Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
U.S. Offers  Million Reward for Tips on Cyber Suspect Zhang Yu

U.S. Offers $10 Million Reward for Tips on Cyber Suspect Zhang Yu

Posted on October 8, 2026 By CWS

The United States is intensifying its efforts to apprehend Zhang Yu, a Chinese national implicated in the 2021 Microsoft Exchange Server breaches attributed to the HAFNIUM group. The U.S. State Department has announced a reward of up to $10 million for details that could lead to Zhang’s identification or capture. This initiative is part of the Rewards for Justice program, which aims to bolster national security through public cooperation.

Details of the Reward Announcement

According to a recent report by NTD, the Rewards for Justice program, established by the State Department, has been instrumental in national security operations, disbursing over $250 million to informants since its inception in 1984. Despite charges being filed against Zhang, he remains at large, with his case yet to be adjudicated in any court.

The ongoing reward offer mirrors a previous call for information in January 2025, which sought tips on individuals involved in hacking U.S. critical infrastructure under foreign directives. Zhang’s alleged cyber activities have drawn significant attention, with authorities describing them as threats to U.S. security.

Legal Proceedings and Indictments

Zhang Yu, alongside Xu Zewei, faces charges in a federal court in Houston. Their indictment, publicized in July 2025, includes nine counts related to cyber espionage activities. The Justice Department has urged the public to assist in locating Zhang, highlighting the severity of his alleged crimes.

Xu Zewei was apprehended in Milan in July 2025 and subsequently extradited to the United States. The FBI’s Cyber Division emphasizes the risks faced by contractors engaged in cyber operations for the Chinese government, warning of potential legal consequences.

Allegations Against Zhang and Xu

Zhang is accused of directing operations at Shanghai Firetech Information Science and Technology, playing a key role in cyber activities coordinated with the Shanghai State Security Bureau. The indictment suggests Zhang oversaw hacking operations and worked closely with Xu, who was affiliated with Shanghai Powerock Network, another entity implicated in cyber espionage.

The charges detail two hacking campaigns: the first targeted U.S. academic institutions and COVID-19 research, while the second exploited Microsoft Exchange Server vulnerabilities, a campaign later dubbed HAFNIUM. These attacks reportedly affected over 12,700 U.S. organizations.

Impact of the HAFNIUM Breaches

Microsoft publicly disclosed the Exchange Server attacks in March 2021, attributing them to HAFNIUM, a group believed to be state-sponsored and operating from China. The disclosure prompted swift action, with software patches released to address the exploited vulnerabilities.

In conjunction with partner governments, the United States identified hackers linked to China’s Ministry of State Security as responsible for the campaign. The involvement of Zhang Yu and Xu Zewei, as outlined in the U.S. indictment, underscores the ongoing challenges in combating state-sponsored cyber threats.

The pursuit of Zhang Yu remains a high priority for U.S. authorities, reflecting the broader efforts to secure critical infrastructure from malicious cyber activities. The $10 million reward underscores the gravity of the situation and the commitment to bringing those responsible to justice.

The Hacker News Tags:cyber espionage, Cybercrime, Cybersecurity, FBI, HAFNIUM, Microsoft Exchange, Rewards for Justice, Shanghai Firetech, U.S. State Department, Zhang Yu

Post navigation

Previous Post: Leading ASPM Platforms of 2026: A Comprehensive Overview
Next Post: Oracle Health Data Breach Exposes 20 Million Records

Related Posts

Hyper-Volumetric DDoS Attacks Reach Record 7.3 Tbps, Targeting Key Global Sectors Hyper-Volumetric DDoS Attacks Reach Record 7.3 Tbps, Targeting Key Global Sectors The Hacker News
Addressing Unanswered SOC Alerts in Cybersecurity Addressing Unanswered SOC Alerts in Cybersecurity The Hacker News
Tor Browser Vulnerability: A Single Webpage Visit Risk Tor Browser Vulnerability: A Single Webpage Visit Risk The Hacker News
Tengu Botnet Uses Watchdog to Restart Linux Devices Tengu Botnet Uses Watchdog to Restart Linux Devices The Hacker News
Preparing for Quantum Security: A Crucial Webinar Preparing for Quantum Security: A Crucial Webinar The Hacker News
CISA Adds Citrix NetScaler CVE-2025-5777 to KEV Catalog as Active Exploits Target Enterprises CISA Adds Citrix NetScaler CVE-2025-5777 to KEV Catalog as Active Exploits Target Enterprises The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Hackers Exploit GitHub Poem for AI Malware Control
  • Owner Charged in $11M Fraudulent Ransomware Scheme
  • Ransomware Fraud: MonsterCloud Owner Charged with $19M Scheme
  • Top SCA Tools of 2026: Comprehensive Review
  • Oracle Health Data Breach Exposes 20 Million Records

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Hackers Exploit GitHub Poem for AI Malware Control
  • Owner Charged in $11M Fraudulent Ransomware Scheme
  • Ransomware Fraud: MonsterCloud Owner Charged with $19M Scheme
  • Top SCA Tools of 2026: Comprehensive Review
  • Oracle Health Data Breach Exposes 20 Million Records

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark