Therecord.Media US Offers $10 Million Reward for Hafnium Hacker Zhang Yu
Article Content
- •Zhang Yu is accused of leading the Hafnium hacking campaign targeting U.S. entities.
- •The U.S. offers a $10 million reward for information on Zhang's whereabouts.
- •Xu Zewei, Zhang's accomplice, was arrested and extradited to the U.S. in 2026.
The U.S. State Department has announced a $10 million reward for information on Zhang Yu, a Chinese national accused of leading the Hafnium hacking campaign. Zhang, director at Shanghai Firetech Information Science and Technology, allegedly collaborated with Xu Zewei to breach computers and steal sensitive COVID-19 research from U.S. universities and a law firm. The hacking campaign, which occurred between February 2020 and June 2021, compromised over 12,700 entities worldwide. Zhang is charged with violating the Computer Fraud and Abuse Act, while Xu was arrested in July 2025 and extradited to the U.S. in April 2026. The Hafnium campaign exploited vulnerabilities in Microsoft Exchange Server, affecting thousands of computers globally. The FBI has indicated that the Chinese Communist Party (CCP) directed these operations through its intelligence services.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Hafnium and Shanghai Firetech Information Science And Technology in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What specific actions did Zhang Yu take?
What is the current status of Zhang Yu?
What are the implications of the Hafnium campaign?
Continue Reading
FBI Disrupts Chinese State-Sponsored Exploitation of Microsoft Exchange Vulnerabilities On April 13, 2021, the FBI executed a novel operation to remove malicious web shells from U.S.-based computers, attributed to the Chinese state-sponsored group Hafnium. These web shells exploited zero-day vulnerabilities in Microsoft Exchange servers, allowing unauthorized access and persistent malware deployment.…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited In late September 2026, two critical zero-day vulnerabilities (CVE-2026-88771 and CVE-2026-88772) in Citrix NetScaler ADC and Gateway were actively exploited, allowing remote code execution. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on…