US seeks Chinese hacker Zhang YU under $10 million reward
RFJ seeks details on Zhang Yu under a reward offer of up to $10 million over alleged COVID-19 research theft and Microsoft Exchange Server intrusions @FBICyberDiv/X

The US Rewards for Justice (RFJ) programme is seeking information on Chinese hacker Zhang Yu under a reward offer of up to $10 million (£7,565,150) over alleged theft of COVID-19 research at American institutions beginning in early 2020.

Zhang remains at large, according to RFJ. His alleged partner, Xu Zewei, was extradited to the United States in April 2026 after his arrest by Italian law enforcement, following alleged intrusions targeting researchers and computers running Microsoft Exchange Server.

Zhang Yu's Alleged Intelligence Connections

RFJ identifies Zhang as a Chinese national and a director at Shanghai Firetech Information Science and Technology Company, Ltd. It alleges that he worked at the behest of the Shanghai State Security Bureau (SSSB), within the Ministry of State Security (MSS) of the People's Republic of China (PRC).

The programme describes the MSS and SSSB as Chinese intelligence services with responsibilities covering domestic counterintelligence, non-military foreign intelligence and aspects of the country's political and domestic security.

RFJ describes the alleged work for intelligence services as part of a broader system involving private businesses. It accuses the PRC of relying on 'an extensive network of private companies and contractors in China' to hack and steal information in a way that obscures the government's involvement.

At the time of the alleged research intrusions, Xu was a general manager at Shanghai Powerock Network Co. Ltd., according to the programme. The two men held positions at separate Shanghai companies, with RFJ identifying them as partners in the alleged operations.

The RFJ account includes no response from Zhang, Xu or the Chinese government. IBTimes UK cannot independently verify the allegations of research theft or intelligence direction.

COVID-19 Research Allegations Against Zhang Yu

RFJ alleges that the pair gained unauthorised access to research conducted by US-based universities and leading immunologists and virologists from early 2020. The purpose, it states, was to steal sensitive information.

The account does not detail what material was obtained through the alleged intrusions or the volume of information involved. Neither the universities nor the researchers are named, and no effect on their research is specified.

In 2021, according to RFJ, Zhang and Xu exploited vulnerabilities in computers running Microsoft Exchange Server, a computer program involved in storing and retrieving emails. Those alleged intrusions formed part of the mass hacking campaign publicly known as HAFNIUM.

RFJ states that the campaign compromised thousands of computers worldwide, with a US university and a US law firm among the victims. That figure describes the wider campaign. The account provides no separate total for computers allegedly compromised by the pair.

Reward Terms in the Search for Zhang Yu

The appeal for information on Zhang sits within a broader reward offer concerning foreign government involvement in cyber activity against US critical infrastructure. Its terms specify both the kind of information sought and the conduct covered.

The programme offers up to $10 million for information leading to the identification or location of anyone who participates in such malicious cyber activities while acting 'at the direction or under the control of a foreign government'.

RFJ names Zhang as a person it seeks information about under that offer. The account does not identify his current whereabouts or provide a location where he is believed to be.