Tyler Technologies paid hackers the ransom they were demanding for a decryption key to recover encrypted files in a recent ransomware attack.
Tyler Technologies claims to be the largest software company in North America serving the public sector, with 2020 revenue of more than $1.2 billion and 5,500 employees.
On September 23, Tyler Technologies was attacked by the operators of the RansomExx ransomware, who were also behind recent attacks on Konica Minolta and IPG Photonics.

In response to the attack, Tyler Technologies immediately “disconnected” parts of its network to limit the spread of the ransomware and limit its customers’ exposure.
“Early this morning, we became aware that an unauthorized attacker had disrupted access to some of our internal systems. Upon discovery and out of an abundance of caution, we closed access points to external systems and immediately began investigating and remediating the issue,” said the email sent to customers by CIO Matt Bieri.
The attack caused an interruption to Tyler Technologies' operations, was contained locally, and did not spread to their customers.
Public sector sources have told BleepingComputer that the ransomware attack severely impacted Tyler Technologies and that the company expected it to take thirty days to fully recover operations .
Ransom paid to obtain a decryptor
A source told BleepingComputer that Tyler Technologies paid the ransom demanded by the RansomExx hackers to recover its encrypted data.
However, it is not known how much was paid to obtain the decryption key.
When the ransomware encrypted Tyler Technologies files, they added an extension similar to ".tylertech911-f1e1a2ac.".
To prove that the decryptor was valid, BleepingComputer was able to decrypt encrypted files uploaded to VirusTotal at the time of the ransomware attack.
When decrypted, the Arin.txt file contained a list of “IP ranges” used by the company.
RansomExx is also known to steal data before encrypting devices on a network. The ransomware operators then threaten to release this stolen dataunless the victim pays the ransom.
Given that many school districts , court systems, and local governments in the United States are customers of Tyler Technologies, the risk of sensitive information and source code being leaked to the public is concerning.
This concern may have been a motivating factor in the decision to pay the ransom.
When asked about the payment, Tyler Technologies did not dispute that it paid the ransom, but told BleepingComputer that it could not disclose further information at this time.
