OAK — OnChain Attack Knowledge

Worked example · 2023-09

Caesars Entertainment ransom payment — ALPHV / Scattered Spider — 2023-09

Loss
approximately $15M paid in cryptocurrency (per multiple Wall Street Journal, Reuters, and Bloomberg reports anchored on people-familiar-with-the-matter sourcing; Caesars's September 7, 2023 Form 8-K filing acknowledges the cyberattack and notes that the company "took steps to ensure that the stolen data is deleted by the unauthorized actor, although [it] cannot guarantee this result," with associated costs reflected in subsequent filings); the original ransom demand per public reporting was approximately $30M and was negotiated down to approximately $15M. The on-chain event documented here is the negotiated ransom-payment surface; the off-chain enterprise IT compromise is out of OAK Tactic scope.
OAK Techniques observed
OAK-T5.008 (Ransomware Extortion Payment) — the extortion-payment leg of the ransomware kill chain; OAK-T7.002 (CEX Deposit-Address Layering) — the canonical post-2023 ALPHV-affiliate off-ramp pattern observed at the affiliate-controlled wallet's downstream layering surface; OAK-T8.001 (Common-Funder Cluster Reuse) — wallet-funder-cluster signature continuity across the ALPHV-affiliate-cohort wallet activity used by industry forensic providers to attest the cluster attribution.
Attribution
confirmed at the cluster-and-named-affiliate level. The November 13, 2024 U.S. DOJ five-defendant indictment named the Caesars campaign explicitly as a predicate intrusion alongside the parallel MGM intrusion ([doj2024scatteredspider]); CISA / FBI joint cybersecurity advisory AA23-352A characterises the Scattered Spider / UNC3944 cluster TTPs ([cisa2023aa23352ascatteredspider]); Mandiant UNC3944 attribution write-ups corroborate the affiliate-cluster identity ([mandiant2023unc3944]); Wired investigative reporting consolidates the public-record facts ([wired2023mgmcaesars]). Per-flow attribution to specific downstream venues for the ~$15M payment is inferred-strong per industry-forensic reconstruction; Caesars's Form 8-K does not disclose the on-chain payment trace at granular detail.
OAK-Gnn
OAK-G10 ALPHV / BlackCat at the operating-brand level; OAK-G12 Scattered Spider / UNC3944 at the affiliate-collective level. The Caesars intrusion is the parallel-pay-yes companion case to MGM Resorts (examples/2023-09-mgm-resorts.md).
Key teaching point
The Caesars Entertainment case is the paired pay-yes companion to the MGM Resorts pay-no case from the same operational week. The contrast across the two cases — same upstream OAK-G10-by-OAK-G12 affiliate-collective cluster activity, opposite victim-side decision — is the canonical 2023 paired case in the public record for ransomware-payment decision-making literature.

Summary

In late August / early September 2023, Caesars Entertainment suffered a Scattered-Spider-attributed intrusion deploying the OAK-G10 ALPHV / BlackCat encryptor. The off-chain entry vector per CISA AA23-352A and Mandiant UNC3944 tracking was social-engineering of an outsourced IT-support vendor — the cluster's signature help-desk-vishing vector adapted to the outsourced-IT-support-vendor surface. Per Caesars's September 7, 2023 Form 8-K filing, the company acknowledged the cyberattack and stated it had taken steps to ensure the stolen data was deleted by the unauthorized actor; per multiple Wall Street Journal, Reuters, and Bloomberg reports the company paid approximately $15M of an originally-demanded $30M ransom in cryptocurrency.

The case is the paired pay-yes companion to the MGM Resorts pay-no case (examples/2023-09-mgm-resorts.md) — same upstream affiliate-collective (Scattered Spider / UNC3944), same operating-brand encryptor (ALPHV / BlackCat), same week of intrusion, opposite victim-side decision. The pay-vs-no-pay contrast across MGM and Caesars in the same operational window is widely cited in incident-response and CISO-decision-making literature as the canonical 2023 paired case.

For OAK's purposes the case anchors OAK-G10 at the operating-brand level and OAK-G12 at the affiliate-collective level on both the cluster-attribution axis and the on-chain-payment-trace axis. Compared with MGM (where no payment was made), the Caesars case provides the on-chain-payment-trace anchor — though at inferred-strong per-flow granularity rather than the confirmed-grade granularity of the Change Healthcare case (examples/2024-02-change-healthcare-ransom.md), because Caesars's Form 8-K disclosure tempo did not produce a public on-chain trace at the granular detail UnitedHealth Group's later disclosure produced.

Timeline (UTC)

When Event OAK ref
Late August 2023 Scattered Spider affiliates social-engineer Caesars's outsourced IT-support vendor; ALPHV / BlackCat encryptor deployed downstream of credential compromise (off-chain entry vector — out of OAK Tactic scope) (off-chain entry)
Early September 2023 Negotiation period; original ransom demand reportedly ~$30M (off-chain negotiation)
September 2023 (early) Caesars pays approximately $15M in cryptocurrency per WSJ / Reuters / Bloomberg reporting; data-deletion assurance taken per the operator's representation Ransom-payment event (T7.002 downstream)
2023-09-07 Caesars Form 8-K filing acknowledges cyberattack and notes data-deletion assurance; payment is implicitly acknowledged through cost recognition without explicit on-chain detail (victim-side disclosure)
2023-09-10 MGM Resorts parallel intrusion begins — see examples/2023-09-mgm-resorts.md (parallel cluster activity)
2023-12-14 CISA / FBI joint cybersecurity advisory AA23-352A "Scattered Spider" issued ([cisa2023aa23352ascatteredspider]) (cluster-attribution document)
2024-11-13 U.S. DOJ unsealed five-defendant indictment naming Caesars and MGM campaigns as predicate intrusions ([doj2024scatteredspider]) Named-defendant attribution at confirmed

What defenders observed

  • Outsourced-IT-support-vendor as initial-access surface. The Caesars case extends the help-desk-vishing initial-access-vector pattern from the in-house help-desk surface (the MGM case) to the outsourced-IT-support-vendor surface. Defenders should expect the Scattered Spider / UNC3944 affiliate cohort to target both surfaces, and the outsourced-vendor surface produces additional supply-chain-style identity-substrate exposure that may not be directly visible to the victim's first-party IAM controls.
  • Pay-yes-with-data-deletion-assurance is a sustained operator-pressure-tactic pattern. The Caesars settlement structure (negotiated payment in exchange for the operator's representation that exfiltrated data was deleted) is a recurring feature of RaaS-affiliate negotiations. Per industry-forensic tracking and per multiple subsequent leaked-internal-chat archives (notably ContiLeaks and BlackBastaLeaks), operator-side data-deletion assurances are frequently not honoured — the affiliate retains access to the exfiltrated data archive and may re-monetise it in a successor-brand re-extortion event (the Change Healthcare re-extortion case at examples/2024-04-change-healthcare-reextortion.md is the canonical worked example).
  • Pay-vs-no-pay disclosure cost asymmetry. Caesars's choice to pay incurred a smaller direct dollar cost ($15M) than MGM's choice to refuse ($100M business-interruption cost), but produced different downstream sectoral-disclosure dynamics: Caesars's Form 8-K disclosure was more constrained in detail and avoided the multi-week public-press-cycle exposure that MGM absorbed. The disclosure-cost asymmetry is not symmetric across all victim contexts; defender / CISO decision-making literature notes that the calculus is sector-specific and victim-specific.
  • On-chain payment trace at inferred-strong per-flow granularity. Unlike the Change Healthcare case (where the ~$22M payment trace was published by industry forensic providers within hours), Caesars's payment was not publicly traced at granular per-hop detail. The cluster attribution remains confirmed-grade through the November 2024 DOJ indictment, but the per-flow trace is inferred-strong only. OAK contributors should preserve this attribution-strength asymmetry between cluster-level and per-flow-level claims.

What this example tells contributors writing future Technique pages

  • Pay-yes outcomes vary in on-chain-trace public-record granularity. Future ransom-payment examples should expect that some pay-yes outcomes (Change Healthcare, Caesars) will have varying granularity on-chain depending on the victim's disclosure tempo and the industry-forensic-provider tracking resources allocated to the case. Granular per-flow trace is not always publicly available even when cluster attribution is confirmed-grade.
  • Outsourced-IT-support-vendor is a sustained initial-access-vector surface. Defender control-set design for help-desk-vishing-class attacks should explicitly include outsourced-IT-support-vendor surfaces, not only in-house help-desk surfaces. The Caesars case is the canonical worked example.
  • Operator-side data-deletion assurances are a recurring operator-pressure-tactic pattern that defenders should treat as low-credibility. Future RaaS-payment examples should explicitly mark whether the operator made a data-deletion assurance and whether subsequent re-extortion or data-leak events occurred. The Change Healthcare → RansomHub re-extortion case is the canonical demonstration that affiliate retention of victim-data archives across cluster-termination events is the default expectation, not an exception.

Public references

  • [doj2024scatteredspider] — U.S. DOJ five-defendant indictment unsealed November 13, 2024 against Elbadawy, Urban, Osiebo, Evans, and Buchanan; cluster-attribution document.
  • [cisa2023aa23352ascatteredspider] — Joint CISA / FBI cybersecurity advisory AA23-352A on Scattered Spider TTPs, December 14, 2023.
  • [mandiant2023unc3944] — Mandiant UNC3944 attribution write-up.
  • [wired2023mgmcaesars] — Wired investigative reporting on the MGM and Caesars intrusions and the Scattered Spider / ALPHV operational pattern.
  • [microsoftoctotempest] — Microsoft Threat Intelligence on Octo Tempest activity.
  • [paloaltomuddledlibra] — Palo Alto Networks Unit 42 Muddled Libra tracker write-up.

Discussion

The Caesars Entertainment case is the paired pay-yes companion to the MGM Resorts pay-no case from the same operational week. The contrast across the two cases — same upstream OAK-G10-by-OAK-G12 affiliate-collective cluster activity, opposite victim-side decision — is the canonical 2023 paired case in the public record for ransomware-payment decision-making literature.

The case also extends the OAK-G12 Scattered Spider initial-access-vector profile from the in-house help-desk surface to the outsourced-IT-support-vendor surface. Defender control-set design for help-desk-vishing-class attacks should explicitly include both surfaces. Caesars's reliance on outsourced IT support produced an identity-substrate-supply-chain exposure that the affiliate cohort exploited successfully; future enterprise IT supply-chain-resilience design should treat outsourced-IT-support vendor identity-substrate as in-scope for help-desk-vishing-class control-set coverage.

The on-chain trace of the ~$15M payment is at inferred-strong per-flow granularity rather than the confirmed-grade granularity of the Change Healthcare case. OAK contributors writing future RaaS-payment examples should expect this asymmetry — the public-record granularity of on-chain payment traces depends on the victim's disclosure tempo and the industry-forensic-provider tracking resources allocated to the case, not solely on cluster-attribution strength.

Techniques demonstrated (3)