The U.S. Department of State has announced a reward of up to $10 million for information leading to the capture of Zhang Yu, a Chinese national implicated in cyberattacks targeting American COVID-19 research. This initiative, part of the Rewards for Justice program, seeks insights into Zhang’s activities and connections, promising potential rewards and relocation for those providing eligible information.
Alleged Ties to Chinese Security
Zhang is accused of collaborating with the Shanghai State Security Bureau, under China’s Ministry of State Security. The FBI’s Cyber Division has emphasized this reward while noting the ongoing case against his alleged accomplice, Xu Zewei, currently detained in the U.S.
The cyber intrusions, detailed by the Justice Department, reportedly spanned from February 2020 to June 2021. Initial targets included American universities and researchers in the fields of vaccines and treatments for COVID-19. Intelligence officials are believed to have directed these hacking efforts, monitoring their progression closely.
Details of the Cyber Attacks
According to court filings, on February 19, 2020, Xu allegedly informed an officer from the Shanghai State Security Bureau about breaching a university in Texas. Shortly thereafter, he was instructed to access specific email accounts of researchers involved in COVID-19 studies.
Prosecutors claim that Xu successfully extracted data from these accounts, marking a clear case of data theft rather than mere attempted breaches. However, the public records do not disclose the university’s identity or the specific documents obtained.
Connection to HAFNIUM Campaign
The investigation also links Zhang and Xu to the HAFNIUM hacking campaign targeting Microsoft Exchange Servers. Starting in late 2020, this group allegedly exploited server vulnerabilities to infiltrate email systems, as publicly revealed by Microsoft in March 2021. This led to the release of patches and guidance for affected systems.
Using these vulnerabilities, hackers reportedly installed web shells, enabling remote server control. At one law firm, attackers searched emails for terms like “Chinese sources” and “MSS.” The FBI reports that this campaign affected over 12,700 U.S. organizations, though not all were related to COVID-19 research.
Xu was apprehended in Milan on July 3, 2025, and extradited to the U.S. where he appeared in Houston federal court on April 27, 2026. Zhang remains at large, with both facing charges in a nine-count indictment, which are not yet proven in court.
Broader Implications and Future Outlook
Prior reporting by Cyber Security News highlighted Chinese companies tied to Xu and Zhang, with patents for data collection tools linked to Shanghai Powerock and Shanghai Firetech. These insights shed light on the contractor network potentially facilitating these hacks.
The Justice Department asserts that China often utilizes private firms to obscure its involvement in cyber activities, with such breaches potentially exposing systems to further attacks by independent threat actors.
The Rewards for Justice program invites tipsters to use its Tor-based reporting channel, offering possible relocation and cryptocurrency payments for useful information on state-sponsored cyber activities.
