2 Remove Virus

US offers $10 million reward for Chinese hacker linked to Microsoft Exchange attacks

The US government is offering a reward of up to $10 million for information that could help locate Zhang Yu, a Chinese national accused of participating in a major cyberespionage campaign that compromised thousands of American organizations.

 

 

Zhang is wanted in connection with the HAFNIUM hacking operation, which exploited security vulnerabilities in Microsoft Exchange email servers in 2021. The attacks allowed hackers to gain unauthorized access to corporate and government networks, potentially exposing sensitive emails and other confidential information.

According to US prosecutors, Zhang worked as a director at Shanghai Firetech Information Science and Technology, a company allegedly involved in carrying out cyber operations for China’s intelligence services. Investigators accuse him of coordinating hacking activities and supervising other employees involved in the operation.

The allegations extend beyond the Microsoft Exchange attacks. Prosecutors say Zhang and his alleged accomplice, Xu Zewei, also targeted American universities and researchers working on COVID-19 vaccines, treatments and testing during 2020.

The two men were named in a nine-count federal indictment issued in November 2023 and made public in July 2025. Their alleged victims included universities in Texas and an international law firm with an office in Washington, DC.

Xu was arrested in Italy in July 2025 and extradited to the United States in April 2026. Zhang, however, remains at large, prompting American authorities to continue seeking information about his location.

The HAFNIUM campaign became widely known in March 2021 when Microsoft disclosed several previously unknown vulnerabilities in Exchange Server. Attackers exploited these weaknesses to access vulnerable email systems, and other hacking groups subsequently began using the same security flaws.

US authorities say the wider campaign compromised more than 12,700 American organizations. Microsoft attributed the original activity to a China-based, state-sponsored hacking group, while US officials later connected the operation to China’s Ministry of State Security.

The reward is being offered through the State Department’s Rewards for Justice program, which provides financial incentives for information about individuals involved in national security threats.