The person at the center of this case
Multiple international victims of data theft and cybercrime
Justice for Multiple international victims of data theft and cybercrime โ the trail went cold in 2026, but the truth hasn't.
Start here
What is Yin Kecheng's current location and operational status? Is he still actively involved in cybercrime from Shanghai or elsewhere?
Which specific companies and government agencies were victimized? What sensitive data was exfiltrated and to whom was it sold?
Who are the co-conspirators and customers that received stolen data? What connections exist between Yin Kecheng and PRC government entities?
Yin Kecheng is wanted by the FBI for his alleged involvement in a sophisticated international cybercrime conspiracy spanning 2013-2020, where he and co-conspirators compromised networks, stole data from scores of victims worldwide, and sold stolen information to customers including PRC government agencies. The case remains unsolved with Kecheng believed to be in Shanghai, China, evading extradition and prosecution. His capture is critical to disrupting ongoing cyber espionage operations and holding accountable those who facilitate data theft on a massive scale.
Try asking
A one-time $10 claim transfers this imported case workspace to your account. You get 10 uploads for this case, 25 daily AI questions for this case, and public tips with files route to you.
This does not start a subscription. When the included limits are reached, the Personal plan unlocks more workspace capacity.
Beyond the top three above โ each detail below could be the thread that pulls this case open.
How was the PlugX malware deployed and what infrastructure supported the data exfiltration servers?
What is the relationship between Yin Kecheng and Zhou Shuai, and how did their roles differ in the conspiracy?
Even the smallest detail could be the key to solving this case.
Official wording
Conspiracy to Cause Damage To, and Obtain Information By Unauthorized Access To, Protected Computers, to Commit Wire Fraud, and to Commit Aggravated Identity Theft; Wire Fraud; Obtaining Information by Unauthorized Access to Protected Computers; Intentionally Causing Damage to Protected Computers; Aggravated Identity Theft; Money Laundering Caution: Yin Kecheng and Zhou Shuai are wanted for their alleged involvement in compromising and stealing data belonging to scores of victims around the world. The men, and their co-conspirators, allegedly exploited vulnerabilities in victim networks, conducted reconnaissance once inside those networks, and installed malware, such as PlugX malware, that provided persistent access.
The men then allegedly identified and stole data from the compromised networks by exfiltrating it to servers under their control. They also allegedly brokered stolen data for sale and provided it to various customers, only some of whom had connections to the PRC government and military.
Zhou Shuai allegedly sold data stolen by Yin Kecheng through i-Soon, a company whose primary customers included the PRC Ministry of State Security (MSS) and the Ministry of Public Safety (MPS). In 2018 and 2023, Grand Juries in the District of Columbia returned indictments against Yin Kecheng on multiple charges related to criminal activity occurring between 2013 and 2020.
Remarks: Yin Kecheng was last known to reside in Shanghai, China.
Alleged cybercriminal activity begins involving network compromise and data theft
Alleged criminal activity concludes; period of documented offenses spans 2013-2020
Grand Jury in District of Columbia returns indictment against Yin Kecheng on multiple charges
Grand Jury in District of Columbia returns additional indictment against Yin Kecheng related to criminal activity
For information leading to the resolution of this case
For information leading to the resolution of this case