Tyler Technologies is advising customers to change their remote access account passwords after suspicious connections were reported to the company.
Last Sunday, we informed you that government technology services provider Tyler Technologies suffered a ransomware attack.

This attack was carried out by the RansomExx/Defray777 operation, which encrypted the company's devices and disrupted operations.
Remote support accounts used in suspicious connections
Some customers create accounts that Tyler Technologies staff use to gain remote access to their network.
In an email sent last night by Tyler Technologies – and obtained by Bleepingcomputer – CIO Matt Bieri warns customers that the “Tyler credentials” used for remote access have been reported to be used to perform suspicious connections.
“We apologize for the inconvenience, but we wanted to let you know about something serious as soon as possible. We recently learned that two customers using Tyler remote access credentials have reported suspicious connections to their systems. While no malicious activity on customer systems and we have not been able to investigate or determine the details of these connections, we wanted to let you know immediately so you can protect your systems,” said the email sent to Tyler Technology customers by CIO Matt Bieri.
It is not known if these reports of suspicious activity are related to the recent ransomware attack, but to be safe, they are advising their customers to change all passwords for accounts used by Tyler Technologies.
“Given this new information, and if you have not already done so, we recommend that you reset remote access passwords for Tyler personnel and the credentials that Tyler personnel would use to access your applications, where applicable. We do not have enough information to know whether the reports of suspicious activity are related to the ongoing investigation of unauthorized access to Tyler’s internal systems, we believe that proactive password,” the email said.
Bieri asks all customers who spot suspicious connections to report them to Tyler Technologies immediately.
Could attackers gain access to customer networks?
When human-operated ransomware attacks are carried out, attackers are typically on the network for days, if not weeks, before deploying the ransomware and encrypting devices.
To be safe, all customers should immediately change the passwords on accounts that Tyler Technologies personnel use to access their network.
