Security2 publishersIndependently confirmed2 min readPublished Updated
US offers $10 million for Hafnium suspect Zhang Yu after his alleged partner's extradition
State Department offers $10 million for information on the whereabouts of Zhang Yu, a Shanghai company director charged in the Hafnium hacking campaign. The bounty keeps the US case against two named men moving years after June 2021, when the indictment says the charged intrusions ended.
The Watch · Security desk

What happened
- Zhang's alleged partner, Xu Zewei, was arrested by Italian authorities while on vacation in Milan in July 2025 and extradited to the US in April.
- Prosecutors say both men hacked on orders from China's Ministry of State Security and the Shanghai State Security Bureau.
- The pair allegedly stole COVID-19 research from US-based universities, immunologists and virologists.
- The State Department says Zhang broke the Computer Fraud and Abuse Act with attacks that hit at least one university and a law firm.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure Xu came within reach only when he travelled to Italy. Zhang now carries the same exposure: the $10 million is aimed at learning where he is, and any trip abroad becomes a risk for him.
- precedent Charging a private company's director as an MSS-tasked hacker puts personal legal and travel risk on the contractor staff that prosecutors say carry out state intrusions.
- decision Defenders have nothing new to act on. The reward pays to locate a person over conduct years old, so patching and detection priorities stay where they were.
The nine-count indictment was unveiled last year. It covers intrusions that began in February 2020 [7]. Xu's arrest came four years and one month after the charged window closed [11], and his extradition took nine more months [12]. Zhang remains at large [6].
Prosecutors describe a chain of command. US officials say Zhang is director of Shanghai Firetech Information Science and Technology and worked on behalf of the Chinese government [2]. The two men allegedly reported back to supervising officers at the SSSB [9]. In one instance, according to prosecutors, Xu confirmed he "had compromised the network of a research university located in the Southern District of Texas" [9].
The charges cover two kinds of operation. One is targeted theft from researchers [3]. The other is what the indictment calls "the indiscriminate HAFNIUM computer intrusion campaign that compromised thousands of computers worldwide, including in the United States" [7].
Brett Leatherman, assistant director of the FBI's cyber division, gave the scale of that campaign last year. "Through HAFNIUM, the CCP targeted over 60,000 U.S. entities, successfully victimizing more than 12,700 in order to steal sensitive information," he said [10]. By his figures, about one targeted entity in five was compromised [13].
In the government's account, the same two contractors did both jobs: collection against specific targets, tasked by intelligence officers, and mass compromise [7][8]. That makes Hafnium, as charged, a sustained state-directed operation, not one opportunistic exploit run by freelancers. Every part of it is an allegation made by US officials and prosecutors [2][8].
What to watch
- Xu's proceedings in US federal court, where a plea or trial would put the government's evidence of MSS and SSSB tasking on the public record.
- Any detention of Zhang in a third country, the route that brought Xu into US custody.
- Further charges or reward offers naming other Shanghai Firetech staff.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence68
- Adoption
- Insufficient
- Hype gap+15
- Incentives45
- Confidence70
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
The State Department is offering $10 million for information on the whereabouts of Zhang Yu, a Chinese national accused of being a key figure in the Hafnium hacking campaign.
ReportedSupportedSource: The Record (Recorded Future News)3 sources— create a free account to open themView cited source - [2]
US officials claimed Zhang, director of Shanghai Firetech Information Science and Technology, worked on behalf of the Chinese government as part of an effort in which hackers breached thousands of computers and stole documents and emails.
ReportedSupportedSource: US officials, via The Record2 sources— create a free account to open themView cited source - [3]
Zhang allegedly worked alongside Xu Zewei and stole COVID-19 research from US-based universities, immunologists and virologists.
- [4]
The State Department said Zhang violated the Computer Fraud and Abuse Act through cyberattacks that targeted at least one university and a law firm.
ReportedSupportedSource: State Department, via The Record2 sources— create a free account to open themView cited source - [5]
Xu Zewei was arrested in July 2025 by Italian authorities while on vacation in Milan and was extradited to the US in April.
- [6]
Zhang remains at large.
- [7]
A nine-count indictment unveiled last year accused Zhang and Xu of "computer intrusions between February 2020 and June 2021, including the indiscriminate HAFNIUM computer intrusion campaign that compromised thousands of computers worldwide, including in the United States."
ReportedSupportedSource: Justice Department indictment, via The Record2 sources— create a free account to open themView cited source - [8]
Prosecutors said the men were ordered to conduct the hacks at the behest of the Ministry of State Security (MSS) and the Shanghai State Security Bureau (SSSB).
ReportedSupportedSource: Prosecutors, via The Record2 sources— create a free account to open themView cited source - [9]
The men allegedly reported back to supervising officers at the SSSB, including one instance where Xu confirmed that he "had compromised the network of a research university located in the Southern District of Texas."
ReportedSupportedSource: Prosecutors, via The Record2 sources— create a free account to open themView cited source - [10]
"Through HAFNIUM, the CCP targeted over 60,000 U.S. entities, successfully victimizing more than 12,700 in order to steal sensitive information," Brett Leatherman, assistant director of the FBI's cyber division, said last year.
ReportedSupportedSource: Brett Leatherman, FBI, via The Record2 sources— create a free account to open themView cited source - [11]
Xu's arrest in July 2025 came four years and one month after the indictment's charged window ended in June 2021.
- [12]
Xu's extradition in April came nine months after his July 2025 arrest.
- [13]
By the FBI's figures, about one in five targeted US entities (roughly 21%) was victimized.
Sources
2 independent publishers whose own reporting we read for this story.
- thehackernews.comU.S. Offers Up to $10 Million for Tips on Zhang Yu, Charged in HAFNIUM Hacks
1 article · October 8, 2026
- therecord.mediaUS posts $10 million reward for accused Chinese ‘Hafnium’ hacker
1 article · October 7, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
- Microsoft Exchange Server vulnerabilitiesFollow
- State-Sponsored HackingFollow
- Cybercrime Prosecution and SentencingFollow
Entities
- Shanghai Powerock NetworkFollow
- US State DepartmentFollow
- MicrosoftFollow
- Shanghai Firetech Information Science and TechnologyFollow
- ProxyLogonFollow
- Computer Fraud and Abuse ActFollow
- Shanghai State Security BureauFollow
- Federal Bureau of InvestigationFollow
- HafniumFollow
- Rewards for JusticeFollow
- Ministry of State Security (PRC)Follow
- Xu ZeweiFollow
- Brett LeathermanFollow
- Zhang YuFollow
- Microsoft Exchange ServerFollow