Skip to content

$10 Million Wanted: Zhang Yu, the Man Charged in China's HAFNIUM Exchange Attacks, Remains at Large

$10 Million Wanted: Zhang Yu, the Man Charged in China's HAFNIUM Exchange Attacks, Remains at Large

The State Department's Rewards for Justice program is offering up to $10 million for information on Zhang Yu — the alleged director behind the HAFNIUM campaign's Exchange Server intrusions, who has never been arrested.

Wanted graphic for Zhang Yu, offered up to $10 million by the U.S. State Department Rewards for Justice program, October 2026
The U.S. State Department is offering up to $10 million for information on Zhang Yu's identity or location. Source: Generated by UnpanicTech.

Zhang Yu, 44, is a Chinese national who U.S. prosecutors say directed and supervised hacking operations for China's Ministry of State Security — including the wave of Microsoft Exchange Server intrusions that became known publicly as HAFNIUM. He has never been arrested. His co-defendant is in U.S. federal custody awaiting trial. And on October 7, 2026, the State Department's Rewards for Justice program posted a $10 million offer for information that could identify him or locate him [1].

The reward doesn't change the charges. Zhang remains innocent until proven guilty. What the offer does reflect is how seriously U.S. authorities treat the HAFNIUM case — and how long they've been trying to find him.

The Indictment and What It Alleges

The nine-count indictment against Zhang Yu and his co-defendant Xu Zewei was filed in November 2023 and made public in July 2025 when Xu was arrested in Milan [2]. The case is being prosecuted in federal court in Houston's Southern District of Texas, with support from the Justice Department's National Security Cyber Section.

According to prosecutors, Zhang held a director's position at Shanghai Firetech Information Science and Technology. The indictment portrays Firetech as one of a number of private Chinese companies that the Ministry of State Security uses as cover — conducting hacking on behalf of the government while obscuring official involvement. Zhang allegedly received direction from the Shanghai State Security Bureau (SSSB), a branch of the MSS, supervised Firetech staff in their hacking activities, and coordinated closely with Xu.

The charges themselves are serious. Conspiracy to commit wire fraud, multiple counts of wire fraud, conspiracy to cause damage to protected computers, unauthorized access to protected computers, intentional damage to protected computers, and aggravated identity theft. The maximum combined exposure across those nine counts runs into decades of potential prison time [2].

All of that, of course, assumes Zhang is ever brought to court.

Two Campaigns: COVID-19 Research, Then Exchange Servers

The indictment covers intrusions from February 2020 through June 2021 — roughly 16 months of alleged activity split across two distinct phases [2].

The first phase began in early 2020. Xu and his co-conspirators targeted U.S.-based universities, immunologists, and virologists who were actively working on COVID-19 vaccines, treatments, and diagnostic testing. According to court documents, Xu confirmed to an SSSB officer on approximately February 19, 2020 that he had breached a research university in the Southern District of Texas. Days later, the SSSB officer directed Xu to target specific mailboxes belonging to researchers at that university — and Xu later confirmed he had taken their email contents.

The second phase involved Microsoft Exchange Server. Beginning in late 2020, Xu and others exploited vulnerabilities in Exchange — the on-premises email and calendar system used by organizations worldwide. That exploitation was part of the campaign Microsoft eventually named HAFNIUM, which it publicly disclosed on March 2, 2021 alongside emergency patches for four zero-day vulnerabilities [3].

ProxyLogon exploit chain — HAFNIUM Exchange Server attack flow Four CVEs chained in sequence: CVE-2021-26855 bypasses authentication via SSRF, then CVE-2021-26857 achieves SYSTEM code execution, then CVE-2021-26858 and CVE-2021-27065 write arbitrary files, resulting in a persistent web shell. ProxyLogon exploit chain CVE-2021-26855 SSRF — auth bypass Pre-authentication CVE-2021-26857 Insecure deserialization SYSTEM code exec CVE-2021-26858 Arbitrary file write Post-authentication CVE-2021-27065 Arbitrary file write Post-authentication Web shell installed Persistent remote access to Exchange server CVE-2021-26855 requires no credentials — it opens the door for the entire chain Affected: Exchange Server 2010, 2013, 2016, 2019 (on-premises only) Conceptual diagram. Source: Generated by UnpanicTech.
The ProxyLogon chain: CVE-2021-26855 bypassed Exchange authentication; the remaining three CVEs enabled code execution and file writes, allowing web shell installation for persistent access. Conceptual diagram. Source: Generated by UnpanicTech.

The HAFNIUM intrusions were significant partly because of how the vulnerability chain worked. The lead flaw, CVE-2021-26855, was a server-side request forgery vulnerability in Exchange that let attackers bypass authentication entirely — accessing the server without valid credentials. Chained with the other three vulnerabilities (CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065), attackers could then execute code, write arbitrary files, and install web shells that gave them persistent remote access to the compromised system [3]. All four were zero-days — no patch existed when exploitation began.

The indictment notes that by the end of March 2021, hundreds of web shells were still active on U.S.-based Exchange servers despite Microsoft's emergency patches and a court-authorized FBI operation in April 2021 to remotely remove shells from some of the most persistently compromised machines. According to the FBI, the HAFNIUM campaign as a whole compromised more than 12,700 U.S. organizations [2].

On or about January 30, 2021, the indictment alleges, Xu told Zhang he had compromised a Texas university's network during the Exchange campaign. Zhang's role wasn't passive observation — prosecutors allege he coordinated the intrusion activity and supervised other Firetech staff in carrying it out.

The Contractor Model: How China Uses Private Companies

One thread running through the indictment is the structure that allegedly sits behind these operations. The Justice Department describes both Shanghai Firetech and Shanghai Powerock Network — the company Xu allegedly worked for — as "enabling" companies: private Chinese firms that conduct hacking on behalf of the MSS while putting some distance between the government and the operations themselves.

It's a model U.S. officials have described repeatedly in recent years. Private contractors and companies cast wide nets — scanning for vulnerable systems, exploiting them, and selling relevant intelligence to government handlers while discarding or monetizing data the government doesn't want. The indiscriminate nature of HAFNIUM fits this description. Tens of thousands of Exchange servers were hit, far more than a narrowly targeted espionage campaign would require.

Brett Leatherman, assistant director of the FBI's Cyber Division, made the point explicitly when Xu was extradited in April 2026: "He is one of many contractors the Chinese government uses to obscure its hand in cyber operations, and others who do the same face the same risk." [2]

The law firm among the alleged victims adds a notable detail. The indictment says Xu and co-conspirators searched stolen mailboxes for terms including "Chinese sources," "MSS," and "HongKong" — suggesting at least part of the operation was oriented toward policy intelligence rather than purely commercial or technical data.

Where the Two Defendants Stand

Defendant Age / Employer Arrest Status Current Status
Zhang Yu (张宇) 44 / Shanghai Firetech Never arrested — at large $10M reward posted Oct. 2026
Xu Zewei (徐泽伟) 34 / Shanghai Powerock Arrested Milan, July 2025; extradited April 2026 In U.S. federal custody; pleaded not guilty

Sources: DOJ USAO-SDTX [2]; The Hacker News [5].

Rewards for Justice and What $10 Million Actually Means

The Rewards for Justice program has been running since 1984, established under the Act to Combat International Terrorism. It's administered by the State Department's Bureau of Diplomatic Security and has paid out more than $250 million to more than 125 people over the decades for actionable tips on national security threats [4].

The program expanded its mandate beyond terrorism to cover malicious cyber activity — specifically targeting individuals who operate at the direction or under the control of a foreign government in violation of the Computer Fraud and Abuse Act. That's exactly the category Zhang allegedly falls into.

The Hacker News noted that a $10 million standing offer for information about anyone who hacks U.S. critical infrastructure under foreign government direction was already in place as of January 2025, and the notice for Zhang appears to reflect that same framework applied to him specifically [1]. The program accepts tips through encrypted messaging apps including Signal, Telegram, and WhatsApp, and also operates a Tor-based submission channel for anonymity [4].

Whether that's enough to surface Zhang's location is another matter. He's a Chinese national, apparently residing in China. The U.S. government has no extradition treaty with China, and Beijing is unlikely to hand him over voluntarily. The reward is most useful if Zhang travels internationally — which is how Xu was caught in Milan.

Timeline of key events in the HAFNIUM case, from February 2020 COVID-19 intrusions through October 2026 reward announcement
Key events in the HAFNIUM case, from the alleged intrusions in 2020–2021 through Xu Zewei's extradition and the October 2026 reward announcement for Zhang Yu. Source: Generated by UnpanicTech based on DOJ and public reporting.

HAFNIUM, Silk Typhoon, and the Attribution Question

Microsoft originally applied the name HAFNIUM to the threat actor it assessed as responsible for the initial Exchange zero-day exploitation — attributing the activity "with high confidence" to a state-sponsored group operating out of China. That attribution was based on observed tactics, victimology, and infrastructure, not on the identities of individual operators [3].

Microsoft now tracks the same group under the name Silk Typhoon, as part of a broader renaming scheme applied to nation-state threat actors. The connection between that group-level attribution and the individual defendants named in the U.S. indictment comes from the Justice Department's own case, not from Microsoft's threat intelligence.

Within days of Microsoft's March 2021 disclosure, other hacking groups — separate from the original HAFNIUM actors — began exploiting the same vulnerabilities against unpatched servers. That's worth noting because some of the broad HAFNIUM-era damage was opportunistic exploitation after the vulnerabilities became public knowledge, not all of it directed by the MSS contractors specifically named in this indictment.

In July 2021, the United States, European Union, and partner governments formally attributed the original Exchange campaign to hackers affiliated with China's MSS [5]. That governmental attribution preceded the indictment by more than two years.

What Comes Next — and What Probably Won't

Xu Zewei's case will eventually go to trial in Houston. He has pleaded not guilty, and his attorney told TechCrunch he denies any involvement in Chinese government hacking, claiming mistaken identity. That defense will be tested in court.

Zhang Yu's situation is different. Without a travel misstep that puts him within reach of a country willing to extradite, the case against him may sit unresolved for years. The reward is a signal — and a long shot. The U.S. has used similar offers to surface information on wanted individuals operating from countries with no extradition relationship, but outcomes vary widely.

The broader significance isn't really about Zhang Yu specifically. It's about the model his alleged activities represent. If prosecutors are right, he wasn't running a sophisticated military intelligence operation — he was a director at a small Shanghai tech company doing contract work for the MSS, assigning tasks and coordinating with a colleague. The HAFNIUM campaign was partly indiscriminate by design, sweeping up far more organizations than any targeted spy operation would need, because the contractor model is optimized for scale over precision.

That's what the FBI means when it says HAFNIUM "compromised more than 12,700 U.S. organizations." Not all of those were valuable targets. Many were just caught in the net.

Sources & References

  1. The Hacker News — "U.S. Offers Up to $10 Million for Tips on Zhang Yu, Charged in HAFNIUM Hacks" (October 8, 2026)
  2. U.S. Department of Justice, USAO-SDTX — "Prolific Chinese state-sponsored contract hacker extradited from Italy" (April 27, 2026)
  3. Microsoft Security Blog — "HAFNIUM targeting Exchange Servers with 0-day exploits" (March 2, 2021)
  4. U.S. State Department Rewards for Justice — Program Overview
  5. CISA — Advisory AA21-062A: Mitigate Microsoft Exchange Server Vulnerabilities (July 2021, updated)
NK

Naseem Khan (Technical Editor)

Cybersecurity Researcher & Technical Editor

UnpanicTech is supported by a dedicated team of cybersecurity specialists and writers. All research and articles are comprehensively reviewed and published by our Technical Editor, Naseem Khan, covering vulnerability analysis, defensive security, incident response, cloud security, and practical security engineering.

Technical Discussion & Feedback

Leave a Comment (Authenticated Users)