$10 Million Bounty Offered for Chinese Hafnium Hacker Tied to Microsoft Exchange Server Zero‑Day Attack
What Happened – The U.S. State Department announced a reward of up to US $10 million for information that leads to the location of Zhang Yu, a Chinese national alleged to be a senior figure in the state‑sponsored Hafnium group. Zhang is accused of helping weaponize zero‑day vulnerabilities in Microsoft Exchange Server in early 2021, resulting in the theft of research data and email content from U.S. universities, health researchers and other targets.
Why It Matters for Trust & Control Assurance
- Demonstrates the risk of unpatched critical vulnerabilities in widely deployed software – a control area that continuous monitoring programs must evidence.
- Shows how private‑sector entities can be leveraged as cover for state‑backed actors, reinforcing the need for robust third‑party risk oversight and documented remediation timelines.
- Provides a concrete audit‑ready artifact (patch‑status logs, vendor‑risk assessments) that can be presented to regulators or auditors to prove due diligence.
Who Is Affected – Technology/SaaS providers, enterprises running on‑prem or cloud‑based Microsoft Exchange, and any organization that relies on third‑party software for critical communications.
Recommended Actions
- Verify that every Exchange server in your environment is fully patched or migrated to a supported cloud service.
- Capture and retain evidence of patch‑management activities and vendor‑risk assessments in a continuous control‑assurance repository.
Technical Notes – The attack leveraged multiple zero‑day exploits disclosed in 2021 (CVE‑2021‑26855, CVE‑2021‑27065, etc.). Exploitation allowed remote code execution and credential theft, leading to large‑scale data exfiltration.
Source: Bitdefender Blog – $10 Million Bounty for Chinese Hafnium Hacker