US Offers $10M Reward for HAFNIUM Hacker Zhang Yu Over Exchange Attacks

Moyen · The Hacker News ·

En bref

  • Zhang Yu, a Chinese national, has been charged for his role in HAFNIUM's 2021 attacks on Microsoft Exchange Server.
  • The U.S. State Department announced a $10 million reward for information on his identity or whereabouts.
  • The reward was announced in 2026, seeking leads on the charged individual.
  • No CVEs are associated with this action; it is a law enforcement and intelligence effort.

In 2021, a wave of cyberattacks struck Microsoft Exchange Server. These intrusions have been tied to a group called HAFNIUM. A Chinese national, Zhang Yu, now faces criminal charges for his alleged role. The U.S. The State Department has offered a bounty of as much as $10 million for details that assist in identifying or finding him. This reward was made public in 2026.

The charges and the bounty directly affect Zhang Yu, as he is the subject of the criminal case and the search. Organizations that ran Microsoft Exchange Server in 2021 were impacted by the attacks. U.S. law enforcement and diplomatic agencies are involved in the effort to find him. The public may also be affected if the reward yields new details about the intrusions.

This case underscores the continuing hunt for state-sponsored cybercriminals. It shows that the United States will use financial incentives to track down people accused of major network breaches. The reward is a way to gather intelligence on a foreign national who might be hiding in a jurisdiction that refuses extradition. The charges and reward also serve as a warning and a step toward international cyber accountability.

HAFNIUM is known for exploiting flaws in Microsoft Exchange Server. The 2021 attacks were widespread and forced many organizations to patch urgently. Zhang Yu's case is part of a broader push to attribute and prosecute cyberattacks. The U.S. State Department's reward program is often used for high-profile terrorism or cyber cases. The absence of CVEs in this action means it is not about a new vulnerability but about a specific individual.

In 2026, the focus will be on whether the reward leads to Zhang Yu's capture or new intelligence. Organizations should keep watching for updates on HAFNIUM's operations. The U.S. may announce further charges or sanctions. IT administrators should ensure their Exchange servers are patched and monitored. The case could set a precedent for how the U.S. pursues foreign cybercriminals.

À faire maintenant

  1. Immediately apply the latest security updates to all Microsoft Exchange Server instances.
  2. Audit Exchange logs for signs of compromise linked to HAFNIUM's 2021 tactics, such as unusual mailbox access or web shells.
  3. Enforce multi-factor authentication for all administrative and user accounts, and restrict privileged access.
  4. Monitor network traffic for suspicious outbound connections to known malicious infrastructure.
  5. Subscribe to threat intelligence feeds and Microsoft advisories for HAFNIUM activity.
  6. Conduct a comprehensive security review of Exchange environments and implement Microsoft's recommended mitigations.
  7. Train staff to recognize phishing attempts and report suspicious emails promptly.

Source originale

The Hacker News

Analyse originale assistée par IA, sources citées. Vérifiez auprès de l'avis du fournisseur avant d'agir.

← Toute la veille cyber