LockBit claimed in April 2024 that it had published data stolen from Tyler Technologies, a public-sector software provider whose STAR system supports government customers. Tyler confirmed that a threat actor encrypted the STAR system and acquired data. Washington, D.C.’s Department of Insurance, Securities and Banking said information connected to the incident came through Tyler as a third-party provider.
The public record does not establish that every Tyler customer, every government agency, or a specific category of personal information was affected. LockBit’s leak-site claims remain allegations, not an independently verified inventory of stolen files.
What happened
Contemporaneous reporting identified a LockBit claim involving Tyler Technologies and data associated with a Washington, D.C., government agency. Tyler’s formal filing with the U.S. Securities and Exchange Commission said a threat actor encrypted the STAR system and acquired data. Tyler said it hired external forensic specialists and advisers and contacted law enforcement.
Tyler described the event as a cybersecurity incident affecting STAR system client data. The company concluded at that time that the incident was not material for SEC disclosure purposes and said it would reassess if new information emerged. That conclusion addresses investor disclosure; it does not establish that the incident had no privacy, regulatory, contractual, or operational consequences.
Free tools Windows power users keep installed
One-click scans. No signup required.
#1 Best Overall
Sources: SecurityWeek reporting and Tyler’s SEC filing.
Was a government network hacked?
The available evidence points to a third-party technology-provider compromise, not proof that the District of Columbia’s own network was penetrated.
- Tyler operated the affected STAR system and held or processed data for public-sector clients.
- The District’s Department of Insurance, Securities and Banking said the relevant information came from a third-party technology provider and identified Tyler as that provider.
- The sources do not establish that attackers entered every customer agency’s internal network or that all Tyler-hosted environments were affected.
This distinction matters: a supplier can expose government-related records even when an agency’s own endpoints and perimeter controls were not directly compromised. Recorded Future News reported the D.C. agency’s statement.
Rank #2
What data was exposed?
The safest description is that the material allegedly came from the STAR system and may have included personally identifiable or securities-related information. The reporting available for the April 2024 event did not establish the exact data categories, number of records, affected agencies, or number of individuals.
Do not treat screenshots or files posted by a criminal leak site as a complete or authenticated record of the breach. Criminal groups may exaggerate claims, combine material from different victims, or publish fabricated or unrelated files. Readers should not download or redistribute alleged stolen files, which can contain sensitive personal information or malware.
Tyler reportedly worked to determine which individuals’ personally identifiable information may have been acquired. Unless an official notification identifies specific categories, it is not accurate to claim that Social Security numbers, credentials, election data, or law-enforcement intelligence were exposed.
Rank #3
Timeline
| Date | What happened |
|---|---|
| February 20, 2024 | U.S., U.K., and international law-enforcement agencies announced a coordinated disruption of LockBit infrastructure. The FBI described the operation. |
| April 19, 2024 | Reporting connected a LockBit claim to Tyler data and a Washington, D.C., agency. |
| April 23, 2024 | SecurityWeek published coverage represented by the original headline. |
| April 24, 2024 | Tyler filed its SEC response concerning the STAR system incident. |
| May 7, 2024 | The Justice Department charged alleged LockBit administrator Dmitry Khoroshev and described the group’s leak-site operation. |
The incident should therefore be dated to 2024, not presented as a new 2026 breach.
Why LockBit could still publish data after its takedown
LockBit used a double-extortion model: attackers encrypted systems and separately threatened to publish data taken from victims. The February operation disrupted infrastructure, but it did not necessarily erase copies of data already stolen or prevent affiliates from using material later.
The Justice Department described LockBit’s public leak site as a service for publishing data from victims who did not pay. In its case against the alleged administrator, the department also alleged that LockBit retained copies of victim data even after some victims paid. A ransom payment therefore cannot be described as a guarantee that stolen information will be deleted.
Rank #4
Sources: Justice Department account of the disruption and the administrator charging announcement.
What remains unknown
- Whether Tyler paid, negotiated, or refused a ransom.
- The total volume and precise categories of data acquired.
- Which Tyler customers and individuals, if any, require notification.
- Whether every file displayed by LockBit was authentic and attributable to Tyler.
- Whether additional government or regulatory disclosures would follow.
None of these points can be resolved from the leak-site claim alone.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Why the incident matters to government technology supply chains
State and local agencies frequently rely on vendors to host, administer, transmit, or process sensitive information. Tyler’s 2024 annual report identifies public-sector clients, suppliers, and other third parties as cybersecurity risk considerations. A compromise at that layer can create downstream data exposure without a confirmed intrusion into an agency’s own network.
Best Value
Tyler describes its public-sector business and services in its media room, while its risk discussion appears in the 2024 annual report.
Questions agencies and contractors should ask a supplier
- Scope: Which systems, tenants, backups, and customer environments were affected?
- Data movement: Was information encrypted, exfiltrated, or both, and what forensic evidence supports that conclusion?
- Customers and people: Which agencies, regulated entities, employees, or residents may be implicated?
- Identity risk: Were credentials, encryption keys, tokens, or privileged accounts exposed, and have they been rotated?
- Containment: What systems were isolated, rebuilt, or placed under enhanced monitoring?
- Notification: Which legal, contractual, sector-specific, and public-record notification duties apply?
- Future resilience: Are backups isolated or immutable, restoration tests documented, and incident-response access guaranteed by contract?
The bottom line on the Tyler incident
This was best understood as a ransomware-related compromise of a government technology provider, with LockBit alleging that it leaked data taken from Tyler’s STAR system. Tyler confirmed encryption and data acquisition, and a D.C. agency confirmed that government-related information was involved through its third-party provider. The available evidence does not show a universal breach of government networks or establish the full scope of affected data and individuals.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




