The United States is intensifying its efforts to apprehend Zhang Yu, a Chinese national implicated in the 2021 Microsoft Exchange Server breaches attributed to the HAFNIUM group. The U.S. State Department has announced a reward of up to $10 million for details that could lead to Zhang’s identification or capture. This initiative is part of the Rewards for Justice program, which aims to bolster national security through public cooperation.
Details of the Reward Announcement
According to a recent report by NTD, the Rewards for Justice program, established by the State Department, has been instrumental in national security operations, disbursing over $250 million to informants since its inception in 1984. Despite charges being filed against Zhang, he remains at large, with his case yet to be adjudicated in any court.
The ongoing reward offer mirrors a previous call for information in January 2025, which sought tips on individuals involved in hacking U.S. critical infrastructure under foreign directives. Zhang’s alleged cyber activities have drawn significant attention, with authorities describing them as threats to U.S. security.
Legal Proceedings and Indictments
Zhang Yu, alongside Xu Zewei, faces charges in a federal court in Houston. Their indictment, publicized in July 2025, includes nine counts related to cyber espionage activities. The Justice Department has urged the public to assist in locating Zhang, highlighting the severity of his alleged crimes.
Xu Zewei was apprehended in Milan in July 2025 and subsequently extradited to the United States. The FBI’s Cyber Division emphasizes the risks faced by contractors engaged in cyber operations for the Chinese government, warning of potential legal consequences.
Allegations Against Zhang and Xu
Zhang is accused of directing operations at Shanghai Firetech Information Science and Technology, playing a key role in cyber activities coordinated with the Shanghai State Security Bureau. The indictment suggests Zhang oversaw hacking operations and worked closely with Xu, who was affiliated with Shanghai Powerock Network, another entity implicated in cyber espionage.
The charges detail two hacking campaigns: the first targeted U.S. academic institutions and COVID-19 research, while the second exploited Microsoft Exchange Server vulnerabilities, a campaign later dubbed HAFNIUM. These attacks reportedly affected over 12,700 U.S. organizations.
Impact of the HAFNIUM Breaches
Microsoft publicly disclosed the Exchange Server attacks in March 2021, attributing them to HAFNIUM, a group believed to be state-sponsored and operating from China. The disclosure prompted swift action, with software patches released to address the exploited vulnerabilities.
In conjunction with partner governments, the United States identified hackers linked to China’s Ministry of State Security as responsible for the campaign. The involvement of Zhang Yu and Xu Zewei, as outlined in the U.S. indictment, underscores the ongoing challenges in combating state-sponsored cyber threats.
The pursuit of Zhang Yu remains a high priority for U.S. authorities, reflecting the broader efforts to secure critical infrastructure from malicious cyber activities. The $10 million reward underscores the gravity of the situation and the commitment to bringing those responsible to justice.
