Skip to main content

US Seeks Alleged Chinese Hafnium Hacker With $10 Million Reward

0
High
News
Published: 10/08/2026 (10/08/2026, 12:46:21 UTC)
Source: SecurityWeek

Description

The US Department of State is offering a $10 million reward for information on Zhang Yu, a Chinese national accused of involvement in the Hafnium cyber espionage campaign targeting Microsoft Exchange servers. Zhang Yu, allegedly working for the Shanghai State Security Bureau, is charged alongside Xu Zewei, who was extradited to the US in 2026. The Hafnium campaign exploited vulnerabilities in Microsoft Exchange Server to compromise thousands of computers worldwide, including US universities and law firms. The campaign also involved unauthorized access to COVID-19 research data from US institutions. Zhang Yu remains at large, while Xu Zewei has appeared in US federal court.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 10/08/2026, 12:48:34 UTC

Technical Analysis

Zhang Yu, a Chinese national and director at Shanghai Firetech Information Science and Technology Company, is wanted by the US for his alleged role in the Hafnium cyber espionage campaign. This campaign, tracked by Microsoft as Silk Typhoon, exploited vulnerabilities in Microsoft Exchange Server starting in 2021 to compromise over 12,700 US organizations and thousands globally. Zhang and his partner Xu Zewei also allegedly accessed sensitive COVID-19 research data from US universities and leading scientists beginning in early 2020. Xu was extradited from Italy to the US in April 2026 and charged alongside Zhang in a nine-count indictment unsealed in July 2025. The US Department of State’s Rewards for Justice program is offering up to $10 million for information leading to Zhang’s capture. The campaign targeted US critical infrastructure and violated the Computer Fraud and Abuse Act while acting under direction of the Chinese Ministry of State Security.

Potential Impact

The Hafnium campaign compromised thousands of computers worldwide, including over 12,700 US organizations such as universities and law firms. Sensitive COVID-19 research data from US-based institutions was accessed without authorization. The campaign represents a significant breach of US critical infrastructure and intellectual property, with implications for national security and public health research confidentiality.

Defensive Guidance

This report does not provide specific remediation or patch information. Microsoft disclosed the Hafnium attacks in March 2021 and has since released patches for the exploited Microsoft Exchange Server vulnerabilities. Organizations should ensure their Microsoft Exchange servers are fully patched with the latest security updates. The US Department of State is actively seeking information on Zhang Yu and offers a reward for assistance. No additional mitigation guidance is provided in this report.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.3,"severitySource":"default","classifier":"rss-v2"}
Article Source
{"url":"https://www.securityweek.com/us-seeks-alleged-chinese-hafnium-hacker-with-10-million-reward/","fetched":true,"fetchedAt":"2026-10-08T12:48:24.241Z","wordCount":1025}

Threat ID: 6ac7911a2cdf04f656151dd3

Added to database: 10/08/2026, 12:48:26 UTC

Last enriched: 10/08/2026, 12:48:34 UTC

Last updated: 10/08/2026, 18:50:25 UTC

Views: 13

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses