Adversary Intelligence — 2026-10-09
US Offers 10 Million Dollar Bounty on Chinese MSS Hacker Zhang Yu Linked to HAFNIUM Campaign
BLUFZhang Yu is very unlikely to be arrested by November 9, 2026, as he is presumed inside China, leaving only an unpredictable foreign trip as a viable capture window.
The State Department's Rewards for Justice (RFJ) program is offering up to $10 million for information on Zhang Yu, a Chinese national and director at Shanghai Firetech Information Science and Technology Company, who remains at large 123. RFJ alleges he acted at the direction of the Ministry of State Security's Shanghai State Security Bureau and, with partner Xu Zewei, accessed U.S. university COVID-19 research from early 2020 13. The Cyber Express reported that the pair exploited Microsoft Exchange Server in 2021 as part of HAFNIUM, whose victims included a U.S. university and law firm 1. It also cited FBI Cyber Division Assistant Director Brett Leatherman's 2025 statement that the campaign targeted over 60,000 U.S. entities and compromised more than 12,700 1. Italy arrested Xu in July 2025, and he was extradited to the United States in April 2026 13. IBTimes UK noted that RFJ gives no location for Zhang and that it could not independently verify the allegations 3.
AnalysisZhang Yu is
very unlikely to be arrested or taken into custody anywhere in the world by November 9, 2026. Confidence is low because no location has been reported for him and the allegations lack independent confirmation, since the Cyber Express supplies the only original reporting and other outlets amplify the State Department notice. He is presumed to be in China, which does not extradite its nationals, so Washington's leverage is his travel abroad. Xu's arrest in Milan on vacation shows that overseas trips by MSS-linked contractors are the main exposure. The bounty may instead aim to deter contractor travel or build pressure ahead of Xu's trial. An arrest would let Justice build a second prosecution and give allies a template for acting on contractor travel. Without one, the reward remains a deterrence and tip-gathering tool, and agencies have no reason to shift resources.
4 sources
- US Puts $10 Million Bounty on Chinese Hacker Accused of Stealing COVID Research - The Cyber Express
- U.S. Offers $10 Million Reward for Chinese Hacker Who Tried to Steal COVID-19 Research - Cyber Security News
- US Seeks Chinese Hacker Zhang Yu Under $10M Reward Programme Over Alleged Theft of COVID-19 Research - IBTimes UK
- US Seeks Alleged Chinese Hafnium Hacker With $10 Million Reward - SecurityWeek
View in full brief →