Skip to content
U.S. Offers $10 Million Reward for Chinese Hacker Behind Alleged COVID

U.S. Offers $10 Million Reward for Chinese Hacker Behind Alleged COVID

Gbhackers •Divya • October 8, 2026

The U.S. Department of State is offering a reward of up to $10 million for information regarding Zhang Yu, a Chinese national accused of participating in cyberattacks that targeted American COVID-19 research.

This initiative, part of the Rewards for Justice program, seeks information Zhang, his associates, and their malicious cyber activities .

Zhang is alleged to have operated under the direction of the Shanghai State Security Bureau, which is part of China’s Ministry of State Security. His alleged partner, Xu Zewei, was extradited from Italy and appeared in federal court in Houston on April 27, 2026. Zhang, however, remains at large.

Reward for Chinese Hacker

According to the Justice Department, the cyber intrusions occurred between February 2020 and June 2021. Early targets included American universities and researchers, specifically immunologists and virologists studying coronavirus vaccines, treatments, and testing. Prosecutors allege that intelligence officers supervised the operations and received progress reports.

On February 19, 2020, Xu allegedly informed an intelligence officer that he had compromised a research university in the Southern District of Texas.

Just three days later, the officer instructed him to access specific email accounts belonging to researchers engaged in COVID-19 studies. Xu subsequently reported that he had successfully obtained the contents of the researchers’ mailboxes.

This indicates data theft rather than attempted access. However, the public case summary does not disclose the university’s name or provide a complete list of the stolen research.

Investigators also connect Zhang and Xu to the HAFNIUM campaign , which began in late 2020 when the attackers exploited vulnerabilities in Microsoft Exchange Server to compromise organizational email systems. Microsoft publicly disclosed this campaign in March 2021.

After gaining access, the attackers allegedly installed web shells, server-side scripts that enable remote administration. This access facilitated mailbox searches and the theft of information. At one targeted international law firm, prosecutors claimed that the intruders searched for terms such as “Chinese sources,” “MSS,” and “Hong Kong.”

The FBI attributes more than 12,700 compromised U.S. organizations to the broader HAFNIUM campaign. However, this figure does not confirm the specific COVID-19 research victims or systems that Zhang personally breached. Despite patches and detection guidance, hundreds of web shells remained active on affected American Exchange servers by late March 2021.

Xu allegedly worked for Shanghai Powerock Network. Cyber Security News reports have identified Shanghai Firetech as Zhang’s employer and have examined patents for intrusive data-collection technologies. These patents do not establish which specific tools were used during the intrusions.

The Justice Department says China’s contractor ecosystem obscures government involvement while leaving compromised systems vulnerable to exploitation by other actors. The nine-count indictment contains allegations, and both defendants are presumed innocent until proven guilty.

The Rewards for Justice program offers a Tor-based reporting channel for information foreign government-directed cyberattacks against U.S. critical infrastructure. Eligible sources of information may receive relocation assistance and cryptocurrency reward payments.

Stops Cyber threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC .

Artificial Intelligence

Cyber security Course

Cyber Security Resources

Cybersecurity

Information Gathering

Information Security Risks

12 Best SAST Tools Compared (2026): Features & Pricing

Critical Citrix NetScaler CVE-2026-88771 Exploited for Reverse Shells and Persistent Access

Hackers Abuse GitHub Actions to Steal SSH Keys, Cloud Credentials and Access Tokens

PoeLLM Malware Hijacks 3,400+ Servers for Crypto Mining and Botnet Expansion

Malicious npm Packages Steal Browser Passwords, Discord Tokens and Crypto Wallets.

EY Data Breach Exposes Goldman Sachs and Man Group Clients’ Tax and Financial Data

Extracted Entities