The person at the center of this case
Multiple victims worldwide (data theft victims)
Justice for Multiple victims worldwide (data theft victims) โ the trail went cold in 2026, but the truth hasn't.
Start here
What is Zhou Shuai's current location and how has he evaded capture since the 2023 indictment?
Which specific organizations and government entities received stolen data through i-Soon, and what sensitive information was compromised?
What is the relationship between Zhou Shuai and Yin Kecheng, and are other co-conspirators still at large?
Zhou Shuai is wanted by the FBI for his alleged involvement in a sophisticated international cybercrime conspiracy that compromised networks and stole data from victims worldwide between 2018 and 2020. Working with co-conspirators including Yin Kecheng, he allegedly exploited network vulnerabilities, installed malware like PlugX, and exfiltrated stolen data to servers under his control. The case remains active as Zhou Shuai, last known to reside in Shanghai, China, has evaded capture despite a $2 million reward and federal indictment in the District of Columbia.
Try asking
A one-time $10 claim transfers this imported case workspace to your account. You get 10 uploads for this case, 25 daily AI questions for this case, and public tips with files route to you.
This does not start a subscription. When the included limits are reached, the Personal plan unlocks more workspace capacity.
Beyond the top three above โ each detail below could be the thread that pulls this case open.
How were the PlugX malware installations discovered, and what vulnerabilities were exploited in victim networks?
Even the smallest detail could be the key to solving this case.
Official wording
Conspiracy to Cause Damage To, and Obtain Information By Unauthorized Access To, Protected Computers, to Commit Wire Fraud, and to Commit Aggravated Identity Theft; Wire Fraud; Obtaining Information by Unauthorized Access to Protected Computers; Intentionally Causing Damage to Protected Computers; Aggravated Identity Theft; Money Laundering Caution: Zhou Shuai and Yin Kecheng are wanted for their alleged involvement in compromising and stealing data belonging to scores of victims around the world. The men, and their co-conspirators, allegedly exploited vulnerabilities in victim networks, conducted reconnaissance once inside those networks, and installed malware, such as PlugX malware, that provided persistent access.
The men then allegedly identified and stole data from the compromised networks by exfiltrating it to servers under their control. They also allegedly brokered stolen data for sale and provided it to various customers, only some of whom had connections to the PRC government and military.
Zhou Shuai allegedly sold data stolen by Yin Kecheng through i-Soon, a company whose primary customers included the PRC Ministry of State Security (MSS) and the Ministry of Public Safety (MPS). In 2023, a Grand Jury in the District of Columbia returned an indictment against Zhou Shuai on multiple charges related to criminal activity occurring between 2018 and 2020.
Remarks: Zhou Shuai was last known to reside in Shanghai, China.
Alleged conspiracy and unauthorized network access activities commence
Alleged criminal activity concludes
Grand Jury in the District of Columbia returns indictment against Zhou Shuai on multiple charges
For information leading to the resolution of this case
For information leading to the resolution of this case