The State Department is offering up to $10 million for information on the identity or whereabouts of Zhang Yu, a Chinese national charged in a nine-count hacking indictment. Its Rewards for Justice program posted the offer on October 7, calling him wanted for “malicious cyber activities against U.S. critical infrastructure.”
Zhang, 44, holds a director’s post at Shanghai Firetech Information Science and Technology. Prosecutors say he took direction from China’s Ministry of State Security and its Shanghai State Security Bureau.
🚨U.S. Department of State-Rewards for Justice is offering a reward up to $10 million for information on Zhang Yu, who is accused of working on behalf of China’s Ministry of State Security to gain unauthorized access into COVID-19 research conducted by U.S.-based universities and… pic.twitter.com/TqfmLdtSp7
— FBI Cyber Division (@FBICyberDiv) October 7, 2026
The indictment, filed in federal court in Houston, covers intrusions between February 2020 and June 2021. Prosecutors say Zhang, co-defendant Xu Zewei and others first went after US universities and researchers for COVID-19 vaccine, treatment and testing research, then exploited Microsoft Exchange Server flaws in the HAFNIUM campaign, which Microsoft now tracks as Silk Typhoon.
The FBI counts more than 12,700 compromised US organizations across the whole HAFNIUM operation, not just the COVID-era intrusions. US authorities say it targeted more than 60,000 entities. The US and partner governments tied HAFNIUM to the ministry in July 2021.
Italian authorities arrested Xu in Milan in July 2025 at Washington’s request, and Italy extradited him in April. He has since appeared in federal court in Houston. The Justice Department says he worked for Shanghai Powerock Network.