"is one of many contractors the Chinese government uses to obscure its hand in cyber operations, and others who do the same face the same risk," Brett Leatherman, assistant director of the FBI's Cyber Division, said at the time.
The U.S. Rewards for Justice offer: up to $10 million
The U.S. State Department's Rewards for Justice program is offering up to $10 million for information leading to the identification or location of Zhang Yu, a Chinese national charged in the United States in connection with the 2021 Microsoft Exchange Server attacks known as HAFNIUM. The program's notice, reported by NTD and cited by other public reporting, frames the reward as specifically for information that will identify or locate Zhang. The department's national security rewards program says it has paid more than $250 million to over 125 people since 1984.
Officials noted that the amount and the wording of the new notice match an offer the program was already making in January 2025 for information on anyone who hacks U.S. critical infrastructure at the direction of a foreign government. Zhang remains at large, according to U.S. authorities, and the charges against him have not been tested in court.
The indictment: Zhang Yu and co-defendant Xu Zewei
Zhang Yu and a second man, Xu Zewei, are charged together in a federal indictment filed in Houston. The indictment contains nine counts, dates from November 2023, and was made public in July 2025. U.S. authorities describe Zhang as a director at Shanghai Firetech Information Science and Technology.
According to the indictment, Zhang worked on tasks assigned by the Shanghai State Security Bureau, supervised hacking by other Firetech staff, and coordinated the hacking with Xu. The notice identifies the Shanghai State Security Bureau as a branch of China's Ministry of State Security (MSS), an intelligence service. Xu allegedly worked for Shanghai Powerock Network; the Justice Department described Powerock as one of many "enabling" companies that hacked for the Chinese government, and said China uses private companies and contractors to hide its role.

The cyber insurance questionnaire just landed. Now what?
SOC 2, HIPAA, insurance renewals - someone has to own security strategy. Nubivance provides fractional CISO leadership without the full-time salary.
Get a security leadAlleged intrusions: universities, a law firm, and the Exchange zero-days
The indictment alleges two sets of intrusions. The first, in early 2020, targeted U.S. universities and scientists working on COVID-19 vaccines, treatment, and testing. The second, from late 2020, exploited flaws in Microsoft Exchange Server in the campaign later called HAFNIUM. The alleged intrusions took place between February 2020 and June 2021.
The alleged victims named in public materials include two Texas universities and an international law firm with an office in Washington, D.C. The record cites a specific exchange of operational information: on or about January 30, 2021, Xu allegedly told Zhang he had compromised a Texas university's network.
HAFNIUM, Microsoft, and the scale of the compromise
Microsoft disclosed the Exchange attacks on March 2, 2021, and released fixes for four zero-day flaws, including the one known as ProxyLogon. At the time Microsoft blamed HAFNIUM, describing it as "a group assessed to be state-sponsored and operating out of China," and Microsoft now tracks the group as Silk Typhoon. Within days of Microsoft's disclosure, other hacking groups also used the same flaws.
The FBI says the HAFNIUM campaign as a whole compromised more than 12,700 U.S. organizations. In July 2021, the United States and partner governments said hackers linked to the MSS carried out the campaign. The specific names Xu Zewei and Zhang Yu appear in the U.S. indictment, which laid out the allegations that later became part of public law-enforcement actions and the current reward offer.
What this means for U.S. universities, international law firms, and security teams
- U.S. universities: Two Texas universities are identified among alleged victims, and the indictment connects intrusions to academic research on COVID-19; university leaders will likely continue to monitor forensic findings and engagement requests from law enforcement tied to the indictment and reward offer.
- International law firms: An international law firm with a Washington, D.C., office is named as an alleged victim; law firms that work on cross-border matters may face heightened scrutiny of past incident response records and communications with affected clients.
- Security teams: The Microsoft Exchange zero-days (including ProxyLogon) and the broad FBI estimate of more than 12,700 compromised organizations underscore persistent risk from exploitation of critical enterprise software and the operational model described in the indictment—coordination between state security branches and private "enabling" companies.
Xu Zewei's arrest and transfer to the United States provide a point of contrast: Xu was arrested in Milan in July 2025 at the request of the United States and Italy extradited him to the United States in April 2026. Zhang, by contrast, remains at large; since the indictment was made public in July 2025 the Justice Department has asked the public for information about Zhang's whereabouts, and the State Department has added the Rewards for Justice incentive to that public appeal.
The reward offer places a financial spotlight on a case that ties alleged contractors and private companies to state-directed cyber operations, while the legal record — a nine-count indictment made public in 2025 — frames the U.S. response as both criminal and diplomatic. Whether the reward produces actionable intelligence that leads to Zhang's identification or location is the immediate question left by the record.




