Security News

US Offers $10 Million Reward for Accused Chinese Hacker Linked to Hafnium Campaign

The Record · 8 Oct 2026
Key Takeaway Treat your business as a possible target even if you are small: keep systems patched, monitor for unusual activity, and know who to call if you suspect a breach.

The US State Department has announced a $10 million reward for information on the whereabouts of Zhang Yu, a Chinese national accused of being a key figure in the Hafnium hacking campaign. US officials say Zhang, director of Shanghai Firetech Information Science and Technology, worked on behalf of the Chinese government. They allege the campaign breached thousands of computers and led to the theft of large volumes of documents and emails.

According to the source, Zhang allegedly worked with another Chinese national, Xu Zewei, and together they stole COVID-19 research from US universities, immunologists and virologists. Authorities say Zhang's attacks targeted at least one university and a law firm, in breach of the Computer Fraud and Abuse Act. Xu was arrested by Italian authorities in July 2025 while on holiday in Milan and was extradited to the US in April. Zhang remains at large.

A nine-count indictment unveiled last year alleges the pair carried out intrusions between February 2020 and June 2021, acting on orders from China's Ministry of State Security and the Shanghai State Security Bureau. The FBI's Brett Leatherman said the campaign targeted more than 60,000 US entities and successfully compromised over 12,700 of them. The case shows that state-linked hackers can cast a wide net, and that organisations of many sizes can end up among the victims.

Hafnium State-sponsored hacking Cyber espionage US Department of Justice

Summarised by CISO AI from The Record, written with Claude Sonnet 5.5. We link back to every original so you can read it yourself.