US Puts $10M Bounty on Hafnium Hacker
The State Department is offering up to $10 million for information on Zhang Yu, accused of COVID-19 research theft and the Hafnium Exchange campaign.
The US Department of State is offering up to $10 million for information on a Chinese national accused of participating in the Hafnium campaign against Microsoft Exchange servers. The reward was announced Wednesday under the State Department's Rewards for Justice (RFJ) program.
The target is Zhang Yu, who is charged alongside Xu Zewei. Xu was extradited from Italy to the US in April 2026, while Zhang remains at large.
The Man Behind the Bounty
According to the State Department's Rewards for Justice program, Zhang is a director at Shanghai Firetech Information Science and Technology Company. RFJ alleges that he worked on behalf of the Shanghai State Security Bureau (SSSB), which is part of China's Ministry of State Security (MSS).
Zhang and Xu were named in a nine-count indictment unsealed in July 2025, days after Italian police arrested Xu in Milan at the request of the US. Xu has since appeared in federal court in Houston, while Zhang remains at large.
The charges against Zhang are not detailed in the RFJ announcement. The bounty was announced on Wednesday, according to the State Department.
COVID-19 Research and Exchange Exploits
According to the RFJ announcement, the alleged operation began in early 2020, when Zhang and Xu targeted COVID-19 research conducted by US-based universities and leading immunologists and virologists. The pair allegedly gained unauthorized access to steal sensitive information.
Starting in early 2020, Zhang and his partner Xu Zewei, then a general manager at Shanghai Powerock Network Co. Ltd., gained unauthorized access to COVID-19 research conducted by US-based universities and leading immunologists and virologists to steal sensitive information
— Rewards for Justice, US Department of State
The following year, the two allegedly exploited vulnerabilities in Microsoft Exchange Server as part of the Hafnium campaign. RFJ says the campaign compromised thousands of computers worldwide, with victims including a US university and a US law firm.
Microsoft disclosed the Hafnium attacks in March 2021 and now tracks the threat actor as Silk Typhoon. When Xu was extradited, the FBI said the campaign had compromised more than 12,700 US organizations.
What the Reward Covers
The reward falls under an RFJ offer for information on anyone who targets US critical infrastructure in violation of the Computer Fraud and Abuse Act while acting at the direction or under the control of a foreign government. The program announced the Zhang reward on Wednesday.
RFJ did not specify exactly what information is sought, only that the reward is for details on Zhang. The State Department did not say whether the reward has already generated any leads.
The Indictment and the Extradition
The nine-count indictment against Zhang and Xu was unsealed in July 2025, just days after Italian police arrested Xu in Milan at the request of the US. Xu's extradition followed in April 2026. He has since appeared in federal court in Houston.
Zhang remains at large, and the State Department is now seeking information on his whereabouts or activities through the RFJ program.
Details on how Xu's extradition was arranged or how long it took are not included in the RFJ announcement. The State Department also did not provide information on the specific charges in the indictment beyond the count total.
Scale of the Hafnium Campaign
The Hafnium campaign compromised thousands of computers worldwide, according to RFJ. The FBI said the operation affected more than 12,700 US organizations when Xu was extradited. The victims included a US university and a US law firm, per RFJ.
Microsoft disclosed the Hafnium attacks in March 2021. The company now tracks the threat actor as Silk Typhoon, a designation the source article links to. The campaign's exploitation of Exchange Server vulnerabilities is the second phase of the alleged operation described by RFJ, following the COVID-19 research targeting that began in early 2020.
Rewards for Justice and State-Sponsored Actors
The reward for Zhang falls under an existing RFJ offer covering individuals who target US critical infrastructure in violation of the Computer Fraud and Abuse Act while acting at the direction or under the control of a foreign government.
The RFJ program has previously offered rewards for information on state-sponsored cyber actors. In a related case, the US charged 17 Iranian hackers and offered $10 million rewards for five of them, according to a SecurityWeek report.
That earlier case involved a separate set of actors and charges. The RFJ program has also been used to seek information on individuals accused of targeting US critical infrastructure on behalf of foreign governments.
What's Next in the Case
Zhang remains at large, and the State Department is now offering up to $10 million for information on him. Xu has appeared in federal court in Houston following his extradition from Italy in April 2026. The indictment against both men was unsealed in July 2025.
The RFJ announcement does not specify a timeline for the reward or indicate whether any information has been received. The State Department has not said whether additional rewards are planned for other individuals tied to the Hafnium campaign.
The case is part of a broader set of US actions targeting alleged Chinese state-sponsored hacking. In a separate development, China's top cybersecurity firms have faced mounting military procurement bans, according to SecurityWeek reporting. The US has also charged 17 Iranian hackers and offered $10 million rewards for five of them.
Why It Matters
For organizations, the Hafnium campaign remains a reminder of the risks posed by unpatched Exchange servers and the value of timely threat intelligence. The $10 million reward for Zhang could encourage informants to come forward with details on his whereabouts or activities, though it is not clear how effective such offers are in practice.
The reward and the ongoing prosecution send a message that the US is willing to pursue alleged state-sponsored hackers years after their campaigns, and that international cooperation, as demonstrated by Italy's arrest and extradition of Xu, can play a role in bringing alleged perpetrators to justice. For businesses that rely on Exchange or similar collaboration platforms, the case also underscores the importance of applying patches and monitoring for signs of compromise, given the scale of the Hafnium campaign and the number of organizations affected.
The case also illustrates the long memory of law enforcement and the potential consequences for those who carry out state-directed cyberattacks, even if it takes years to bring charges and secure extraditions.
Sources
- SecurityWeek Original source
- Silk Typhoon Also reporting
Continue Reading
YMCO Leader Pleads Guilty in Mule Case
A dual citizen admits to running a 15,000-mule money laundering network that moved millions for cybercriminals over nearly two decades.
Unpatched AhsayCBS Bugs Exploited as Zero-Days
Attackers are chaining two unpatched AhsayCBS vulnerabilities to gain remote code execution and deploy webshells, with at least five organizations targeted.
FBI Seizes Domains Tied to Chinese Hacking Tools
The FBI has seized seven domains linked to Chinese state-sponsored hackers, disrupting two key platforms used in attacks on critical infrastructure.