US Offers $10M Reward for Fugitive Linked to HAFNIUM Hacks

The U.S. State Department has announced a reward of up to $10 million for information to track down Zhang Yu, a Chinese national indicted for his involvement in the HAFNIUM attacks on Microsoft Exchange Server. The reward seeks information leading to Zhang’s identification or location through the department’s Rewards for Justice program.

Background: Who’s Zhang Yu?

Zhang remains at large and hasn’t stood trial. He’s charged alongside Xu Zewei in a 2023 federal indictment unveiled publicly in July 2025. The pair are accused of orchestrating cyberattacks from February 2020 through June 2021, targeting U.S. critical infrastructure. Zhang is alleged to have held a director role at Shanghai Firetech Information Science and Technology and acted under the direction of the Shanghai State Security Bureau while supervising hacking efforts carried out by others. Xu, tied to another Shanghai company called Powerock Network, has already been arrested, extradited from Italy to the U.S. in April 2026.

The HAFNIUM Operation

The HAFNIUM campaign, exposed in March 2021, exploited multiple zero-day vulnerabilities in Microsoft Exchange Server—including a critical one known as ProxyLogon. It is credited with penetrating an estimated 12,700 U.S. organizations and has been linked to hackings of universities and companies involved in COVID-19 research. The U.S. government has officially attributed the operation to the Chinese Ministry of State Security (MSS), naming HAFNIUM (now tracked by Microsoft as Silk Typhoon) as a state-sponsored actor.

What’s New: The $10 Million Incentive

The State Department’s new offer via the Rewards for Justice program matches a previous offer from January 2025 aimed generally at anyone hacking U.S. critical infrastructure on behalf of a foreign government. While the language echoes that earlier announcement, this time it’s explicitly connected to Zhang Yu and the ongoing HAFNIUM case. The appeal comes amid ongoing efforts by U.S. authorities to bring him to justice in relation to cyberespionage against the U.S.

Authorities say Zhang Mu—allegedly in collaboration with Xu Zewei—participated in attacks orchestrated by the MSS. Xu, now in U.S. custody, is specifically charged with involvement in operations tied both to HAFNIUM and other espionage attacks targeting universities and firms working on COVID-19 research and treatments.

The February 2020–June 2021 timeframe encompasses two major campaigns: initial intrusions into institutions engaged with COVID-19 efforts, and later, widespread attacks leveraging flaws in Exchange Server. The first forensic reports of these vulnerabilities—including the ProxyLogon exploit—were shared by Microsoft in March 2021, triggering emergency patches and exposure of the operation worldwide.

The indictment alleges Zhang’s role included supervising Firetech employees carrying out MSS-directed intrusions. In one incident, Xu told Zhang around January 30, 2021, that he had successfully compromised a Texas university’s network. Internal emails and documentation released as part of the legal case connect both men to multiple victims, including universities and an international law firm in Washington, D.C.

The U.S. Justice Department and the Rewards for Justice program now openly seek tips that could lead to Zhang’s whereabouts. Anyone with credible information is eligible for that up-to-$10 million reward.

Zhang’s charges remain untested in court due to his continued absence, whereas Xu’s case has progressed with his extradition, bringing matters closer to trial in the U.S. Vigilant monitoring and international cooperation continue to be central as investigators pursue Zhang.

What this means: Offering millions for a detained or missing hacker is part of a broader strategy in U.S. cybersecurity policy—one that combines legal indictments, public attribution, and monetary incentives to deter state-backed hacking. As of late, the U.S. has leaned heavily into these tools to pressure foreign adversaries, especially where digital attacks touch critical infrastructure. The effectiveness of this approach depends on both diplomatic leverage and individuals willing—or able—to come forward. Going forward, watch for signs that Zhang is located, or that evidence emerges to advance his case, and whether similar bounties are tied to other major cyber campaigns.