U.S. Offers Up to $10 Million for Tips on Zhang Yu, Charged in HAFNIUM Hacks
The U.S. State Department is offering a $10 million reward for information on Zhang Yu, a Chinese national charged in the 2021 HAFNIUM Microsoft Exchange Server attacks.
Intelligence analysis by Gemini 2.5 Flash Lite

The U.S. is actively seeking Zhang Yu, a Chinese national accused of involvement in the 2021 HAFNIUM cyberattacks. A $10 million reward is offered for information leading to his capture, highlighting the severity of the alleged breaches against critical infrastructure.
Imagine a detective is looking for a very sneaky person who broke into many computer systems. The detective is offering a huge reward, like $10 million, to anyone who can help find this person. This person is accused of helping a country's spies steal information and cause trouble online.
Analysis
Zhang Yu
The U.S. State Department's substantial $10 million reward for information leading to the identification or location of Zhang Yu signifies the high priority placed on apprehending individuals accused of significant cybercrimes. Zhang, a Chinese national, is charged in the United States in connection with the 2021 Microsoft Exchange Server attacks, widely known as HAFNIUM. Authorities allege that Zhang played a directorial role at Shanghai Firetech Information Science and Technology, a company reportedly tasked with executing cyber operations for China's Ministry of State Security (MSS). His alleged responsibilities included supervising hacking activities and coordinating efforts with other individuals, such as Xu Zewei, who has since been arrested and extradited.
HAFNIUM
The HAFNIUM campaign, disclosed by Microsoft in March 2021, exploited four zero-day vulnerabilities in Microsoft Exchange Server, including the widely publicized ProxyLogon flaw. This campaign is assessed by Microsoft and U.S. authorities as a state-sponsored operation originating from China, now tracked as Silk Typhoon. The FBI estimates that the HAFNIUM campaign compromised over 12,700 U.S. organizations. The indictment against Zhang and Xu details two sets of intrusions: one in early 2020 targeting U.S. universities and scientists involved in COVID-19 research, and a second, more extensive campaign from late 2020 that exploited the Exchange Server flaws. The alleged victims include academic institutions and an international law firm, underscoring the broad impact of these cyber intrusions.
Shanghai State Security Bureau
Zhang Yu's alleged activities were reportedly carried out under the direction of the Shanghai State Security Bureau, a branch of China's Ministry of State Security (MSS). This connection firmly places the alleged cyber activities within the realm of state-sponsored espionage and cyber warfare. The U.S. Justice Department views companies like Shanghai Firetech and Shanghai Powerock Network (allegedly associated with Xu Zewei) as 'enabling' entities used by the Chinese government to obscure its involvement in cyber operations. This strategy of using private companies and contractors allows nation-states to conduct malicious cyber activities while maintaining a degree of plausible deniability. The ongoing pursuit of Zhang Yu and the extradition of Xu Zewei highlight the U.S. government's strategy to hold both individuals and the entities that facilitate their actions accountable.
Key points
- The U.S. State Department is offering up to $10 million for information on Zhang Yu.
- Zhang Yu is charged in connection with the 2021 HAFNIUM attacks on Microsoft Exchange Servers.
- Authorities allege Zhang Yu worked for a company directed by China's Ministry of State Security.
- The HAFNIUM campaign is believed to have compromised over 12,700 U.S. organizations.
- Another individual charged in the case, Xu Zewei, has been arrested and extradited to the U.S.
The substantial reward offered could incentivize individuals with knowledge of Zhang Yu's whereabouts to come forward, potentially leading to his apprehension. Successful prosecution would send a strong message about accountability for state-sponsored cyberattacks and could deter future similar activities.
Despite the reward, Zhang Yu may remain at large due to his location or the reluctance of individuals to provide information, especially if they fear repercussions. The charges against him have not yet been tested in court, and the complexities of international cybercrime investigations can make apprehension and prosecution challenging.



