This case study details how a global game developer successfully thwarted a $10 million ransomware attack using network evidence. The company faced a significant challenge when it received a ransom demand, claiming that sensitive source code and critical intellectual property had been stolen. Their existing security measures were insufficient to verify the attackers' claims. The security team utilized Corelight’s Open NDR Platform, which provided comprehensive network evidence through its Zeek and Suricata engines. This evidence allowed the team to trace the attackers' movements and build a timeline of the incident. The investigation revealed that the attackers had lied about the extent of the data exfiltration, which was limited and non-critical. Consequently, the leadership team confidently rejected the ransom demand, saving the company $10 million. The findings also led to improvements in security posture by identifying vulnerabilities in network hygiene, such as the use of plaintext passwords. Overall, the case study illustrates the effectiveness of high-fidelity network evidence in incident response.