The U.S. Department of State’s Rewards for Justice program is offering up to $10 million for information on Zhang Yu, a Chinese national accused of taking part in cyber operations linked to China’s Ministry of State Security. U.S. authorities allege that Zhang Yu and his co-conspirator, Xu Zewei, targeted American universities and scientists working on COVID-19 vaccines, treatments and testing.
Investigators later connected the pair to the wider HAFNIUM cyber campaign, which exploited Microsoft Exchange servers and compromised thousands of organizations. Xu Zewei was arrested in Milan in July 2025 and extradited to the United States in April 2026, where he now faces federal charges. Zhang Yu remains at large.
The case offers a rare look at how U.S. officials say Chinese intelligence services use private technology companies and cyber contractors to collect scientific, political and strategic information from foreign targets.
Who is Zhang Yu?
Zhang Yu, also written as 张宇, is a Chinese national identified by the U.S. Department of State’s Rewards for Justice program. U.S. authorities say he served as a director of Shanghai Firetech Information Science and Technology Company Ltd.
American prosecutors allege that Zhang worked at the direction of the Shanghai State Security Bureau, a regional branch of China’s Ministry of State Security.
The U.S. government says Chinese intelligence agencies sometimes work with private technology companies and cyber contractors to carry out operations against foreign targets.
Why is the U.S. offering $10 million for Zhang Yu?
The U.S. Department of State is offering up to $10 million for information that could help identify or locate Zhang Yu.
Rewards for Justice says Zhang participated in malicious cyber activity while allegedly acting at the direction of China’s Ministry of State Security.
Zhang remains at large.
The reward does not automatically mean someone will receive the full $10 million for any information. The U.S. government decides whether information qualifies and how much any reward should be.
The alleged target: COVID-19 research
According to the U.S. Department of Justice, Zhang Yu and Xu Zewei targeted American universities and researchers during the early stages of the COVID-19 pandemic.
Their alleged targets included scientists working on COVID-19 vaccines, treatments and testing.
Prosecutors say the hackers tried to gain unauthorized access to research conducted by leading immunologists and virologists.
This happened at a time when governments and pharmaceutical companies around the world were racing to understand the coronavirus and develop effective vaccines.
How the COVID-19 research operation allegedly worked
U.S. prosecutors say that on February 19, 2020, Xu Zewei told an officer of the Shanghai State Security Bureau that he had compromised the network of a research university in Texas.
Three days later, prosecutors allege that the intelligence officer instructed Xu to target email accounts belonging to specific virologists and immunologists.
Investigators say Xu later reported that he had obtained material from those researchers’ email accounts.
The allegations remain unproven in court.
Zhang Yu and Xu Zewei charged together
A U.S. federal grand jury returned a nine-count indictment against Zhang Yu and Xu Zewei in November 2023.
The indictment accused them of participating in cyber intrusions between February 2020 and June 2021.
The charges include allegations involving unauthorized access to protected computers, wire fraud, intentional damage to computer systems and aggravated identity theft.
An indictment contains allegations. It does not establish guilt.
The HAFNIUM connection
The Zhang Yu case later became connected to one of the most serious Chinese-linked cyber campaigns disclosed in recent years: HAFNIUM.
Beginning in late 2020, hackers exploited security weaknesses in Microsoft Exchange Server.
Microsoft Exchange is widely used by governments, universities, companies and other organizations for email and internal communications.
In March 2021, Microsoft publicly revealed that attackers operating from China had exploited previously unknown vulnerabilities in Exchange Server.
The hackers could gain access to compromised servers and install tools that allowed continued remote access.
More than 12,700 U.S. organizations affected
The FBI said the HAFNIUM campaign associated with the case compromised more than 12,700 organizations in the United States.
Thousands of computer systems around the world were also affected.
This made the operation much larger than a traditional intelligence mission targeting only a small number of carefully chosen organizations.
The U.S. and several allied governments later attributed HAFNIUM-related activity to actors linked to China’s Ministry of State Security.
Why Microsoft Exchange became important
A compromised email server can contain enormous amounts of sensitive information.
Attackers may gain access to:
- internal emails,
- documents,
- employee information,
- confidential research,
- government communications,
- business negotiations,
- and information about outside contacts.
This is why the Microsoft Exchange vulnerabilities became such a serious cybersecurity issue.
February 2020 — COVID-19 research targeted
2020–2021 — Microsoft Exchange attacks
November 2023 — Federal indictment
July 3, 2025 — Xu arrested in Italy
April 25, 2026 — Xu extradited to America
2026 — $10 million reward for Zhang Yu
Xu Zewei arrested in Italy
Xu Zewei remained outside U.S. custody for years.
That changed when he traveled to Europe.
Italian authorities arrested Xu in Milan on July 3, 2025, following a request from the United States.
The arrest gave U.S. prosecutors their first opportunity to bring one of the two accused men into the American justice system.
Xu Zewei extradited to the United States
Italy later approved Xu’s extradition.
He arrived in U.S. custody on April 25, 2026 and appeared in federal court in Houston.
Xu now faces the charges contained in the nine-count indictment.
Zhang Yu remains outside U.S. custody.
That difference explains why Washington is now focusing international attention on finding Zhang.
Why this case matters
The Zhang Yu case shows how modern espionage can operate without traditional spies entering secure government buildings.
A cyber operator can potentially obtain enormous amounts of information without leaving a computer.
One compromised university network can expose scientific research.
One email server can reveal years of private correspondence.
One law firm can hold information about government policy, corporations and political figures.
U.S. authorities argue that Chinese intelligence agencies increasingly combine government officers with private technology companies and cyber contractors.
Private hackers and China’s intelligence system
The case also highlights the role private companies allegedly play in Chinese cyber operations.
According to U.S. authorities, contractors can identify vulnerable networks, exploit computer systems and collect information that may interest Chinese intelligence agencies.
That structure can create distance between the Chinese government and the individuals actually carrying out an intrusion.
The United States has increasingly targeted not only government officials but also the companies and contractors that allegedly support these operations.
What happens next?
Xu Zewei now faces the U.S. justice system.
Zhang Yu remains at large.
The State Department’s Rewards for Justice program is offering up to $10 million for information connected to Zhang Yu.
If Zhang travels outside China, authorities could potentially attempt an arrest if he enters a country willing to cooperate with the United States.
The investigation may also reveal additional people, companies or intelligence officials connected to the alleged operation.
The bigger story behind the $10 million reward
The reward is eye-catching.
But the bigger story is what U.S. authorities say happened behind it.
Hackers allegedly targeted researchers working on COVID-19 vaccines and treatments during a global health emergency.
The same network later became associated with the massive HAFNIUM Microsoft Exchange campaign.
One alleged participant traveled abroad and ended up in U.S. custody.
The other remains at large.
That is why Washington is now willing to offer millions of dollars for information about Zhang Yu.
Legal note: Zhang Yu and Xu Zewei have been accused through a federal indictment. An indictment contains allegations and does not establish guilt. Defendants are presumed innocent unless and until prosecutors prove the charges in court.















Leave a Reply