US posts $10 million reward for accused Chinese ‘Hafnium’ hacker
The U.S. government has posted a $10 million bounty for Zhang Yu, whom officials identify as a key actor in the Hafnium hacking campaign, a Chinese state-linked operation that breached thousands of computers and exfiltrated large volumes of documents.
Why this matters: Hafnium was not a narrow espionage operation. It hit thousands of organizations — businesses, hospitals, local governments, think tanks — by exploiting Microsoft Exchange vulnerabilities. Most of those victims never learned exactly what was taken. A $10 million reward is a public pressure tool, not an arrest. Zhang Yu is almost certainly in China, beyond U.S. reach. What matters for everyone else is that the stolen data is still out there, and the organizations that were breached are still responsible for whatever came next.
Who should care: Cybersecurity · Privacy officers · Administrators
This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.