The U.S. State Department has announced a reward of up to $10 million for information that could lead to the identification or location of Zhang Yu, a Chinese national charged in connection with the 2021 Microsoft Exchange Server attacks, known as HAFNIUM. Zhang is alleged to have played a significant role in these attacks, which compromised critical infrastructure in the United States. The State Department's Rewards for Justice program is behind this offer, which has historically paid out over $250 million to individuals providing valuable information since its inception in 1984.
Zhang and another individual, Xu Zewei, face charges in a federal court in Houston, outlined in an indictment consisting of nine counts. This document, which was issued in November 2023 and made public in July 2025, accuses them of orchestrating cyber intrusions between February 2020 and June 2021. While Xu was apprehended in Milan and extradited to the United States in April 2026, Zhang remains at large.
The indictment details two major sets of intrusions. The first targeted U.S. universities and scientific institutions involved in COVID-19 research in early 2020, while the second exploited vulnerabilities in Microsoft Exchange Server later that year. Microsoft publicly disclosed these attacks on March 2, 2021, attributing them to a group it identified as HAFNIUM, now referred to as Silk Typhoon. The campaign reportedly impacted over 12,700 U.S. organizations.
Zhang is associated with Shanghai Firetech Information Science and Technology, where he allegedly worked under the supervision of the Shanghai State Security Bureau, coordinating hacking activities with Xu. Xu, in turn, was linked to Shanghai Powerock Network, identified as one of the many companies allegedly used by the Chinese government to mask its involvement in cyber operations. The U.S. government continues to seek information on Zhang's whereabouts as part of ongoing efforts to combat state-sponsored cyber threats.

