Recommended Free Tools
iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
Chinese national Xu Zewei was arrested in Milan on July 3, 2025, at the request of the United States, and was extradited to the U.S. in April 2026. Prosecutors allege that he helped target U.S. COVID-19 researchers and later exploited Microsoft Exchange Server vulnerabilities in activity associated with the HAFNIUM campaign. The allegations have not been established at trial; the U.S. Department of Justice says Xu is presumed innocent unless proven guilty.
What Xu Zewei is accused of
A nine-count indictment in the Southern District of Texas alleges two strands of hacking activity between February 2020 and June 2021. The U.S. Department of Justice says Xu worked for Shanghai Powerock Network Co. Ltd. and that officers in China’s Ministry of State Security, including the Shanghai State Security Bureau, directed his alleged work. These are claims in the indictment and court documents, not findings of guilt. DOJ’s July 2025 arrest announcement and its April 2026 extradition update describe the case.
Alleged targeting of COVID-19 researchers
Prosecutors say Xu and co-conspirators began targeting U.S.-based universities and researchers in February 2020. The alleged targets included immunologists and virologists working on COVID-19 vaccines, treatments, and testing. In one example described by DOJ, an SSSB officer directed Xu to access specified mailboxes belonging to researchers at a university in the Southern District of Texas.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →Alleged Microsoft Exchange intrusions
Beginning in late 2020, Xu and others allegedly exploited vulnerabilities in Microsoft Exchange Server, enterprise email software, as part of activity publicly known as HAFNIUM. The indictment says alleged victims included another university in the Southern District of Texas and a law firm with offices worldwide. DOJ alleges the actors installed web shells—malicious scripts that can provide remote access—and searched stolen law-firm mailboxes for information about U.S. policymakers and government agencies.
#1 Best Overall
Case timeline
- February 2020: Prosecutors say the alleged targeting of U.S. researchers working on COVID-19 vaccines, treatment, and testing began.
- Late 2020 to early 2021: The indictment says Exchange Server exploitation began. The alleged intrusions covered by the case continued through June 2021.
- March 2021: Microsoft publicly disclosed the Exchange campaign and issued patches and tools. On March 10, the FBI and CISA released a joint advisory. FBI Director Christopher Wray’s March 6 statement urged network owners to patch immediately: FBI statement.
- April 13, 2021: DOJ announced a court-authorized operation to remove certain web shells from hundreds of U.S. computers. It did not patch Exchange vulnerabilities or search for other malware and hacking tools, according to the department’s announcement.
- July 3, 2025: Xu was arrested in Milan at the request of the United States. DOJ announced the arrest and charges on July 8.
- April 25–27, 2026: DOJ reported that Xu had been extradited and appeared in federal court in Houston.
What the HAFNIUM scale figures mean
In its July 2025 release, DOJ quoted FBI Cyber Division Assistant Director Brett Leatherman as saying HAFNIUM targeted more than 60,000 U.S. entities and successfully victimized over 12,700. DOJ’s April 2026 release also cited the FBI figure of more than 12,700 U.S. organizations compromised. The releases do not explain how those totals were counted, so they should be understood as figures attributed to the FBI, not independently audited measurements.
What the 2021 web-shell removal did—and did not do
The April 2021 operation addressed certain web shells already found on hundreds of U.S. computers. Removing a web shell was not the same as fixing the Exchange vulnerabilities that enabled intrusions, and DOJ explicitly said the operation did not patch systems or look for additional malware and hacking tools. Organizations running affected Exchange servers therefore needed to apply Microsoft’s security updates and assess systems for other signs of compromise; the operation alone did not establish that a system was secure.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Xu’s current case status
As of DOJ’s April 27, 2026 update, Xu had been extradited from Italy and appeared in federal court in Houston on the nine-count indictment. The cited DOJ releases describe allegations and charges, not a conviction. DOJ states that an indictment is only an allegation and that Xu is presumed innocent unless and until proven guilty.
Quick Recap
Best Value
Rank #4
Rank #3
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

