The U.S. Department of State is offering up to $10 million for information that could help locate Chinese national Zhang Yu, who is accused of helping Chinese intelligence-linked hackers target U.S. COVID-19 research.

The Rewards for Justice program is seeking information about Zhang, his associates, and their alleged cyber activities. Eligible sources may also receive relocation assistance, according to U.S. authorities.

Prosecutors allege Zhang worked for the Shanghai State Security Bureau, an agency under China’s Ministry of State Security. The FBI Cyber Division promoted the reward while highlighting the case against Zhang’s alleged associate, Xu Zewei, who is currently in U.S. custody.

The alleged attacks took place between February 2020 and June 2021, according to the Justice Department. Early targets reportedly included American universities and researchers working on COVID-19 vaccines, treatments and testing.

Court documents say Xu told a Shanghai State Security Bureau officer in February 2020 that he had compromised a research university in Texas. A few days later, the officer allegedly instructed him to access specific email accounts belonging to researchers involved in COVID-19 research.

Prosecutors say Xu later reported that he had obtained the contents of those mailboxes. The allegations therefore involve the alleged theft of research-related email data rather than unsuccessful attempts to gain access.

The investigation also links Zhang and Xu to the HAFNIUM hacking campaign that targeted Microsoft Exchange servers. Attackers allegedly exploited Exchange vulnerabilities to compromise email systems before Microsoft publicly disclosed the campaign in March 2021.

READ
KillSec Ransomware Group Targeted in International Crackdown

Once inside targeted servers, the hackers allegedly installed web shells, giving them a way to remotely control compromised systems and search for email data. Investigators say attackers at one law firm searched for terms including “Chinese sources,” “MSS” and “HongKong.”

The FBI has said the broader HAFNIUM campaign compromised more than 12,700 U.S. organizations. That number relates to the overall campaign and does not mean all of those organizations were targeted by Zhang or were involved in COVID-19 research.

Xu was arrested in Milan, Italy, on July 3, 2025, following a U.S. request. He was extradited to the United States on April 25, 2026, and appeared in federal court in Houston two days later.

Zhang remains wanted by U.S. authorities. Both men face charges under a nine-count indictment, but the allegations against them have not been proven in court.

The investigation has also examined companies allegedly connected to the two men, including Shanghai Powerock and Shanghai Firetech. Research into patents associated with those companies has provided additional context about the alleged network, although the patent records do not establish that the tools were used in the attacks.

U.S. authorities say the case illustrates how private companies can allegedly be used to conceal the involvement of Chinese intelligence agencies in cyber operations. They also warn that compromised systems can remain exposed to other attackers after an initial intrusion.


Buy ExpressVPN with PayPal or Credit Card

The Rewards for Justice program is asking for information that could help authorities identify Zhang’s whereabouts, associates or activities connected to foreign state-backed cyber operations. Eligible sources may receive rewards of up to $10 million.

READ
Musician Sentenced After AI Bots Generated $10 Million in Fake Streaming Royalties
Advertisement