HomeSecurityTyler Technologies: Change remote support passwords

Tyler Technologies: Change remote support passwords

Tyler Technologies is advising customers to change their remote access account passwords after suspicious connections were reported to the company.

Last Sunday, we informed you that government technology services provider Tyler Technologies suffered a ransomware attack.

Tyler Technologies

This attack was carried out by the RansomExx/Defray777 operation, which encrypted the company's devices and disrupted operations.

Remote support accounts used in suspicious connections

Some customers create accounts that Tyler Technologies staff use to gain remote access to their network.

In an email sent last night by Tyler Technologies – and obtained by Bleepingcomputer – CIO Matt Bieri warns customers that the “Tyler credentials” used for remote access have been reported to be used to perform suspicious connections.

“We apologize for the inconvenience, but we wanted to let you know about something serious as soon as possible. We recently learned that two customers using Tyler remote access credentials have reported suspicious connections to their systems. While no malicious activity on customer systems and we have not been able to investigate or determine the details of these connections, we wanted to let you know immediately so you can protect your systems,” said the email sent to Tyler Technology customers by CIO Matt Bieri.

It is not known if these reports of suspicious activity are related to the recent ransomware attack, but to be safe, they are advising their customers to change all passwords for accounts used by Tyler Technologies.

“Given this new information, and if you have not already done so, we recommend that you reset remote access passwords for Tyler personnel and the credentials that Tyler personnel would use to access your applications, where applicable. We do not have enough information to know whether the reports of suspicious activity are related to the ongoing investigation of unauthorized access to Tyler’s internal systems, we believe that proactive password,” the email said.

Bieri asks all customers who spot suspicious connections to report them to Tyler Technologies immediately.

Could attackers gain access to customer networks?

When human-operated ransomware attacks are carried out, attackers are typically on the network for days, if not weeks, before deploying the ransomware and encrypting devices.

To be safe, all customers should immediately change the passwords on accounts that Tyler Technologies personnel use to access their network.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS