惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

IT之家
IT之家
博客园 - 聂微东
雷峰网
雷峰网
Microsoft Azure Blog
Microsoft Azure Blog
WordPress大学
WordPress大学
Hugging Face - Blog
Hugging Face - Blog
S
SegmentFault 最新的问题
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
T
Tailwind CSS Blog
博客园 - 三生石上(FineUI控件)
V
Visual Studio Blog
博客园 - 司徒正美
爱范儿
爱范儿
月光博客
月光博客
阮一峰的网络日志
阮一峰的网络日志
博客园_首页
博客园 - 【当耐特】
Jina AI
Jina AI
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
酷 壳 – CoolShell
酷 壳 – CoolShell
大猫的无限游戏
大猫的无限游戏
小众软件
小众软件
人人都是产品经理
人人都是产品经理
V
V2EX

GRAHAM CLULEY

Smashing Security podcast #485: These researchers got drunk to hack an LG TV Former AT&T store worker jailed after moonlighting as a SIM-swap gang's inside man 'Anne Hathaway' admits leading $245 million crypto theft gang that spent a fortune on nightclubs, watches, and luxury cars Smashing Security podcast #484: How websites are tracking you with silence CRPx0 ransomware: what you need to know The US military just turned off ad tracking on its phones. Maybe you should too How a hole in Lenovo's login system let hackers walk into 5,000 Dropbox accounts Smashing Security podcast #483: This AI helps thieves steal your iPhone Revolut scam steals £180,000 from Jersey residents in just four weeks Shai-Hulud hackers: two men charged over TeamPCP's global supply chain crime spree that hit OpenAI, and thousands more US Navy tells sailors and their families: scrub your social media, enemies are watching Smashing Security podcast #482: This hacker leaked GTA 6 - and launched their own cryptocurrency Malicious Firefox add-ons caught stealing cryptowallet seed phrases and browser credentials Gunra ransomware: what you need to know Smashing Security podcast #481: Never say this to a robot dog Prison for data analyst who tried to extort $2.5 million from his employer An "invisible" car? Researcher uses machine learning to hide vehicles from Flock cameras Smashing Security podcast #480: This is the AI service you should never sign up to Meta's Ray-Bans are being banned from pubs, restaurants, and theatres Beware cut-price AI services that read your every word Apple's bug bounty program is drowning in so much AI slop, it is in danger of missing serious exploits Smashing Security podcast #479: How a fake police officer nearly stole Graham’s cryptocurrency Smashing Security podcast #479: How a fake police officer nearly stole Graham’s cryptocurrency Fake IRS letters target cryptocurrency holders The $5 million threat: AI Is supercharging phishing attacks North Korea's elite hackers turned on their own government — and got caught Smashing Security podcast #478: This job interview could destroy your company OpenAI's AI "goes rogue" and hacks Hugging Face: what you need to know Smashing Security podcast #477: How 14 orders of chicken McNuggets helped nail a suspected Russian hacker Ukraine warns fake CAPTCHAs are being used to make you hack yourself
Alleged Silk Typhoon hacker extradited to the United Stat...
Graham CLULEY · 2026-04-29 · via GRAHAM CLULEY

A man accused of working as a hacker for China's Ministry of State Security has been extradited to the USA from Italy, and faces - if found guilty - the prospect of decades behind bars.

34-year-old Xu Zewei arrived in Houston, Texas at the weekend after Italian authorities approved his extradition to the United States. At a federal court hearing on Monday, he pleaded not guilty, and is currently being held at the Federal Detention Center in Houston.

Xu, who has consistently denied the charges and insists that Italian police detained the wrong man, was originally arrested in July 2025 while on holiday in Milan with his wife.

According to the indictment, Xu and a co-conspirator spent the early months of 2020 attempting to steal coronavirus research from American universities, immunologists, and virologists.

While the world's scientists raced to understand COVID-19, the alleged hackers were quietly trying to siphon off their work on vaccines, treatments, and testing. One of the instituions reportedly targeted was a Texas university.

The US Department of Justice alleges that Xu was following orders from officers at the Shanghai State Security Bureau, an arm of China's Ministry of State Security. At the time, Xu was employed by Shanghai Powerock Network, a Chinese firm that prosectors described as existing to carry out hacking on Beijing's behalf.

Xu is accused of being part of Hafnium - the Chinese state-backed hacking crew that Microsoft dubbed Silk Typhoon.

This hacking group has been blamed for zero-day attacks on Microsoft Exchange Server that began in early 2021. Using a chain of previously unknown vulnerabilities, the attackers compromised as many internet-facing Exchange servers as they could, unlocking long-term access for themselves.

According to the FBI, Hafnium targeted more than 60,000 organisations in the United States and successfully broke into over 12,700 of them. Those organisations impacted by the spate of attacks varied from defence contractors and law firms to think tanks and infectious disease researchers.

Predictably, China has denied any involvement. The Chinese Foreign Ministry opposed Xu's extradition to the United States, and claimed that cases are being fabricated against Chinese citizens.

If convicted on all charges - which include wire fraud, conspiracy to damage protected computers, and aggravated identity theft - Xu could spend decades in prison.

What makes this case unusual is that most state-sponsored hackers indicted by the US Department of Justice never see the inside of an American courtroom. That's because those alleged to have been behind the attacks live in countries with no intention of handing their citizens over to the US legal system.

But every so often, a suspect makes the mistake of going on holiday somewhere with an extradition agreement with the United States.

For organisations that were caught up in the original Exchange Server free-for-all of 2021, this week's news might bring a small sense of vindication.

For the rest of us, it's a useful reminder that the people behind these enormous, headline-grabbing campaigns are not faceless ghosts . They have names, employers, and - occasionally - travel plans.

And just sometimes, those plans don't end the way they expected.