What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
The headline figures need careful translation. The widely reported $22 million payment is associated with the 2024 Change Healthcare ransomware incident, not a confirmed 2025 SaaS ransom. “More than 100 million” refers to people potentially affected in public descriptions of that incident—not automatically 100 million records stolen. HHS’s breach FAQ does not independently confirm the payment figure or a final affected-person count: HHS Change Healthcare FAQ.
The useful 2025 question is broader: which financially motivated and state-sponsored actors repeatedly abused SaaS identities, cloud services, remote-access tools or trusted integrations? The answer is a watchlist, not a league table. Ransomware operators, credential-abuse crews and espionage teams have different objectives and cannot be ranked fairly by ransom totals alone.
What counts as a SaaS threat actor?
A SaaS threat actor materially uses cloud applications or their identity and integration layers. That includes compromising SaaS accounts, OAuth tokens, API keys or session cookies; abusing connected applications; using collaboration and remote-access services for phishing or persistence; or exploiting cloud-connected systems to steal data or deploy ransomware.
Ordinary endpoint ransomware is not automatically a SaaS attack. The cause might instead be a stolen customer password, missing MFA, an infostealer, a help-desk reset, a malicious OAuth grant, a third-party compromise or a genuine vendor vulnerability. Those scenarios have different owners and controls.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Threat-actor watchlist
| Actor or cluster | Category | Typical access and objective | 2025 relevance |
|---|---|---|---|
| ShinyHunters / UNC5537 | Credential abuse and data extortion | Compromised credentials; cloud data theft | High: track the technique, not just the label |
| ALPHV/BlackCat | Ransomware-as-a-service (RaaS) | Affiliate intrusions; encryption and extortion | Historically important; verify current activity |
| RansomHub | RaaS | Affiliate-led encryption and exfiltration | Major 2024-to-2025 watch candidate |
| LockBit | RaaS | Affiliate access; encryption and extortion | Disrupted, but residual affiliates and brands matter |
| Midnight Blizzard (APT29) | State espionage | Phishing, stolen credentials and cloud or remote-access abuse | Persistent intelligence threat |
| Scattered Spider | Identity and social-engineering cluster | Help-desk manipulation, MFA resets and SIM swapping | Watch candidate; a definitive 2025 ranking is not established |
ShinyHunters and UNC5537: the credential problem
The Snowflake-related campaign made a crucial distinction visible: customer environments can be accessed with stolen credentials without proving that the SaaS platform itself was breached. A June 2024 HHS bulletin described approximately 165 organizations affected by data theft and extortion involving compromised credentials attributed to UNC5537: HHS bulletin.
#1 Best Overall
That attack path commonly involves infostealer-derived passwords, absent or weak MFA, reused credentials and insufficient identity telemetry. Defenders should inventory every account, enforce phishing-resistant MFA, rotate exposed secrets, restrict service accounts and alert on unusual locations, devices, downloads and API use. “Snowflake breach” is therefore too broad unless a specific incident establishes vendor-side compromise.
ALPHV/BlackCat: the affiliate business model
ALPHV/BlackCat is best understood as a RaaS operation: developers and operators provide malware and infrastructure while affiliates conduct many intrusions. The reported $22 million Change Healthcare payment should be attributed to reporting or threat-intelligence accounts, not presented as confirmed by the HHS FAQ. Operator, affiliate, negotiator and any later extortion actor are not necessarily the same entity.
The U.S. Department of Justice describes the broader campaign against BlackCat and a decryption tool that helped victims avoid approximately $68 million in ransom demands, but that figure does not validate the Change Healthcare payment: DOJ cybercrime fact sheet. A payment also does not prove that stolen data was deleted or that systems were safely restored.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problemsRansomHub: portable affiliates and disputed attribution
A joint FBI, CISA, HHS and MS-ISAC advisory identifies RansomHub as a RaaS variant formerly known as Cyclops and Knight. It reported that at least 210 victims had experienced encryption and exfiltration since February 2024 and that experienced affiliates had moved into the operation: joint RansomHub advisory.
Rank #3
RansomHub was discussed in connection with fallout from the Change Healthcare attack, but public material does not establish that it itself stole more than 100 million Change Healthcare records. Victim counts, data custody and attribution can change as affiliates and brands change. Treat the advisory’s 210-victim figure as a reported threshold, not a universal measure of all activity.
LockBit: disruption reduces capacity, not the business model
International authorities announced the disruption of LockBit infrastructure on February 20, 2024. DOJ said the operation had targeted more than 2,000 victims and received over $120 million in ransom payments before that action: DOJ disruption announcement. A later case alleged that the administrator received a 20% share and at least $100 million in digital-currency disbursements; those are separate legal allegations and should not be merged casually: DOJ administrator case.
Rank #4
Google Cloud reported a substantial fall in LockBit incidents after the legal actions, while some LockBit-branded activity continued: Google Cloud 2025 ransomware analysis. Rebrands, retained stolen data and migrating affiliates mean a takedown is not the same as eradication.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Midnight Blizzard: cloud identity as an espionage target
Midnight Blizzard (also known as APT29) is a Russia-linked espionage actor, not primarily a ransom operation. Microsoft documented a campaign that sent malicious RDP configuration files to thousands of users across more than 100 organizations, with lures referencing Microsoft, AWS and Zero Trust: Microsoft analysis.
Best Value
Its SaaS relevance lies in stolen credentials, cloud-account persistence, legitimate remote-access tools and downstream access through service providers. Detection must include identity, session and impossible-travel analytics, not only endpoint malware alerts.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Scattered Spider and emerging brands
Scattered Spider is a watch candidate associated with help-desk social engineering, password resets, MFA-enrollment abuse and SIM swapping. These methods make recovery procedures part of the SaaS attack surface. Phishing-resistant authentication is stronger than SMS MFA, but only when enrollment, device replacement and account recovery are tightly controlled. The available evidence does not support calling it a confirmed 2025 “comeback.”
New names such as Hellcat illustrate an attribution problem. A fresh leak-site brand may be a rebrand, an affiliate collective or an opportunistic claimant. Evaluate infrastructure, tooling, victimology and tactics—not a name or an unverified announcement alone.
The shared cloud attack chain
- Initial access: stolen credentials, infostealer logs, phishing, help-desk manipulation, exposed remote access or a compromised supplier.
- Identity escalation: MFA reset or enrollment abuse, session-cookie or OAuth-token theft, privilege escalation and dormant administrator accounts.
- Discovery: mailboxes, shared drives, CRM records, ticketing systems, collaboration channels, connected applications, cloud storage and data warehouses.
- Collection: bulk API requests, archive creation, valid-account downloads and legitimate synchronization or transfer tools.
- Outcome: encryption and ransom, leak-site extortion, quiet intelligence collection or downstream targeting through a provider.
- Persistence: extra accounts, OAuth applications, API keys, forwarding rules, remote-management tools and backdoor accounts retained after a password reset.
Controls mapped to the attack path
| Exposure | Priority controls |
|---|---|
| Stolen credentials | Phishing-resistant MFA or passkeys, conditional access, password rotation and infostealer response |
| OAuth and token abuse | Admin approval for consent, scoped permissions, grant reviews and token revocation |
| Privilege escalation | Least privilege, separate administrator accounts and just-in-time access |
| Bulk SaaS exfiltration | API and download monitoring, user/entity behavior analytics and volume alerts |
| Help-desk takeover | Strong identity proofing, independent callbacks and dual approval for MFA resets |
| Third-party integrations | Application inventory, scoped tokens, rotation and prompt offboarding |
| Remote-access abuse | Allowlisting, privileged-access management and session recording |
| Extortion response | Immutable backups, evidence preservation, breach counsel and a rehearsed communications plan |
How to read claims without overcounting
- Separate a demand, a negotiated amount, a cryptocurrency transfer and total criminal proceeds.
- Do not equate affected people with downloaded records or complete medical files.
- Label evidence as government or victim-confirmed, named-vendor assessed, reputable-media reported, actor-claimed or disputed.
- Track affiliates and techniques because ransomware brands frequently rebrand and share infrastructure.
- Remember that data theft, account takeover and espionage can matter even when no systems are encrypted.
What to monitor in 2025
- Affiliate migration after arrests and infrastructure takedowns.
- Identity-provider compromise, OAuth abuse and session-token theft.
- Bulk downloads from cloud storage, CRM and data-warehouse services.
- Help-desk and account-recovery attacks.
- State actors using legitimate cloud APIs and remote-access tooling.
- Extortion brands claiming attacks without independently verifiable evidence.
The Bottom Line
The durable risk is not one “all-star” gang. It is the repeated abuse of legitimate identities, trusted integrations and cloud services in ways that resemble normal business activity. Organizations that harden authentication and recovery, limit privilege, govern OAuth and integrations, monitor SaaS data movement and rehearse extortion response will reduce exposure across ransomware, credential theft and espionage alike.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




