THE U.S. State Department has announced a reward of up to $10 million for information leading to the arrest of Zhang Yu, a director at Shanghai Firetech Information Science and Technology. He is accused of playing a central role in the HAFNIUM campaign, the 2021 operation that targeted Microsoft Exchange servers globally.
U.S. prosecutors allege that Zhang, working under China’s Ministry of State Security via the Shanghai State Security Bureau, supervised employees involved in cyberattacks and collaborated with Xu Zewei.
The indictment describes two distinct campaigns. The first, beginning in early 2020, involved unauthorized access to research at U.S. universities and other institutions working on COVID-19 vaccines and treatments. The second, later that year, exploited vulnerabilities in Microsoft Exchange Server as part of HAFNIUM, compromising thousands of servers worldwide. Targeted entities included two Texas universities and an international law firm with offices in Washington.
Prosecutors allege that Zhang and Xu operated under state direction, with Xu reporting directly to Zhang about intrusions into the Texas university network. The Rewards for Justice programme notes the offer is for information identifying or locating individuals engaged in malicious cyber activity against U.S. critical infrastructure, under the Computer Fraud and Abuse Act. The case also notes Xu Zewei’s arrest in Milan in July 2025 and extradition to the U.S. in 2026; Zhang Yu remains at large.