VYPR
breachPublished Oct 7, 2026· 1 source

US Offers $10 Million Reward for Accused Chinese 'Hafnium' Hacker Zhang Yu

The U.S. State Department has announced a $10 million reward for information leading to the arrest of Zhang Yu, a Chinese national allegedly involved in the widespread Hafnium hacking campaign.

The United States is intensifying its efforts to apprehend Zhang Yu, a Chinese national identified as a key figure in the notorious Hafnium hacking group, by offering a substantial $10 million reward for information leading to his arrest. U.S. officials have accused Zhang, who reportedly serves as the director of Shanghai Firetech Information Science and Technology, of acting on behalf of the Chinese government. This alleged state-sponsored operation compromised thousands of computers globally and exfiltrated vast quantities of sensitive documents and emails.

Zhang is specifically implicated in a campaign that targeted at least one university and a law firm, allegedly stealing critical data including COVID-19 research from U.S.-based academic institutions, immunologists, and virologists. These actions, according to the State Department, constitute violations of the Computer Fraud and Abuse Act. While Zhang remains at large, his alleged accomplice, Xu Zewei, was apprehended in Italy in July 2025 and subsequently extradited to the U.S. in April of this year.

A nine-count indictment unsealed last year detailed the Justice Department's accusations against Zhang and Xu. Prosecutors claim the duo engaged in extensive computer intrusions between February 2020 and June 2021, including the indiscriminate Hafnium campaign that impacted thousands of computers worldwide. The indictment further alleges that these cyberattacks were conducted under the direction of China's Ministry of State Security (MSS) and the Shanghai State Security Bureau (SSSB).

Evidence presented suggests that Zhang and Xu regularly reported their activities to supervising intelligence officers within the SSSB. In one instance, Xu confirmed the successful compromise of a research university's network located in the Southern District of Texas. This admission highlights the direct involvement of Chinese intelligence services in directing and benefiting from these sophisticated cyber intrusions.

The scale of the Hafnium campaign was immense. Last year, Brett Leatherman, assistant director of the FBI’s cyber division, stated that the Chinese Communist Party, through Hafnium, targeted over 60,000 U.S. entities, successfully victimizing more than 12,700 to steal sensitive information. This underscores the broad impact of the group's activities on American organizations and critical infrastructure.

The Hafnium campaign, which leveraged zero-day vulnerabilities in Microsoft Exchange Server, allowed attackers to gain initial access to victim networks. Once inside, they could steal credentials, deploy additional malware, and establish persistent access for espionage and data exfiltration. The group's ability to exploit multiple vulnerabilities simultaneously made detection and mitigation particularly challenging for affected organizations.

This reward offering signifies a significant escalation in the U.S. government's pursuit of individuals responsible for large-scale cyber espionage campaigns. By placing a high bounty on Zhang Yu, the U.S. aims to incentivize international cooperation and gather actionable intelligence that could lead to his capture and prosecution, thereby disrupting future operations by the Hafnium group and similar state-sponsored actors.

The ongoing efforts to bring Zhang Yu to justice reflect a broader strategy by the U.S. to hold nation-state actors accountable for cybercrimes. The Hafnium campaign serves as a stark reminder of the persistent threat posed by sophisticated state-sponsored hacking groups and the critical need for robust cybersecurity defenses and international law enforcement collaboration.

Synthesized by Vypr AI