Co-leader of Hafnium operation accused of targeting U.S. medical research centers

On July 8, 2025, U.S. authorities announced that Italian law enforcement had arrested Xu Zewei, a 33-year-old Chinese national, on charges of conducting cyberespionage campaigns for the Chinese government between February 2020 and June 2021. Xu allegedly targeted American researchers working on COVID-19. He was apprehended in Milan at the request of the U.S. Department of Justice and is awaiting extradition to the United States.

Xu Zewei and his co-defendant, Zhang Yu—who remains at large—are believed to have operated under the direction of the Shanghai State Security Bureau (SSSB), a regional branch of China’s Ministry of State Security. Their targets reportedly included universities, laboratories, law firms, and government institutions, from which they stole sensitive data, particularly related to vaccines and COVID-19 treatments.

The duo is also implicated in the widespread hacking campaign against Microsoft Exchange servers known as “Hafnium,” which was publicly disclosed by Microsoft in March 2021. Xu Zewei faces up to 20 years in prison if convicted on all counts.

Stay tuned in real time
Subscribe to
the newsletter
By providing your email address you agree to receive the Incyber newsletter and you have read our privacy policy. You can unsubscribe at any time by clicking on the unsubscribe link in all our emails.
Stay tuned in real time
Subscribe to
the newsletter
By providing your email address you agree to receive the Incyber newsletter and you have read our privacy policy. You can unsubscribe at any time by clicking on the unsubscribe link in all our emails.