U.S. Offers $10 Million Reward for Alleged HAFNIUM Hacker Zhang Yu

The U.S. offers $10M for Zhang Yu, accused of helping run HAFNIUM attacks that compromised thousands of organizations worldwide.
The U.S. State Department is offering a $10 million reward for information leading to the arrest of Zhang Yu. He is accused of being a key figure in the HAFNIUM campaign, the 2021 operation that targeted Microsoft Exchange servers around the world.
Zhang is a director at Shanghai Firetech Information Science and Technology, a company that U.S. authorities say also carried out hacking operations for the Chinese government. According to the indictment, Zhang supervised Firetech employees involved in cyberattacks and worked directly with another accused hacker, Xu Zewei.
U.S. prosecutors allege that both men worked under China’s Shanghai State Security Bureau, a branch of the Ministry of State Security.
“Rewards for Justice (RFJ) is offering a reward of up to $10 million for information leading to the identification or location of any person who, while acting at the direction or under the control of a foreign government, participates in malicious cyber activities against U.S. critical infrastructure in violation of the Computer Fraud and Abuse Act.” reads the announcement published by the State Department. “Under this reward offer, RFJ seeks information on Zhang Yu, a Chinese national and director at Shanghai Firetech Information Science and Technology Company, Ltd. working at the behest of the People’s Republic of China (PRC) Ministry of State Security (MSS) Shanghai State Security Bureau (SSSB).”
U.S. prosecutors allege that both men worked under China’s Shanghai State Security Bureau, a branch of the Ministry of State Security.
The indictment covers two distinct hacking campaigns. The first, in early 2020, hit U.S. universities and scientists working on COVID-19 vaccines and treatments. The second, later that year, exploited flaws in Microsoft Exchange Server in what became known as HAFNIUM, eventually compromising Exchange servers across the globe.
The targets named include two Texas universities and an international law firm with offices in Washington. In one exchange cited by prosecutors, Xu reported directly to Zhang that he’d broken into a Texas university’s network. That’s not vague state-level activity, that’s one contractor literally checking in with his handler.
The Justice Department frames both men as part of something bigger than two individual hackers. Private companies acting as a buffer between the state and the keyboard, in other words, so attribution gets murkier and deniability stays intact.
“Starting in early 2020, Zhang and his partner Xu Zewei, then a general manager at Shanghai Powerock Network Co. Ltd., gained unauthorized access to COVID-19 research conducted by U.S.-based universities and leading immunologists and virologists to steal sensitive information.” continues the announcement. “The following year, Zhang and Xu exploited vulnerabilities in computers running Microsoft Exchange Server, a computer program involved in the storage and retrieval of e-mails. Those intrusions were part of mass intrusion campaign, publicly known as HAFNIUM, which compromised thousands of computers worldwide.”
The scale of HAFNIUM backs up why anyone would pay $10 million for a tip. The FBI puts the total at more than 12,700 compromised U.S. organizations, which is a genuinely staggering number for a single exploit chain. Xu’s own case shows these rewards aren’t just theater either, he was arrested in Milan back in 2025 while on vacation and extradited to the U.S. this past April.
Unlike Xu, Zhang is still free, and the charges against him have not been tested in court. Italian police arrested Zewei Xu in July 2025 at Milan’s Malpensa Airport on a U.S. warrant. Xu was arrested at Malpensa Airport on July 3rd after arriving on a flight from China. Authorities accused the man of cyberespionage, U.S. authorities linked him to the China-nexus group Hafnium (aka Silk Typhoon), which carried out attacks against U.S. government, including the US Treasury.
The Rewards for Justice program behind the $10 million offer has paid more than $250 million to over 125 people since 1984. Rewards for Justice (RFJ) is a U.S. Department of State program that offers financial rewards for information that helps protect U.S. national security. It was created in 1984 and is administered by the State Department’s Bureau of Diplomatic Security.
Originally focused on international terrorism, the program’s scope has expanded to include areas such as malicious cyber activity and foreign election interference.
Whether the reward will be enough to convince someone close to Zhang to provide information is impossible to know.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
Pierluigi Paganini
(SecurityAffairs – hacking, HAFNIUM)

