday under the State Department's Rewards for Justice (RFJ) program.

The target is Zhang Yu, who is charged alongside Xu Zewei. Xu was extradited from Italy to the US in April 2026, while Zhang remains at large.

The Man Behind the Bounty

According to the State Department's Rewards for Justice program, Zhang is a director at Shanghai Firetech Information Science and Technology Company. RFJ alleges that he worked on behalf of the Shanghai State Security Bureau (SSSB), which is part of China's Ministry of State Security (MSS).

Zhang and Xu were named in a nine-count indictment unsealed in July 2025, days after Italian police arrested Xu in Milan at the request of the US. Xu has since appeared in federal court in Houston, while Zhang remains at large.

The charges against Zhang are not detailed in the RFJ announcement. The bounty was announced on Wednesday, according to the State Department.

COVID-19 Research and Exchange Exploits

According to the RFJ announcement, the alleged operation began in early 2020, when Zhang and Xu targeted COVID-19 research conducted by US-based universities and leading immunologists and virologists. The pair allegedly gained unauthorized access to steal sensitive information.

Starting in early 2020, Zhang and his partner Xu Zewei, then a general manager at Shanghai Powerock Network Co. Ltd., gained unauthorized access to COVID-19 research conducted by US-based universities and leading immunologists and virologists to steal sensitive information

— Rewards for Justice, US Department of State

The following year, the two allegedly exploited vulnerabilities in Microsoft Exchange Server as part of the Hafnium campaign. RFJ says the campaign compromised thousands of computers worldwide, with victims including a US university and a US law firm.

Microsoft disclosed the Hafnium attacks in March 2021 and now tracks the threat actor as Silk Typhoon. When Xu was extradited, the FBI said the campaign had compromised more than 12,700 US organizations.

What the Reward Covers

The reward falls under an RFJ offer for information on anyone who targets US critical infrastructure in violation of the Computer Fraud and Abuse Act while acting at the direction or under the control of a foreign government. The program announced the Zhang reward on Wednesday.

RFJ did not specify exactly what information is sought, only that the reward is for details on Zhang. The State Department did not say whether the reward has already generated any leads.

The Indictment and the Extradition

The nine-count indictment against Zhang and Xu was unsealed in July 2025, just days after Italian police arrested Xu in Milan at the request of the US. Xu's extradition followed in April 2026. He has since appeared in federal court in Houston.

Zhang remains at large, and the State Department is now seeking information on his whereabouts or activities through the RFJ program.

Details on how Xu's extradition was arranged or how long it took are not included in the RFJ announcement. The State Department also did not provide information on the specific charges in the indictment beyond the count total.

Scale of the Hafnium Campaign

The Hafnium campaign compromised thousands of computers worldwide, according to RFJ. The FBI said the operation affected more than 12,700 US organizations when Xu was extradited. The victims included a US university and a US law firm, per RFJ.

Microsoft disclosed the Hafnium attacks in March 2021. The company now tracks the threat actor as Silk Typhoon, a designation the source article links to. The campaign's exploitation of Exchange Server vulnerabilities is the second phase of the alleged operation described by RFJ, following the COVID-19 research targeting that began in early 2020.

Rewards for Justice and State-Sponsored Actors

The reward for Zhang falls under an existing RFJ offer covering individuals who target US critical infrastructure in violation of the Computer Fraud and Abuse Act while acting at the direction or under the control of a foreign government.

The RFJ program has previously offered rewards for information on state-sponsored cyber actors. In a related case, the US charged 17 Iranian hackers and offered $10 million rewards for five of them, according to a SecurityWeek report.

That earlier case involved a separate set of actors and charges. The RFJ program has also been used to seek information on individuals accused of targeting US critical infrastructure on behalf of foreign governments.

What's Next in the Case

Zhang remains at large, and the State Department is now offering up to $10 million for information on him. Xu has appeared in federal court in Houston following his extradition from Italy in April 2026. The indictment against both men was unsealed in July 2025.

The RFJ announcement does not specify a timeline for the reward or indicate whether any information has been received. The State Department has not said whether additional rewards are planned for other individuals tied to the Hafnium campaign.

The case is part of a broader set of US actions targeting alleged Chinese state-sponsored hacking. In a separate development, China's top cybersecurity firms have faced mounting military procurement bans, according to SecurityWeek reporting. The US has also charged 17 Iranian hackers and offered $10 million rewards for five of them.

Why It Matters

For organizations, the Hafnium campaign remains a reminder of the risks posed by unpatched Exchange servers and the value of timely threat intelligence. The $10 million reward for Zhang could encourage informants to come forward with details on his whereabouts or activities, though it is not clear how effective such offers are in practice.

The reward and the ongoing prosecution send a message that the US is willing to pursue alleged state-sponsored hackers years after their campaigns, and that international cooperation, as demonstrated by Italy's arrest and extradition of Xu, can play a role in bringing alleged perpetrators to justice. For businesses that rely on Exchange or similar collaboration platforms, the case also underscores the importance of applying patches and monitoring for signs of compromise, given the scale of the Hafnium campaign and the number of organizations affected.

The case also illustrates the long memory of law enforcement and the potential consequences for those who carry out state-directed cyberattacks, even if it takes years to bring charges and secure extraditions.

#hafnium#rewards for justice#china#exchange server#state-sponsored hacking#extradition

Sources

Iliyas

Founder & Editor, Xploitwire

This article was written and reviewed against the sources listed above before publication, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories