The U.S. State Department is offering a reward of up to $10 million for information that leads to the identification or location of Zhang Yu, a Chinese citizen facing charges in connection with the 2021 Microsoft Exchange Server intrusions known as HAFNIUM, according to a report published this week by The Hacker News. The reward comes through the department's Rewards for Justice program, which focuses on national security threats. Zhang remains at large and has not been arrested, with the charges against him yet to be tested in court.
Zhang and a co-defendant, Xu Zewei, face nine counts in a federal indictment filed in Houston dating from November 2023 and unsealed in July 2025. The alleged hacking activities occurred between February 2020 and June 2021, targeting both U.S. universities conducting COVID-19 research and organizations through vulnerabilities in Microsoft Exchange Server. The HAFNIUM campaign as a whole compromised more than 12,700 U.S. organizations, according to FBI estimates. Xu was arrested in Milan in July 2025 at U.S. request and extradited to the United States in April 2026. On or around January 30, 2021, Xu allegedly informed Zhang he had breached a Texas university's network, with victims including two Texas universities and an international law firm with a Washington, D.C. office.
U.S. authorities identify Zhang as a director at Shanghai Firetech Information Science and Technology, a Shanghai-based company. The indictment alleges he performed tasks assigned by the Shanghai State Security Bureau, oversaw hacking conducted by other Firetech employees, and coordinated the intrusions with Xu. The bureau operates as a branch of China's Ministry of State Security, an intelligence agency. Xu allegedly worked for Shanghai Powerock Network, which the Justice Department characterizes as one of numerous "enabling" companies that conducted hacking operations on behalf of the Chinese government. "Xu is one of many contractors the Chinese government uses to obscure its hand in cyber operations," said Brett Leatherman, assistant director of the FBI's Cyber Division. The Rewards for Justice program has distributed more than $250 million to over 125 individuals since 1984.
Microsoft disclosed the Exchange attacks on March 2, 2021, releasing patches for four zero-day vulnerabilities, including the flaw known as ProxyLogon. The company attributed the intrusions to HAFNIUM, describing it as "a group assessed to be state-sponsored and operating out of China," and now tracks the group as Silk Typhoon. Within days of Microsoft's disclosure, the company observed additional hacking groups exploiting the same vulnerabilities. In July 2021, the United States and allied governments publicly stated that hackers connected to the Ministry of State Security carried out the campaign. The indictment alleges two distinct sets of intrusions: the first in early 2020 targeted U.S. universities and scientists working on COVID-19 vaccines, treatment, and testing, while the second from late 2020 exploited the Microsoft Exchange Server flaws. The reward amount and language match an offer the program was already advertising in January 2025 for information on anyone who hacks U.S. critical infrastructure at the direction of a foreign government. For organizations still weighing the tradeoffs between contractor flexibility and direct oversight, the case illustrates how attribution eventually surfaces regardless of how many intermediary layers are deployed. The Justice Department's characterization of private companies as enablers suggests that commercial relationships won't shield participants from prosecution when state interests drive the activity.

