US Places Massive Bounty on Elusive Hacker
US bounty Chinese hacker Zhang Yu Hafnium campaign Microsoft Exchange
The United States government stands ready to pay up to 10 million dollars for critical information leading to the apprehension of Chinese hacker Zhang Yu. Authorities definitively link him to the massive and devastating Hafnium cyber espionage campaign. During these brazen attacks, malicious actors infiltrated thousands of vulnerable computer systems and pilfered sensitive correspondence. Unfortunately, the primary suspect remains entirely at large.
The Rewards for Justice Initiative
The US Department of State established this extraordinary reward through its renowned Rewards for Justice program. Zhang Yu currently holds a directorial position at Shanghai Firetech Information Science and Technology. According to American authorities, the hacker operated directly under the strict directives of the Shanghai State Security Bureau. This organization functions as a prominent branch within the broader structure of the Chinese Ministry of State Security.
Targeting Crucial COVID-19 Research
Investigators trace the genesis of the coordinated actions between Zhang and his accomplice, Xu Zewei, back to the turbulent year of 2020. Initially, their primary targets included esteemed American universities and dedicated coronavirus researchers. The assailants desperately sought confidential results regarding vaccine development, experimental treatments, and novel COVID-19 testing methodologies. In one notable instance, prosecutors assert that the hackers successfully compromised the private email inboxes of prominent virologists at a major university.
The Microsoft Exchange Compromise
Subsequently, the attacks pivoted aggressively toward corporate email infrastructures. The Hafnium operatives brilliantly weaponized four previously undiscovered vulnerabilities lurking within Microsoft Exchange Server. They systematically gained unauthorized access to targeted servers and covertly installed insidious web shells. This sophisticated technique allowed them to establish persistent remote control, enabling the hackers to silently read and exfiltrate countless emails. Microsoft eventually issued emergency patches to combat these exploits in March 2021.
The FBI did not reveal the true, horrifying scale of this campaign until 2025. According to the bureau’s comprehensive assessment, the attackers initially targeted over 60,000 American organizations. Shockingly, more than 12,700 entities suffered actual, verified compromises. These colossal figures represent the entirety of the Hafnium campaign, rather than solely the proven, individual actions of Zhang himself. Furthermore, thousands of additional computers experienced severe compromises well beyond the borders of the United States.
The Victims and the Indictments
The victims documented by the US Department of Justice notably included a university situated in Texas and an international law firm operating an office in Washington, D.C. Within the compromised legal correspondence, the attackers utilized specific keywords to actively hunt for sensitive information concerning American politicians and vital government agencies. The extensive case files also document a chilling message from Xu to Zhang, triumphantly reporting the successful breach of a university network in January 2021.
Authorities formally indicted both individuals on nine severe counts, encompassing hacking, fraud, and aggravated identity theft. Law enforcement apprehended Xu in Milan while he was visiting Italy in July 2025. Subsequently, they extradited him to the United States in April 2026. Conversely, Zhang Yu remains a highly sought fugitive. It is imperative to note that formal accusations do not legally equate to proven guilt.
The Ongoing Pursuit and Remediation
Within the official reward announcement regarding Zhang Yu, American authorities clarified their unwavering commitment. They are prepared to disburse up to 10 million dollars for actionable intelligence regarding his whereabouts. This reward also extends to identifying anyone involved in these state-sponsored cyberattacks. Naturally, the ultimate payout size directly correlates with the tactical value of the provided information.
The catastrophic consequences of the Hafnium campaign required extensive remediation efforts long after the initial updates were deployed. In the spring of 2021, the FBI secured an unprecedented court order. Armed with this authorization, they proactively removed the malicious web shells from hundreds of compromised Exchange servers across the United States. Authorities frequently cited this extraordinary operation when describing subsequent bureau actions against sophisticated malware threats. The sweeping criminal case regarding these massive intrusions remains resolutely open.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.