THE United States has announced a reward of up to $10 million for information leading to the capture of Zhang Yu, a Chinese national accused of involvement in the Hafnium cyber campaign against Microsoft Exchange servers. Zhang is charged alongside Xu Zewei, who was extradited from Italy to the US in April 2026.
The State Department’s Rewards for Justice programme stated that Zhang is a director at Shanghai Firetech Information Science and Technology Company and allegedly worked on behalf of the Shanghai State Security Bureau, part of China’s Ministry of State Security. The pair were named in a nine-count indictment unsealed in July 2025, days after Xu was arrested in Milan; Xu has since appeared in federal court in Houston, while Zhang remains at large.
RFJ describes that starting in early 2020, Zhang and Xu—Xu was then a general manager at Shanghai Powerock Network Co. Ltd.—gained unauthorized access to COVID-19 research conducted by US universities and leading immunologists to steal sensitive information. In 2021, they allegedly exploited vulnerabilities in Microsoft Exchange Server as part of Hafnium, compromising thousands of computers worldwide. Victims reportedly included a US university and a US law firm.
Microsoft previously disclosed the Hafnium attacks and now tracks the threat actor as Silk Typhoon; when Xu was extradited, the FBI said the campaign had compromised more than 12,700 US organisations. The RFJ reward falls under an offer for information on individuals targeting US critical infrastructure in violation of the Computer Fraud and Abuse Act under foreign-government direction.