U.S. State Department Offers $10 Million Reward for Chinese National Charged in HAFNIUM Microsoft Exchange Attacks
Reward offered for information leading to identification or location of Zhang Yu, accused of exploiting zero-day vulnerabilities in on-premises Exchange servers in 2021

Key Takeaways
- U.S. State Department offering up to $10 million for information leading to the identification or location of Zhang Yu.
- Zhang Yu is charged in connection with the 2021 HAFNIUM attacks on Microsoft Exchange Server.
- The HAFNIUM campaign exploited four zero-day vulnerabilities in Microsoft Exchange Server in early 2021.
Related Security News

Suspected ShinyHunters Operative Detained in Jordan, Reportedly Cooperating with FBI
According to Reuters, cited by The Hacker News, a suspected member of the ShinyHunters ransomware/extortion collective identified as "Rey" — whose real name is Saif al-Din Khader — was brought into custody by Jordanian authorities on September 29, 2026. The individual is reported to be cooperating with the U.S. Federal Bureau of Investigation (FBI) to identify other group members. The detention claims remain unconfirmed by official Jordanian or U.S. government sources at the time of reporting.




