Worked example · 2023-09
MGM Resorts ransomware intrusion — ALPHV / Scattered Spider — 2023-09-10
Summary
On September 10, 2023, MGM Resorts International suffered a multi-day IT-system outage across casino-floor systems, hotel-keycard systems, slot machines, digital reservations, and consumer-services infrastructure at multiple Las Vegas Strip properties (Bellagio, Aria, MGM Grand, Mandalay Bay, Cosmopolitan-MGM-managed, others). The off-chain entry vector per industry-forensic reporting and per the November 2024 DOJ indictment was help-desk-vishing of an MGM IT-support staff member by Scattered Spider / UNC3944 affiliates running the OAK-G10 ALPHV / BlackCat encryptor. The intrusion produced approximately a 10-day operational outage with manual fallback procedures (paper keycards, manual reservation handling) across multiple properties.
Per MGM's October 2023 Form 8-K filing, the company estimated approximately $100M in business-interruption cost from the incident and chose to refuse the ransom demand. No on-chain payment was made; the case therefore does not produce a payment-trace anchor and OAK records it as a negative-case (no-payment) example of an OAK-G10-by-OAK-G12 operational pattern. The case anchors OAK-G10 at the operating-brand level and OAK-G12 at the affiliate-collective level on the cluster-attribution axis rather than on the on-chain-payment-trace axis.
For OAK's purposes the case is the canonical worked example of the English-speaking-affiliate-collective running a Russian-language-RaaS-encryptor operational pattern that defines the OAK-G10 / OAK-G12 cluster-boundary distinction. Compared to OAK-G05 LockBit (where the affiliate cohort is dominantly Russian-language criminal-forum operators) the MGM case demonstrates that the RaaS-as-tooling and RaaS-as-affiliate-collective layers can have different operator-language-and-passport profiles, and that defender control-set design needs to assume both layers are operative.
Timeline (UTC)
| When | Event | OAK ref |
|---|---|---|
| 2023-09-10 onward | Help-desk-vishing of MGM IT-support staff member by Scattered Spider affiliates; ALPHV / BlackCat encryptor deployed (off-chain entry vector — out of OAK Tactic scope) | (off-chain entry) |
| 2023-09-10 to 2023-09-20 | ~10-day multi-property IT-system outage across MGM Las Vegas Strip properties; paper-keycard and manual-reservation fallback in operation | (off-chain operational impact) |
| 2023-09-14 | Caesars Entertainment publicly discloses parallel intrusion with reported ransom payment — see examples/2023-09-caesars-entertainment.md |
(parallel cluster activity) |
| 2023-10 | MGM Resorts International Form 8-K filing estimates ~$100M in business-interruption cost; MGM publicly refuses to pay | No-payment outcome on the negative-case axis |
| 2023-12-14 | CISA / FBI joint cybersecurity advisory AA23-352A "Scattered Spider" issued ([cisa2023aa23352ascatteredspider]) |
(cluster-attribution document) |
| 2024-07 | Tyler Robert Buchanan arrested in Palma de Mallorca by Spanish National Police pursuant to U.S. and U.K. extradition requests | (named-defendant arrest) |
| 2024-11-13 | U.S. DOJ unsealed five-defendant indictment naming MGM and Caesars campaigns as predicate intrusions ([doj2024scatteredspider]) |
Named-defendant attribution at confirmed |
What defenders observed
- Help-desk-vishing as primary initial-access vector. The MGM intrusion is the canonical 2023 case of help-desk social-engineering as the principal RaaS-affiliate initial-access vector. Per the CISA AA23-352A advisory and Mandiant UNC3944 tracking, the Scattered Spider / UNC3944 affiliate cohort's English-speaking operator profile produces native-speaker advantage in vishing U.S.-and-U.K. help-desk staff — a profile materially different from the Russian-language-affiliate-cohort vector profile (exploitation-of-public-facing-vulnerabilities, exposed-RDP, exposed-VPN-without-MFA) that dominates the broader RaaS-affiliate landscape.
- No-payment outcome and the disclosure-cost trade-off. MGM's choice to refuse payment incurred approximately $100M in business-interruption cost; Caesars's parallel choice to pay incurred a smaller direct dollar cost (~$15M reported) but produced different downstream sectoral-disclosure dynamics. The MGM-vs-Caesars contrast is the canonical 2023 case in the public record of paired victim-pay-vs-no-pay decision outcomes for parallel intrusions by the same affiliate-collective in the same week and is widely cited in incident-response and CISO-decision-making literature.
- Multi-RaaS-affiliate operating model. Scattered Spider's operational pattern of running intrusions against multiple RaaS-tooling brands (ALPHV in 2023, RansomHub from 2024 onward, DragonForce / Qilin in 2025) means that defender attribution against the affiliate-collective surface can produce confirmed-grade attribution at the OAK-G12 layer that survives RaaS-tooling-rotation events. Defender control-set design should treat OAK-G12 as a persistent identity across RaaS-tooling rotations.
- Negative-case attribution anchoring. Even without an on-chain payment, the MGM case anchors OAK-G10 and OAK-G12 at confirmed-grade attribution because the November 2024 DOJ indictment named the campaigns explicitly. Future OAK content should not require an on-chain payment trace to anchor a Group-attribution case at confirmed-grade — court-filing-and-OFAC-designation-level attribution is sufficient.
What this example tells contributors writing future Technique pages
- No-payment outcomes are valid OAK examples. Examples without on-chain payment traces but with strong cluster attribution at the indictment-and-advisory layer are valid Group-attribution anchors in the OAK corpus. The MGM case anchors OAK-G10 and OAK-G12 at confirmed-grade despite the absence of an on-chain payment trace. Future Group-attribution examples should not be excluded for lack of payment trace if the indictment-and-advisory attribution layer is sufficient.
- The Russian-language-RaaS-tooling × English-speaking-affiliate-collective pattern is a sustained operating model. Future RaaS-attributed examples should expect that the operating-brand language profile and the affiliate-collective language profile may differ; OAK content should mark this distinction explicitly when both layers are operative, rather than collapsing them into a single language-or-passport attribution.
- The paired-victim-decision contrast (MGM-pay-no vs Caesars-pay-yes) is a structural OAK observation. Defender control-set design and OAK contributor framing should treat the pay-vs-no-pay decision as a structurally observable downstream outcome of the same upstream cluster intrusion, not as evidence of different upstream cluster activity. The companion example at
examples/2023-09-caesars-entertainment.mddocuments the parallel pay-yes outcome.
Public references
[doj2024scatteredspider]— U.S. DOJ five-defendant indictment unsealed November 13, 2024 against Elbadawy, Urban, Osiebo, Evans, and Buchanan for wire fraud, conspiracy, and aggravated identity theft tied to MGM Resorts and Caesars Entertainment campaigns.[cisa2023aa23352ascatteredspider]— Joint CISA / FBI cybersecurity advisory AA23-352A on Scattered Spider TTPs, December 14, 2023.[mandiant2023unc3944]— Mandiant UNC3944 attribution write-up.[wired2023mgmcaesars]— Wired investigative reporting on the MGM and Caesars intrusions and the Scattered Spider / ALPHV operational pattern.[microsoftoctotempest]— Microsoft Threat Intelligence on Octo Tempest activity and the multi-RaaS-affiliate operating profile.[paloaltomuddledlibra]— Palo Alto Networks Unit 42 Muddled Libra tracker write-up.
Discussion
MGM Resorts is the canonical 2023 case of the Russian-language-RaaS-tooling × English-speaking-affiliate-collective operational pattern that anchors the OAK-G10 / OAK-G12 cluster-boundary distinction. The case demonstrates that RaaS-as-tooling (OAK-G10 ALPHV) and RaaS-as-affiliate-collective (OAK-G12 Scattered Spider) operate as independent persistent identities in the public record — Scattered Spider continued running intrusions against successor RaaS brands (RansomHub, DragonForce, Qilin) after the OAK-G10 March 2024 exit-scam terminated the ALPHV operating brand. Defender control-set design should treat the two cluster layers as orthogonal: anti-OAK-G10 controls (encryptor-strain-specific detection, ALPHV-cluster-wallet watchlist) target the operating-brand layer; anti-OAK-G12 controls (help-desk-vishing detection, identity-substrate-attack defense, English-speaking-affiliate-collective TTP coverage) target the affiliate-collective layer.
The MGM case also illustrates that negative-case (no-payment) outcomes are first-class OAK examples. The case has no on-chain payment trace, but the cluster-attribution at the November 2024 DOJ indictment layer is confirmed-grade and the off-chain operational impact (~$100M in business-interruption cost) is on the public record. OAK contributors should not require an on-chain payment trace to anchor a Group-attribution case if the indictment-and-advisory attribution is sufficient. The companion Caesars Entertainment example (examples/2023-09-caesars-entertainment.md) documents the parallel pay-yes outcome and provides the on-chain-payment-trace anchor for the same upstream cluster activity.