Worked example · 2023-09
Caesars Entertainment ransom payment — ALPHV / Scattered Spider — 2023-09
Summary
In late August / early September 2023, Caesars Entertainment suffered a Scattered-Spider-attributed intrusion deploying the OAK-G10 ALPHV / BlackCat encryptor. The off-chain entry vector per CISA AA23-352A and Mandiant UNC3944 tracking was social-engineering of an outsourced IT-support vendor — the cluster's signature help-desk-vishing vector adapted to the outsourced-IT-support-vendor surface. Per Caesars's September 7, 2023 Form 8-K filing, the company acknowledged the cyberattack and stated it had taken steps to ensure the stolen data was deleted by the unauthorized actor; per multiple Wall Street Journal, Reuters, and Bloomberg reports the company paid approximately $15M of an originally-demanded $30M ransom in cryptocurrency.
The case is the paired pay-yes companion to the MGM Resorts pay-no case (examples/2023-09-mgm-resorts.md) — same upstream affiliate-collective (Scattered Spider / UNC3944), same operating-brand encryptor (ALPHV / BlackCat), same week of intrusion, opposite victim-side decision. The pay-vs-no-pay contrast across MGM and Caesars in the same operational window is widely cited in incident-response and CISO-decision-making literature as the canonical 2023 paired case.
For OAK's purposes the case anchors OAK-G10 at the operating-brand level and OAK-G12 at the affiliate-collective level on both the cluster-attribution axis and the on-chain-payment-trace axis. Compared with MGM (where no payment was made), the Caesars case provides the on-chain-payment-trace anchor — though at inferred-strong per-flow granularity rather than the confirmed-grade granularity of the Change Healthcare case (examples/2024-02-change-healthcare-ransom.md), because Caesars's Form 8-K disclosure tempo did not produce a public on-chain trace at the granular detail UnitedHealth Group's later disclosure produced.
Timeline (UTC)
| When | Event | OAK ref |
|---|---|---|
| Late August 2023 | Scattered Spider affiliates social-engineer Caesars's outsourced IT-support vendor; ALPHV / BlackCat encryptor deployed downstream of credential compromise (off-chain entry vector — out of OAK Tactic scope) | (off-chain entry) |
| Early September 2023 | Negotiation period; original ransom demand reportedly ~$30M | (off-chain negotiation) |
| September 2023 (early) | Caesars pays approximately $15M in cryptocurrency per WSJ / Reuters / Bloomberg reporting; data-deletion assurance taken per the operator's representation | Ransom-payment event (T7.002 downstream) |
| 2023-09-07 | Caesars Form 8-K filing acknowledges cyberattack and notes data-deletion assurance; payment is implicitly acknowledged through cost recognition without explicit on-chain detail | (victim-side disclosure) |
| 2023-09-10 | MGM Resorts parallel intrusion begins — see examples/2023-09-mgm-resorts.md |
(parallel cluster activity) |
| 2023-12-14 | CISA / FBI joint cybersecurity advisory AA23-352A "Scattered Spider" issued ([cisa2023aa23352ascatteredspider]) |
(cluster-attribution document) |
| 2024-11-13 | U.S. DOJ unsealed five-defendant indictment naming Caesars and MGM campaigns as predicate intrusions ([doj2024scatteredspider]) |
Named-defendant attribution at confirmed |
What defenders observed
- Outsourced-IT-support-vendor as initial-access surface. The Caesars case extends the help-desk-vishing initial-access-vector pattern from the in-house help-desk surface (the MGM case) to the outsourced-IT-support-vendor surface. Defenders should expect the Scattered Spider / UNC3944 affiliate cohort to target both surfaces, and the outsourced-vendor surface produces additional supply-chain-style identity-substrate exposure that may not be directly visible to the victim's first-party IAM controls.
- Pay-yes-with-data-deletion-assurance is a sustained operator-pressure-tactic pattern. The Caesars settlement structure (negotiated payment in exchange for the operator's representation that exfiltrated data was deleted) is a recurring feature of RaaS-affiliate negotiations. Per industry-forensic tracking and per multiple subsequent leaked-internal-chat archives (notably ContiLeaks and BlackBastaLeaks), operator-side data-deletion assurances are frequently not honoured — the affiliate retains access to the exfiltrated data archive and may re-monetise it in a successor-brand re-extortion event (the Change Healthcare re-extortion case at
examples/2024-04-change-healthcare-reextortion.mdis the canonical worked example). - Pay-vs-no-pay disclosure cost asymmetry. Caesars's choice to pay incurred a smaller direct dollar cost (
$15M) than MGM's choice to refuse ($100M business-interruption cost), but produced different downstream sectoral-disclosure dynamics: Caesars's Form 8-K disclosure was more constrained in detail and avoided the multi-week public-press-cycle exposure that MGM absorbed. The disclosure-cost asymmetry is not symmetric across all victim contexts; defender / CISO decision-making literature notes that the calculus is sector-specific and victim-specific. - On-chain payment trace at inferred-strong per-flow granularity. Unlike the Change Healthcare case (where the ~$22M payment trace was published by industry forensic providers within hours), Caesars's payment was not publicly traced at granular per-hop detail. The cluster attribution remains confirmed-grade through the November 2024 DOJ indictment, but the per-flow trace is inferred-strong only. OAK contributors should preserve this attribution-strength asymmetry between cluster-level and per-flow-level claims.
What this example tells contributors writing future Technique pages
- Pay-yes outcomes vary in on-chain-trace public-record granularity. Future ransom-payment examples should expect that some pay-yes outcomes (Change Healthcare, Caesars) will have varying granularity on-chain depending on the victim's disclosure tempo and the industry-forensic-provider tracking resources allocated to the case. Granular per-flow trace is not always publicly available even when cluster attribution is confirmed-grade.
- Outsourced-IT-support-vendor is a sustained initial-access-vector surface. Defender control-set design for help-desk-vishing-class attacks should explicitly include outsourced-IT-support-vendor surfaces, not only in-house help-desk surfaces. The Caesars case is the canonical worked example.
- Operator-side data-deletion assurances are a recurring operator-pressure-tactic pattern that defenders should treat as low-credibility. Future RaaS-payment examples should explicitly mark whether the operator made a data-deletion assurance and whether subsequent re-extortion or data-leak events occurred. The Change Healthcare → RansomHub re-extortion case is the canonical demonstration that affiliate retention of victim-data archives across cluster-termination events is the default expectation, not an exception.
Public references
[doj2024scatteredspider]— U.S. DOJ five-defendant indictment unsealed November 13, 2024 against Elbadawy, Urban, Osiebo, Evans, and Buchanan; cluster-attribution document.[cisa2023aa23352ascatteredspider]— Joint CISA / FBI cybersecurity advisory AA23-352A on Scattered Spider TTPs, December 14, 2023.[mandiant2023unc3944]— Mandiant UNC3944 attribution write-up.[wired2023mgmcaesars]— Wired investigative reporting on the MGM and Caesars intrusions and the Scattered Spider / ALPHV operational pattern.[microsoftoctotempest]— Microsoft Threat Intelligence on Octo Tempest activity.[paloaltomuddledlibra]— Palo Alto Networks Unit 42 Muddled Libra tracker write-up.
Discussion
The Caesars Entertainment case is the paired pay-yes companion to the MGM Resorts pay-no case from the same operational week. The contrast across the two cases — same upstream OAK-G10-by-OAK-G12 affiliate-collective cluster activity, opposite victim-side decision — is the canonical 2023 paired case in the public record for ransomware-payment decision-making literature.
The case also extends the OAK-G12 Scattered Spider initial-access-vector profile from the in-house help-desk surface to the outsourced-IT-support-vendor surface. Defender control-set design for help-desk-vishing-class attacks should explicitly include both surfaces. Caesars's reliance on outsourced IT support produced an identity-substrate-supply-chain exposure that the affiliate cohort exploited successfully; future enterprise IT supply-chain-resilience design should treat outsourced-IT-support vendor identity-substrate as in-scope for help-desk-vishing-class control-set coverage.
The on-chain trace of the ~$15M payment is at inferred-strong per-flow granularity rather than the confirmed-grade granularity of the Change Healthcare case. OAK contributors writing future RaaS-payment examples should expect this asymmetry — the public-record granularity of on-chain payment traces depends on the victim's disclosure tempo and the industry-forensic-provider tracking resources allocated to the case, not solely on cluster-attribution strength.