The U.S. government has put a price on catching one of the men accused of being behind one of the most damaging hacking campaigns in recent memory.
The U.S. State Department has announced a reward of up to $10 million for information leading to the identification or location of Zhang Yu, a Chinese national federally charged in connection with the 2021 Microsoft Exchange Server attacks known as the HAFNIUM campaign.
What happened
Zhang Yu and a second man, Xu Zewei, were indicted together in federal court in Houston on a nine-count indictment. The indictment, filed in November 2023 and unsealed in July 2025, accuses Zhang of directing hacking operations out of Shanghai Firetech Information Science and Technology, a company U.S. authorities say carried out tasking assigned by China's Shanghai State Security Bureau — a branch of the Ministry of State Security (MSS).
Prosecutors allege two waves of intrusions. In early 2020, the pair allegedly targeted U.S. universities and researchers working on COVID-19 vaccines, treatments, and testing. From late 2020, the campaign shifted to exploiting then-unknown flaws in Microsoft Exchange Server — activity Microsoft would later publicly attribute to a group it named HAFNIUM, now tracked as Silk Typhoon. Investigators say Xu worked through a separate Shanghai firm, Shanghai Powerock Network, which the Justice Department describes as one of several "enabling" companies China's government uses to carry out hacking while keeping official involvement at arm's length. Alleged victims include two Texas universities and an international law firm with a Washington, D.C. office.
Xu Zewei was arrested in Milan in July 2025 and extradited to the United States in April 2026. Zhang remains at large. The $10 million reward is offered through the State Department's Rewards for Justice program, which has paid out more than $250 million to over 125 people since 1984.
Why it matters
Microsoft disclosed the Exchange Server attacks on March 2, 2021, patching four zero-day vulnerabilities — including the flaw known as ProxyLogon — after HAFNIUM began exploiting them to break into mail servers. Within days, multiple other threat actors piled onto the same flaws, and the FBI estimates the combined campaign compromised more than 12,700 organizations in the United States alone.
More than five years on, the case is a reminder that the fallout from unpatched on-premises Exchange servers didn't end when the emergency patches shipped — some of that access, and the infrastructure behind it, has had a long operational life, and the group behind it (now Silk Typhoon) remains active under a new name. It's also a window into how state-linked hacking operations are structured: contractors and front companies carry out the intrusions, giving a government plausible deniability while absorbing the legal risk themselves.
What to do
- Confirm Exchange Server patch status, even on systems believed remediated years ago — verify there's no lingering web shell or backdoor left over from the original 2021 compromise wave.
- Retire on-premises Exchange where possible, or isolate it behind strict network segmentation and MFA if it must stay in production.
- Hunt for Silk Typhoon indicators and TTPs in your environment, particularly around credential theft and cloud/email pivoting, which the group has increasingly favored.
- Review third-party and contractor access to sensitive systems — the "enabling company" model in this case is a reminder that nation-state risk often arrives through an intermediary, not a direct actor.
- Keep incident response and threat-intel feeds current for nation-state activity tied to China, and report any credible information on fugitive threat actors through official law-enforcement channels.
