CSIDB logo
Incident

Tyler Technologies

Incident posture

Attack window
Sep 2020
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-10-28 00:00

Linked entities

Victim
Tyler Technologies
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Sep 2020
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Tyler Technologies, a major U.S. government software provider serving the public sector, experienced a ransomware attack attributed to the RansomExx group that disrupted its operational activities. The incident impacted the company's systems and services, though specific details regarding data compromise or recovery efforts were not disclosed in initial reports. As a leading technology services firm specializing in government solutions, the attack highlighted vulnerabilities in critical infrastructure providers supporting public sector entities.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On or around September 23, 2020, Tyler Technologies, a leading U.S. software development and technology services company specializing in government sector solutions, experienced a ransomware attack that disrupted its operational activities. The incident was attributed to the RansomExx ransomware group based on reporting by Lawrence Abrams of BleepingComputer. Tyler Technologies, recognized as one of the largest providers of technology services to the public sector, faced immediate operational interruptions, though the specific internal systems or client-facing platforms affected were not detailed in available reports. The attack’s timing coincided with Tyler’s prominence in providing critical software infrastructure to municipal, state, and federal government entities, though no evidence confirmed immediate downstream impacts on client systems during the initial disclosure period. The company did not publicly disclose the initial attack vector, data exfiltration scope, or ransom demands at the time of the report.

The incident drew attention due to Tyler Technologies’ extensive role in supporting government operations, including case management systems, payment processing, and public administration software. No verifiable information indicated whether client data or government systems were compromised as a direct result of the breach. The company’s public acknowledgment centered on internal disruptions, with no supplementary details provided regarding containment measures, forensic investigations, or recovery timelines. Industry observers noted the potential implications of a successful ransomware attack on a vendor with deep public-sector integration, though concrete evidence of lateral movement or secondary infections remained unconfirmed. Operational resilience procedures were not described in the available reporting, leaving the duration and severity of service interruptions unclear beyond the confirmed disruption occurring in late September 2020.

Sources

Sources available to members: 1 source.

CSIDB