By Interestana AI Editorial — AI-drafted, human-overseen. How we report
US Offers $10 Million Reward for Zhang Yu in HAFNIUM Hacks

The U.S. State Department announced a reward of up to $10 million for information that leads to the identification or location of Zhang Yu, a Chinese national. Zhang Yu has been charged in the United States in connection with the 2021 Microsoft Exchange Server attacks, which are widely known as the HAFNIUM hacks. This significant reward underscores the U.S. government's commitment to pursuing individuals involved in large-scale cyber intrusions that impact critical infrastructure and private sector entities. The HAFNIUM attacks, which exploited vulnerabilities in Microsoft Exchange Server software, allowed attackers to gain unauthorized access to email accounts and potentially other sensitive data on affected systems. The U.S. Department of Justice previously unsealed indictments against Zhang Yu and other alleged co-conspirators, detailing their alleged roles in conducting these widespread cyber operations. The charges include conspiracy to commit wire fraud, conspiracy to commit computer fraud and abuse, and conspiracy to commit access device fraud. The State Department's reward program, managed by its Rewards for Justice (RFJ) office, aims to incentivize the public to provide actionable intelligence on individuals who pose a threat to national security or international stability through malicious cyber activities. The HAFNIUM incident affected tens of thousands of organizations globally, including government agencies, small businesses, and critical infrastructure providers. The attackers were believed to be affiliated with a China-based hacking group, and their motives were thought to include espionage and data theft. The U.S. government has consistently attributed these types of sophisticated cyber operations to state-sponsored actors, highlighting the ongoing challenges in attributing cyberattacks and bringing perpetrators to justice. The offering of a substantial reward reflects the complexity of investigating and prosecuting cybercrimes that transcend national borders and involve sophisticated technical evasion techniques. The RFJ program has a history of successfully leveraging public tips to apprehend terrorists and cybercriminals, leading to the disruption of numerous malicious networks and plots. The specific details of Zhang Yu's alleged involvement and the evidence against him are outlined in the unsealed indictments, which detail the methods used to exploit the vulnerabilities and the scope of the intrusions. The investigation into the HAFNIUM attacks has been a multi-agency effort, involving the FBI, the Cybersecurity and Infrastructure Security Agency (CISA), and other intelligence community partners. The U.S. government continues to urge organizations to implement robust cybersecurity measures, including timely patching of software vulnerabilities and the use of multi-factor authentication, to protect against similar attacks. The HAFNIUM attacks served as a stark reminder of the persistent and evolving threat posed by advanced persistent threat (APT) groups operating on behalf of nation-states.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.