October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsWindows FixRecommendedWindows errors stealing your time? Find the fix fastScan stability, cleanup and performance issues.Fix NowOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

SaaS Threat Actors to Watch in 2025: Ransomware, Credential Theft and Cloud Espionage

The 2025 SaaS threat landscape spans credential theft, ransomware-as-a-service and state espionage. Here is what is confirmed, disputed and actionable.
From TheFinanceBase Team6 min to read

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The headline figures need careful translation. The widely reported $22 million payment is associated with the 2024 Change Healthcare ransomware incident, not a confirmed 2025 SaaS ransom. “More than 100 million” refers to people potentially affected in public descriptions of that incident—not automatically 100 million records stolen. HHS’s breach FAQ does not independently confirm the payment figure or a final affected-person count: HHS Change Healthcare FAQ.

The useful 2025 question is broader: which financially motivated and state-sponsored actors repeatedly abused SaaS identities, cloud services, remote-access tools or trusted integrations? The answer is a watchlist, not a league table. Ransomware operators, credential-abuse crews and espionage teams have different objectives and cannot be ranked fairly by ransom totals alone.

What counts as a SaaS threat actor?

A SaaS threat actor materially uses cloud applications or their identity and integration layers. That includes compromising SaaS accounts, OAuth tokens, API keys or session cookies; abusing connected applications; using collaboration and remote-access services for phishing or persistence; or exploiting cloud-connected systems to steal data or deploy ransomware.

Ordinary endpoint ransomware is not automatically a SaaS attack. The cause might instead be a stolen customer password, missing MFA, an infostealer, a help-desk reset, a malicious OAuth grant, a third-party compromise or a genuine vendor vulnerability. Those scenarios have different owners and controls.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Threat-actor watchlist

Actor or cluster Category Typical access and objective 2025 relevance
ShinyHunters / UNC5537 Credential abuse and data extortion Compromised credentials; cloud data theft High: track the technique, not just the label
ALPHV/BlackCat Ransomware-as-a-service (RaaS) Affiliate intrusions; encryption and extortion Historically important; verify current activity
RansomHub RaaS Affiliate-led encryption and exfiltration Major 2024-to-2025 watch candidate
LockBit RaaS Affiliate access; encryption and extortion Disrupted, but residual affiliates and brands matter
Midnight Blizzard (APT29) State espionage Phishing, stolen credentials and cloud or remote-access abuse Persistent intelligence threat
Scattered Spider Identity and social-engineering cluster Help-desk manipulation, MFA resets and SIM swapping Watch candidate; a definitive 2025 ranking is not established

ShinyHunters and UNC5537: the credential problem

The Snowflake-related campaign made a crucial distinction visible: customer environments can be accessed with stolen credentials without proving that the SaaS platform itself was breached. A June 2024 HHS bulletin described approximately 165 organizations affected by data theft and extortion involving compromised credentials attributed to UNC5537: HHS bulletin.

That attack path commonly involves infostealer-derived passwords, absent or weak MFA, reused credentials and insufficient identity telemetry. Defenders should inventory every account, enforce phishing-resistant MFA, rotate exposed secrets, restrict service accounts and alert on unusual locations, devices, downloads and API use. “Snowflake breach” is therefore too broad unless a specific incident establishes vendor-side compromise.

ALPHV/BlackCat: the affiliate business model

ALPHV/BlackCat is best understood as a RaaS operation: developers and operators provide malware and infrastructure while affiliates conduct many intrusions. The reported $22 million Change Healthcare payment should be attributed to reporting or threat-intelligence accounts, not presented as confirmed by the HHS FAQ. Operator, affiliate, negotiator and any later extortion actor are not necessarily the same entity.

The U.S. Department of Justice describes the broader campaign against BlackCat and a decryption tool that helped victims avoid approximately $68 million in ransom demands, but that figure does not validate the Change Healthcare payment: DOJ cybercrime fact sheet. A payment also does not prove that stolen data was deleted or that systems were safely restored.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

RansomHub: portable affiliates and disputed attribution

A joint FBI, CISA, HHS and MS-ISAC advisory identifies RansomHub as a RaaS variant formerly known as Cyclops and Knight. It reported that at least 210 victims had experienced encryption and exfiltration since February 2024 and that experienced affiliates had moved into the operation: joint RansomHub advisory.

RansomHub was discussed in connection with fallout from the Change Healthcare attack, but public material does not establish that it itself stole more than 100 million Change Healthcare records. Victim counts, data custody and attribution can change as affiliates and brands change. Treat the advisory’s 210-victim figure as a reported threshold, not a universal measure of all activity.

LockBit: disruption reduces capacity, not the business model

International authorities announced the disruption of LockBit infrastructure on February 20, 2024. DOJ said the operation had targeted more than 2,000 victims and received over $120 million in ransom payments before that action: DOJ disruption announcement. A later case alleged that the administrator received a 20% share and at least $100 million in digital-currency disbursements; those are separate legal allegations and should not be merged casually: DOJ administrator case.

Google Cloud reported a substantial fall in LockBit incidents after the legal actions, while some LockBit-branded activity continued: Google Cloud 2025 ransomware analysis. Rebrands, retained stolen data and migrating affiliates mean a takedown is not the same as eradication.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Midnight Blizzard: cloud identity as an espionage target

Midnight Blizzard (also known as APT29) is a Russia-linked espionage actor, not primarily a ransom operation. Microsoft documented a campaign that sent malicious RDP configuration files to thousands of users across more than 100 organizations, with lures referencing Microsoft, AWS and Zero Trust: Microsoft analysis.

Its SaaS relevance lies in stolen credentials, cloud-account persistence, legitimate remote-access tools and downstream access through service providers. Detection must include identity, session and impossible-travel analytics, not only endpoint malware alerts.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Scattered Spider and emerging brands

Scattered Spider is a watch candidate associated with help-desk social engineering, password resets, MFA-enrollment abuse and SIM swapping. These methods make recovery procedures part of the SaaS attack surface. Phishing-resistant authentication is stronger than SMS MFA, but only when enrollment, device replacement and account recovery are tightly controlled. The available evidence does not support calling it a confirmed 2025 “comeback.”

New names such as Hellcat illustrate an attribution problem. A fresh leak-site brand may be a rebrand, an affiliate collective or an opportunistic claimant. Evaluate infrastructure, tooling, victimology and tactics—not a name or an unverified announcement alone.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The shared cloud attack chain

  1. Initial access: stolen credentials, infostealer logs, phishing, help-desk manipulation, exposed remote access or a compromised supplier.
  2. Identity escalation: MFA reset or enrollment abuse, session-cookie or OAuth-token theft, privilege escalation and dormant administrator accounts.
  3. Discovery: mailboxes, shared drives, CRM records, ticketing systems, collaboration channels, connected applications, cloud storage and data warehouses.
  4. Collection: bulk API requests, archive creation, valid-account downloads and legitimate synchronization or transfer tools.
  5. Outcome: encryption and ransom, leak-site extortion, quiet intelligence collection or downstream targeting through a provider.
  6. Persistence: extra accounts, OAuth applications, API keys, forwarding rules, remote-management tools and backdoor accounts retained after a password reset.

Controls mapped to the attack path

Exposure Priority controls
Stolen credentials Phishing-resistant MFA or passkeys, conditional access, password rotation and infostealer response
OAuth and token abuse Admin approval for consent, scoped permissions, grant reviews and token revocation
Privilege escalation Least privilege, separate administrator accounts and just-in-time access
Bulk SaaS exfiltration API and download monitoring, user/entity behavior analytics and volume alerts
Help-desk takeover Strong identity proofing, independent callbacks and dual approval for MFA resets
Third-party integrations Application inventory, scoped tokens, rotation and prompt offboarding
Remote-access abuse Allowlisting, privileged-access management and session recording
Extortion response Immutable backups, evidence preservation, breach counsel and a rehearsed communications plan

How to read claims without overcounting

  • Separate a demand, a negotiated amount, a cryptocurrency transfer and total criminal proceeds.
  • Do not equate affected people with downloaded records or complete medical files.
  • Label evidence as government or victim-confirmed, named-vendor assessed, reputable-media reported, actor-claimed or disputed.
  • Track affiliates and techniques because ransomware brands frequently rebrand and share infrastructure.
  • Remember that data theft, account takeover and espionage can matter even when no systems are encrypted.

What to monitor in 2025

  • Affiliate migration after arrests and infrastructure takedowns.
  • Identity-provider compromise, OAuth abuse and session-token theft.
  • Bulk downloads from cloud storage, CRM and data-warehouse services.
  • Help-desk and account-recovery attacks.
  • State actors using legitimate cloud APIs and remote-access tooling.
  • Extortion brands claiming attacks without independently verifiable evidence.

The Bottom Line

The durable risk is not one “all-star” gang. It is the repeated abuse of legitimate identities, trusted integrations and cloud services in ways that resemble normal business activity. Organizations that harden authentication and recovery, limit privilege, govern OAuth and integrations, monitor SaaS data movement and rehearse extortion response will reduce exposure across ransomware, credential theft and espionage alike.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase07 MAR 2625 minWhat Is a 457 Plan?
  2. The Money DeskBlogTheFinanceBase07 MAR 2621 minTime Value of Money: What It Is and How It Works
  3. The Money DeskBlogTheFinanceBase07 MAR 2627 minAre You Living in One of These Top 10 Most Expensive Cities to Retire?
Recommended PC Tool
Recommended PC Tool
PC Slower Than It Used to Be?Free scan - under a minute
Crashes, No Sound, or Screen Glitches?Free driver scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.