The United States Government has directed a chain of cyberattacks that has long been hidden under the shell of China National Camp Technology, directly to the Shanghai City National Security Agency of the Ministry of National Security of China.
On October 7, the United States Department of State's Justice Incentives Scheme announced a reward of up to $10 million for the identity, whereabouts and related information of Zhang Yu, a citizen of a concentrated country.
The official United States description of Zhang Woo's identity is very specific: he is a member of the Shanghai ITD Ltd. and “is commissioned by the Shanghai City National Security Agency of the Ministry of National Security of the People's Republic of China”.
原始来源 · rewardsforjustice.net美国国务院“正义奖励计划”:Zhang Yu (SSSB)rewardsforjustice.net ↗This has led to a case that no longer focuses solely on “one Chinese hacker being rewarded”, but rather on how Chinese intelligence agencies conduct State-level cyber operations through private companies and technical contractors.

Started with the new crown research and then entered the HAFNIUM mass attack
The United States Department of State states that since early 2020, Zhang Woo and his associate Xu Dae Wei have been unauthorized to access the computer systems of American universities and immunology and viral researchers, with the aim of including sensitive research information related to the New Crown Virus.
They then used Microsoft Exchange Server's loophole to participate in a large-scale Hafnium network invasion.
Operation HAFNIUM in 2021 used multiple zero-day loopholes to attack locally deployed Exchange Server. Microsoft described HAFNIUM as a threat organization that was supported by the State and operated from China. The United States Government and its allies subsequently attributed the relevant activities to the Chinese Ministry of National Security.

The United States claims that this operation has affected thousands of computers around the world. The FBI has previously indicated that the entire HAFNIUM operation targeted more than 60,000 United States entities, of which more than 127,000 were affected by the actual invasion.
One extradited, one still at large
原始来源 · justice.gov美国司法部:徐泽伟被意大利引渡至美国justice.gov ↗The co-accused, Xu Ze Wei, of Zhang Woo, has fallen into the United States judicial system.
Xu Ze Wei was arrested in Italy in 2025, extradited to the United States in April 2026 and appeared before the Federal Court in Houston. Nine charges issued by the United States Department of Justice relate to computer invasion, telecommunications fraud, illegal access to protected computer information and identity theft.
Zhang Woo has not been arrested.
The Justice Incentive Scheme has thus increased the bonus to “up to $10 million” with the goal of obtaining information that can help identify and locate the individuals concerned.
The real name of the US is the Chinese Communist Party model of outsourcing intelligence to private companies
The United States Department of State directly stated on Zhang Woo's reward page that China uses a wide network of private companies and contractors in China to conduct hacker attacks and information thefts in order to cover up the Chinese Government's involvement.
This is the most critical layer of the entire case.
Companies such as Shanghai Illness, Shanghai Iwam are business enterprises, but according to the current publicly available United States prosecution material, their personnel are subject to the Shanghai City National Security Agency ' s mandate, coordinate hacker activities and report the results to the National Security System.
This is a typical “deniable” structure: State organs do not have to have all operational personnel in uniform and in a formal setting; The task could be accomplished through business, contractors and technical teams, and once exposed, Beijing could cut responsibility and State institutions off.
This model also explains the increasing shift in accountability for China's cyber-operations from “blackers' organizations” to the relationship between specific companies, directors, project leaders and intelligence agencies.
From outbreak research to critical infrastructure, the borders of the Ministry of National Security have been extended to global networks
The year 2020 is a time of global urgency to find information on vaccines, treatments and viruses. The United States accused Zhang Woo and others of attacking medical research institutions during this period, suggesting that the Beijing intelligence system included public health research as a target for information acquisition.
At the stage of HAFNIUM, the attacks were extended to universities, law firms and a large number of enterprise systems.
This is not a mere economic espionage, but a long-term infiltration of the national intelligence system into the global digital infrastructure.
This time, the United States offered a reward to Zhang Woo, turning a chain of responsibility that was hidden behind codes, loopholes and proxy servers into a specific name:
Zhang Woo — Shanghai Illumination — Shanghai City National Security Service — Ministry of National Security of China.
The Xi regime has expanded “national security” in the country to almost all areas of social life, while the other has projected this security logic abroad through a network of intelligence agencies and technical contractors.
The $10 million reward is a real exposure not only to a suspect who is still at large, but to how the CCP intelligence system uses the shell of a private enterprise to embed State behaviour in global cyberspace.

Article discussion
Verified members can discuss this report publicly and manage their own content.
Checking member sign-in status…