Tyler Technologies tells users to change passwords after ransomware attack

(Image credit: Shutterstock / Askobol)

Tyler Technologies, one of the largest US public sector technology providers, has suffered a ransomware attack that disrupted operations, and may have resulted in the theft of remote access credentials, among other data.

The ransomware in question, dubbed RansomExx, terminates more than 280 security process on Windows devices, enabling hackers to gain access to a system and sift through files for sensitive or proprietary data, in the hopes of stealing, encrypting, and holding it for ransom.

While hackers may have been in the system for days or even weeks, as is often the case with ransomware attacks, Tyler Technologies only became aware of the problem late last week. An email was sent out to customers on the 23rd stating an "unauthorized intruder" had disrupted access to its internal systems.

Change passwords

Shortly after customers received news of the ransomware attack, Tyler was forced to send out another security email, this time advising clients of reports it had received concerning suspicious activity linked to Tyler remote-access credentials, which the company uses to provide technical support.

The email goes on to say that, although it was unable to pinpoint any malicious activity, the company recommended “precautionary password resets," to be safe.

“Given this new information … we strongly recommend that you reset passwords on your remote network access for Tyler staff, and the credentials that Tyler personnel would use to access your applications, where applicable,” wrote Tyler Technology CIO Matt Bieri, and urged clients to immediately report any suspicious activity.

While it’s unclear whether the ransomware attack and suspicious remote activity are related, it can’t be ruled out. The long investment in time put in by hackers when infiltrating a system and the high incentive for finding sensitive data means that few stones are left unturned, and this wouldn’t be the first time login credentials were stolen in an attack.

If the two are connected, then the same hackers who attacked Tyler may be able to gain access to clients’ systems as well. For this reason, all customers should update their passwords, and may want to use the opportunity to implement simple but effective security training.

Via BleepingComputer

Christian Rigg

Christian is a freelance writer and content project manager with 6+ years' experience writing and leading teams in finance and technology for some of the world's largest online publishers, including TechRadar and Tom's Guide.

Latest in Security
Data leak
Hacked Tata Technologies data leaked by ransomware gang
A close-up photo of an iPhone, with the App Store icon prominent in the center of the image.
Thousands of iOS apps found to expose user data and leak Stripe keys
China
Chinese hackers targeting Juniper Networks routers, so patch now
Google Chrome dark mode
Google updates Chrome extension rules to ban affiliate link injection without user action or benefit
Abstract image of robots working in an office environment including creating blueprint of robot arm, making a phone call, and typing on a keyboard
This worrying botnet targets unsecure TP-Link routers - thousands of devices already hacked
Avast cybersecurity
UK cybersecurity sector could be worth £13bn, research shows
Latest in News
UK Prime Minister Sir Kier Starmer
UK PM says AI should soon replace civil servants
Eight Samsung TVs mounted to the wall showing different basketball games
Samsung is offering you 8 new TVs in one bundle for March Madness, in case you want to watch all games at once like a Bond villain’s lair
The Steam Logo on a mobile phone in front of a wall of games.
Today’s Steam Spring Sale features my absolute favorite game of all time - here's when the sale starts and all the key info
Apple iPhone 16 Pro Max REVIEW
The latest iPhone 17 Pro Max leak may have given us another look at its upcoming redesign
Half-Life running on a smartwatch
This Redditor installed a game engine on their smartwatch, and now it runs Doom, Quake, and Half-Life
Samsung Galaxy Z Fold 6
The Samsung Galaxy Z Fold 7 could be in line for a Galaxy S25 Ultra-level camera upgrade