US Justice Dept puts a $10 million bounty on at-large 'hacker-for-hire' cabal it says targeted China critics, religious missionaries, and the Treasury

An FBI wanted poster for alleged hacker Zhou Shuai.
(Image credit: FBI)

The US Department of Justice announced yesterday that it's charging 12 alleged Chinese hackers over a string of cyber-attacks supposedly undertaken on behalf of China's Public and State Security Ministries (the MPS and MSS, respectively).

"Victims include US-based critics and dissidents of the PRC, a large religious organization in the United States, the foreign ministries of multiple governments in Asia, and US federal and state government agencies," says the DOJ.

The 12 defendants are divided into three groups across three unsealed indictments—eight are employees of an "ostensibly private" Chinese company called Anxun Information Technology Co. Ltd. (or i-Soon), two are officers of China's MPS, and the final two are said to be members of the hacking group Advanced Persistent Threat 27 (APT27)—known also by such Robert Ludlum-esque names as Bronze Union, Emissary Panda, Lucky Mouse, Iron Tiger, Silk Typhoon, and Threat Group 3390.

The DOJ accuses the eight i-Soon techs of conducting "computer intrusions at the direction of the PRC’s MPS and Ministry of State Security (MSS) and on their own initiative," and turning over stolen data to the Ministries for hefty sums of money.

The DOJ notes the US Treasury as one victim of such an attack, but otherwise remains pretty vague about precisely who was targeted—describing them as "a large religious organization that previously sent missionaries to China and was openly critical of the PRC government and an organization focused on promoting human rights and religious freedom in China." The US also claims that these alleged hackers "targeted multiple news organizations in the United States, including those that have opposed the CCP or delivered uncensored news to audiences in Asia."

The i-Soon and MPS defendants are part of a single indictment, while the alleged APT27 members get their own pair of specific indictments. The APT27 cases accuse the duo—Yin 'Coldface' Kecheng and Zhou 'YKCAI' Shuai—of "multi-year, for-profit computer intrusion campaigns dating back, in the case of Yin, to 2013."

The DOJ accuses the pair of being motivated by money, and alleges that both left systems open and vulnerable in their campaign against organisations ranging from universities, to think tanks, to local governments, to defence contractors. Zhou and Yin each have their own entries on the FBI's Most Wanted database.

Absolutely none of the accused are in custody, which is probably why the State Department has just announced a $10 million bounty for information leading to the identification or location of anyone targeted in the DOJ's i-Soon/MPS indictment. Or, indeed, for anyone who "while acting at the direction or under the control of a foreign government, participates in malicious cyber activities against U.S. critical infrastructure in violation of the Computer Fraud and Abuse Act."

Yin Kecheng and Zhou Shuai, meanwhile, each have a $2 million bounty on their heads for anyone who provides "information leading to [their] arrests and convictions, in any country".

2025 gamesBest PC gamesFree PC gamesBest FPS gamesBest RPGsBest co-op games

2025 games: This year's upcoming releases
Best PC games: Our all-time favorites
Free PC games: Freebie fest
Best FPS games: Finest gunplay
Best RPGs: Grand adventures
Best co-op games: Better together

Joshua Wolens
News Writer

One of Josh's first memories is of playing Quake 2 on the family computer when he was much too young to be doing that, and he's been irreparably game-brained ever since. His writing has been featured in Vice, Fanbyte, and the Financial Times. He'll play pretty much anything, and has written far too much on everything from visual novels to Assassin's Creed. His most profound loves are for CRPGs, immersive sims, and any game whose ambition outstrips its budget. He thinks you're all far too mean about Deus Ex: Invisible War.

You must confirm your public display name before commenting

Please logout and then login again, you will then be prompted to enter your display name.

Read more
 In this photo illustration a novelty Bitcoin token is photographed on a US Dollar bank note, on January 4, 2025 in Bath, England. The Cryptocurrency market has recently received a significant boost by the election of Donald Trump with hopes of the start of a policy framework that could see Bitcoin as a strategic asset
Man charged with $65,000,000 worth of cryptocurrency heists was reportedly discovered through chatting on Discord with a company they allegedly stole from
Three Magikarp Pokémon
The FBI used self-destruct on malware infecting over 4,000 US computers, it's super effective
An image of a fake Bitcoin with a laptop in the background displaying financial data
North Korean hackers are said to have stolen $1,300,000,000 in crypto in 2024, an estimated 61% of the total funds swiped this year
FBI 10 Most Wanted poster.
The FBI put a $5 million bounty on the 'Cryptoqueen' last year but still hasn't found her, so take your pick: Russia, South Africa, or murdered on a yacht in 2018
TP-Link AXE75 Wi-Fi 6E router
US congressman calls again for the government to ban Chinese-made TP-Link routers: 'I would not have that in my home'
Tencent
Tencent has been designated a Chinese military company by the US Department of Defense, which the conglomerate calls a 'misunderstanding'
Latest in Security
An FBI wanted poster for alleged hacker Zhou Shuai.
US Justice Dept puts a $10 million bounty on at-large 'hacker-for-hire' cabal it says targeted China critics, religious missionaries, and the Treasury
Kinzie, in an FBI jacket, uses a computer with the logo of the Third Street Saints on it
Have I Been Pwned adds over 284 million compromised passwords from latest breach
A still from a YouTube video of Senator Mark Warner speaking
Telecoms hack on US government officials is 'worst in nations history' and 'the barn door is still wide open' says senator
HDMI cable
Hackers can wirelessly spy on your display by collecting HDMI signal leaks and churning them through an AI, but I wouldn't break out the tin foil just yet
Computer code and text displayed on computer screens. Photographer: Chris Ratcliffe/Bloomberg
Forcing users to periodically change their passwords should go the way of the dodo according to the US government
An original Apple Macintosh Model M0001, as they celebrate 40th anniversary, is on display in between 2024 Apple models at the independent Apple products store chain Amac, on January 24, 2024 in Utrecht, The Netherlands. Based on the Motorola 68000 microprocessor, the Macintosh was the first successful mouse-driven computer with a graphical user interface.
Major browser providers scramble to patch an 18-year-old vulnerability affecting MacOS and Linux systems but Windows remains gloriously immune
Latest in News
An FBI wanted poster for alleged hacker Zhou Shuai.
US Justice Dept puts a $10 million bounty on at-large 'hacker-for-hire' cabal it says targeted China critics, religious missionaries, and the Treasury
A picture of Bowser behind jail bars.
Nintendo wins major French piracy case with EU-wide consequences: 'Significant not only for Nintendo, but for the entire games industry'
Protein molecules, illustration
AI helps turn highschool project into world saving tech which promises to devour 150 tons of fast-fashion plastic each year
Trump chip tariff
Japanese companies begin stockpiling in response to new Trump tariffs: Cue a ton of PS5 stock and stale cans of coffee
An image of a WD_Black SN850X SSD against a teal background with a white border
The best 1 TB gaming SSD you can buy is now just $79, the cheapest it's been for a good while
Mark Zuckerberg, chief executive officer of Meta Platforms Inc., wears Orion augmented reality (AR) glasses during the Meta Connect event in Menlo Park, California, US, on Wednesday, Sept. 25, 2024. Meta Platforms Inc. debuted its first pair of augmented reality glasses, devices that show a combined view of the digital and physical worlds, a key step in Chief Executive Officer Mark Zuckerberg's goal of one day offering a hands-free alternative to the smartphone.
Meta's Orion AR glasses still have no 'killer use case' but want devices to hang out on your face, on your wrist, and now in your pocket too