[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$faWYH5eaJmAJo7SQrtBtZohDrOmxXZ1sqm4Bjo9N-K8w":3},{"article":4,"iocs":56},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":33,"category":34,"article_tags":38},"155c276b-5f0b-4fb9-8955-f1f959db126a","US Seeks Alleged Chinese Hafnium Hacker With $10 Million Reward","us-seeks-alleged-chinese-hafnium-hacker-with-10-million-reward-ff329b","Zhang Yu was charged alongside Xu Zewei, who was extradited from Italy to the US in April 2026. The post US Seeks Alleged Chinese Hafnium Hacker With $10 Million Reward appeared first on SecurityWeek.","The US Department of State is offering a $10 million reward for information on Zhang Yu, a Chinese national accused of participating in the Hafnium campaign against Microsoft Exchange servers. Zhang is alleged to have worked for the Shanghai State Security Bureau and targeted COVID-19 research and other sensitive data. He is charged alongside Xu Zewei, who was extradited from Italy to the US.","US offers $10M reward for info on alleged Chinese hacker Zhang Yu linked to Hafnium campaign.","The US Department of State is offering up to $10 million for information on Zhang Yu, a Chinese national accused of taking part in the Hafnium campaign against Microsoft Exchange servers. The State Department’s Rewards for Justice (RFJ) program announced the reward on Wednesday. Zhang is charged alongside Xu Zewei, who was extradited from Italy to the US in April 2026. According to RFJ, Zhang is a director at Shanghai Firetech Information Science and Technology Company. He allegedly worked on behalf of the Shanghai State Security Bureau (SSSB), part of China’s Ministry of State Security (MSS). Zhang and Xu were named in a nine-count indictment unsealed in July 2025, days after Italian police arrested Xu in Milan at the request of the US. Xu has since appeared in federal court in Houston, while Zhang remains at large. “Starting in early 2020, Zhang and his partner Xu Zewei, then a general manager at Shanghai Powerock Network Co. Ltd., gained unauthorized access to COVID-19 research conducted by US-based universities and leading immunologists and virologists to steal sensitive information,” RFJ said. The following year, the two allegedly exploited vulnerabilities in Microsoft Exchange Server as part of Hafnium. RFJ says the campaign compromised thousands of computers worldwide, and its victims included a US university and a US law firm.Advertisement. Scroll to continue reading. Microsoft disclosed the Hafnium attacks in March 2021 and now tracks the threat actor as Silk Typhoon. When Xu was extradited, the FBI said the campaign had compromised more than 12,700 US organizations. The reward falls under an RFJ offer for information on anyone who targets US critical infrastructure in violation of the Computer Fraud and Abuse Act while acting at the direction or under the control of a foreign government. Related: US Charges 17 Iranian Hackers, Offers $10 Million Rewards for 5 of Them Related: China’s Top Cybersecurity Firms Hit by Mounting Military Procurement Bans Related: Report Links Chinese Companies to Tools Used by State-Sponsored Hackers Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Eduard Kovacs Advantest Discloses Data Breach Months After Ransomware AttackAnthropic Introduces 3-Tier Cyber Verification Program for AI AccessWikimedia Says Rogue OpenAI Agents Tried to Turn Its Tools Into ProxiesFBI Blames Contractor’s Missed Patch for ShinyHunters BreachCybersecurity M&A Roundup: 39 Deals Announced in September 2026Google Narrows Open Source Bug Bounty Amid Wave of Invalid Automated ReportsExploitation of Citrix NetScaler Zero-Day Hits Appliances Patched Days EarlierCrypto Scammers Hijack Microsoft’s Official X Account Latest News SonicWall and Splunk Patch Critical VulnerabilitiesRein Security Raises $25 Million to Guard AI Agents at RuntimeTP-Link Faces State Lawsuits and New Scrutiny Over ISP Router FlawsFake Decryption Tools Masked $11M Markup in Ransomware Recovery SchemeOracle Health Data Breach Tally Climbs to Nearly 20 MillionFortiBleed Attackers Locking Victims Out of Fortinet DevicesGeorgia Power, Alabama Power Data Breach Hits 400,000 AccountsQilin Ransomware Suspect Arrested in Japan, Extradited to Germany Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Securing AI Agents, MCPs, and AI Automations October 7, 2026 Learn how to address potential risks and not restrict AI adoption in your organization. See what a centralized AI gateway is and how it works in practice. Register Virtual Event: Zero Trust & Identity Strategies Summit 2026 October 14, 2026 Join as we decipher the world of zero trust and share war stories on securing an organization by eliminating implicit trust and continuously validating every stage of a digital interaction. Register People on the MoveChip Wentz has been appointed as SVP & CISO at Keurig Dr Pepper Inc.Lumen Technologies has named Kim Keever as CSO.Quantum Secure Encryption Corp. has appointed Joseph Hall as CIO.More People On The MoveExpert Insights AI Has Changed Attack Speed, Not Security Fundamentals As AI accelerates vulnerability discovery and exploitation, so-called virtual patching still comes down to defense-in-depth and strong application security fundamentals. (Joshua Goldfarb) Four Cyber Threats Harboring Big Plans for the Future - AI, supply-chain exposure, quantum computing and geopolitical conflict are testing security programs. Preparing for disruption must become part of day-to-day operations. (Steve Durbin) Begin at the End: How to Enable Agentic Remediation Agentic remediation is not an act of faith. We are talking about fixing known problems, not judgment calls about unfamiliar risk. (Nadir Izrael) “We Think the Security Control Is Working” Is No Longer Good Enough Point-in-time audits and sampled assessments offer only snapshots; continuous control monitoring provides evidence that security controls are working today. (Sravish Sridhar) This Key Will Self-Destruct: An Open Standard for Revocable API Keys Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. (Matt Honea) Flipboard Reddit Whatsapp Whatsapp Email","https:\u002F\u002Fwww.securityweek.com\u002Fus-seeks-alleged-chinese-hafnium-hacker-with-10-million-reward\u002F","https:\u002F\u002Fwww.securityweek.com\u002Fwp-content\u002Fuploads\u002F2026\u002F10\u002FHafnium-hacker-reward.jpg","2026-10-08T12:46:21+00:00","2026-10-08T14:00:21.351042+00:00",8,[18,21,23,25,27,30],{"name":19,"type":20},"Zhang Yu","threat_actor",{"name":22,"type":20},"Xu Zewei",{"name":24,"type":20},"Hafnium",{"name":26,"type":20},"Silk Typhoon",{"name":28,"type":29},"Microsoft","vendor",{"name":31,"type":32},"Microsoft Exchange Server","product","6cbdd207-aaa1-4176-9534-e156b125e917",{"id":33,"icon":35,"name":36,"slug":37},null,"Nation-state","nation-state",[39,44,46,51],{"category":40},{"id":41,"icon":35,"name":42,"slug":43},"2e06f76c-d5b9-4f54-9eef-4d3447b10730","Breaches","breaches",{"category":45},{"id":33,"icon":35,"name":36,"slug":37},{"category":47},{"id":48,"icon":35,"name":49,"slug":50},"c5c77cdb-f7d7-4990-9436-c81dcbff1163","Policy","policy",{"category":52},{"id":53,"icon":35,"name":54,"slug":55},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[]]