US Offers $10M for Tips on Chinese Hacker Tied to Microsoft Exchange Mega-Attack

Moyen · Graham Cluley ·

En bref

  • US State Department announced a $10 million reward for information on Zhang Yu.
  • Zhang, 44, is linked to Hafnium and Chinese state-backed hacking.
  • He is accused in a mega-attack against Microsoft Exchange Server.
  • No CVE identifiers were cited in the facts provided.

The U.S. State Department has put up as much as $10 million for details leading to Zhang Yu, a 44-year-old figure tied to Hafnium and to Chinese state-sponsored cyber operations. The reward reflects an effort to gather intelligence on a person accused of participating in a large-scale hacking campaign.

At the center of the case is Microsoft's Exchange Server. The intrusion described as a mega-attack targeted that widely used email and collaboration platform, though the available facts do not list any specific CVE identifiers associated with the incident.

Zhang Yu is identified among actors connected to Hafnium, a group associated with Chinese state hackers. The State Department's reward offer signals that investigators want more information about his role, whereabouts, or network. The accusation against him involves hacking activity, but no additional technical indicators were provided.

For K-12 IT teams in New Brunswick, the news matters less as a direct new vulnerability and more as a reminder that Exchange Server remains a high-value target. Government and education environments often hold sensitive data and can be caught in broad exploitation campaigns even when they are not named.

Because no CVE is cited, administrators should avoid chasing a single patch and instead verify that Exchange systems are fully updated, monitored, and segmented. Watch for official guidance from Microsoft and government cyber agencies, and treat unsolicited bounty-related claims with caution.

À faire maintenant

  1. Inventory all on-premises Exchange Server instances and confirm supported versions, prioritizing internet-facing endpoints.
  2. Apply the latest Microsoft security updates and cumulative updates, then verify build numbers across every server.
  3. Review Exchange logs for suspicious web shells, anomalous mailbox exports, and unusual OWA or EWS access.
  4. Enforce MFA, disable legacy authentication, restrict external access, and audit administrator privileges.
  5. Segment Exchange from flat internal networks and block unnecessary inbound protocols or services.
  6. Monitor threat intelligence for Hafnium and Chinese state activity, and brief staff on phishing and social engineering.
  7. Preserve logs and establish incident response contacts if compromise is suspected or reported.

Source originale

Graham Cluley

Analyse originale assistée par IA, sources citées. Vérifiez auprès de l'avis du fournisseur avant d'agir.

← Toute la veille cyber