What we know about CrowdStrike's update fail that's causing global outages and travel chaos | TechCrunch (2024)

A faulty software update issued by security giant CrowdStrike has resulted in a massive overnight outage that’s affected Windows computers around the world, disrupting businesses, airports, train stations, banks, broadcasters and the healthcare sector.

CrowdStrike said the outage was not caused by a cyberattack, but was the result of a “defect” in a software update for its flagship security product, Falcon Sensor. The defect caused any Windows computers that Falcon is installed on to crash without fully loading.

“The issue has been identified, isolated and a fix has been deployed,” said CrowdStrike in a statement on Friday. Some businesses and organizations are beginning to recover, but many expect the outages to drag on into the weekend or next week given the complexity of the fix. CrowdStrike CEO George Kurtz told NBC News that it may take “some time for some systems that just automatically won’t recover.” In a later tweet, Kurtz apologized for the disruption.

Here’s everything you need to know about the outages.

What happened?

Late Thursday into Friday, reports began to emerge of IT problems wherein Windows computers were getting stuck with the infamous “blue screen of death” — a bright blue error screen with a message that displays when Windows encounters a critical failure, crashes or cannot load.

The outages were first noticed in Australia early on Friday, and reports quickly came in from the rest of Asia and Europe as the regions began their day, as well as the United States.

Within a short time, CrowdStrike confirmed that a software update for Falcon had malfunctioned and was causing Windows computers that had the software installed to crash. Falcon lets CrowdStrike remotely analyze and check for malicious threats and malware on installed computers.

At around the same time, Microsoft reported a significant outage at one of its most used Azure cloud regions covering much of the central United States. A spokesperson for Microsoft told TechCrunch that its outage was unrelated to CrowdStrike’s incident.

Around Friday noon (Eastern time), Microsoft CEO Satya Nadella posted on X saying the company is aware of the CrowdStrike botched update and is “working closely with CrowdStrike and across the industry to provide customers technical guidance and support to safely bring their systems back online.”

What is CrowdStrike and what does Falcon Sensor do?

CrowdStrike, founded in 2011, has quickly grown into a cybersecurity giant. Today the company provides software and services to 29,000 corporate customers, including around half of Fortune 500 companies, 43 out of 50 U.S. states and eight out of the top 10 tech firms, according to its website.

The company’s cybersecurity software, Falcon, is used by enterprises to manage security on millions of computers around the world. These businesses include large corporations, hospitals, transportation hubs and government departments. Most consumer devices do not run Falcon and are unaffected by this outage.

One of the company’s biggest recent claims to fame was when it caught a group of Russian government hackers breaking into the Democratic National Committee ahead of the 2016 U.S. presidential election. CrowdStrike is also known for using memorable animal-themed names for the hacking groups it tracks based on their nationality, such as: Fancy Bear, believed to be part of Russia’s General Staff Main Intelligence Directorate, or GRU; Cozy Bear, believed to be part of Russia’s Foreign Intelligence Service, or SVR; Gothic Panda, believed to be a Chinese government group; and Charming Kitten, believed to be an Iranian state-backed group. The company even makes action figures to represent these groups, which it sells as swag.

CrowdStrike is so big it’s one of the sponsors of the Mercedes F1 team, and this year even aired a Super Bowl ad — a first for a cybersecurity company.

Who are the outages affecting?

Practically anyone who during their everyday life interacts with a computer system running software from CrowdStrike is affected, even if the computer isn’t theirs.

These devices include the cash registers at grocery stores, departure boards at airports and train stations, school computers, your work-issued laptops and desktops, airport check-in systems, airlines’ own ticketing and scheduling platforms, healthcare networks and many more. Because CrowdStrike’s software is so ubiquitous, the outages are causing chaos around the world in a variety of ways. A single affected Windows computer in a fleet of systems could be enough to disrupt the network.

TechCrunch reporters around the world are seeing and experiencing outages, including at points of travel, doctors’ offices and online. Early on Friday, the Federal Aviation Administration put in effect a ground stop, effectively grounding flights across the United States, citing the disruption. It looks like so far the national Amtrak rail network is functioning as normal.

What is the U.S. government doing so far?

Given that the problem stems from a company, there isn’t much that the U.S. federal government can do. According to a pool report, President Biden was briefed on the CrowdStrike outage, and “his team is in touch with CrowdStrike and impacted entities.” That’s in large part because the federal government is a customer of CrowdStrike and also affected.

Several federal agencies are affected by the incident, including the Department of Education, and Social Security Administration, which said Friday that it closed its offices as a result of the outage.

The pool report said Biden’s team is “engaged across the interagency to get sector by sector updates throughout the day and is standing by to provide assistance as needed.”

In a separate tweet, Homeland Security said it was working with its U.S. cybersecurity agency CISA, CrowdStrike and Microsoft — as well as its federal, state, local and critical infrastructure partners — to “fully assess and address system outages.”

There will no doubt be questions for CrowdStrike (and to some extent Microsoft, whose unrelated outage also caused disruption overnight for its customers) from government and congressional investigators.

For now, the immediate focus will be on the recovery of affected systems.

How do affected customers fix their Windows computers?

The major problem here is that CrowdStrike’s Falcon Sensor software malfunctioned, causing Windows machines to crash, and there’s no easy way to fix that.

So far, CrowdStrike has issued a patch, and it has also detailed a workaround that could help affected systems function normally until it has a permanent solution. One option is for users to “reboot the [affected computer] to give it an opportunity to download the reverted channel file,” referring to the fixed file.

In a message to users, CrowdStrike detailed a few steps customers can take, one of which requires physical access to an affected system to remove the defective file. CrowdStrike says users should boot the computer into Safe Mode or Windows Recovery Environment, navigate to the CrowdStrike directory, and delete the faulty file “C-00000291*.sys.”

The wider problem with having to fix the file manually could be a major headache for companies and organizations with large numbers of computers, or Windows-powered servers in datacenters or locations that might be in another region, or an entirely different country.

CISA warns that malicious actors are ‘taking advantage’ of the outage

In a statement on Friday, CISA attributed the outages to the faulty CrowdStrike update and that the issue was not due to a cyberattack. CISA said that it was “working closely with CrowdStrike and federal, state, local, tribal and territorial partners, as well as critical infrastructure and international partners to assess impacts and support remediation efforts.”

CISA did note, however, that it has “observed threat actors taking advantage of this incident for phishing and other malicious activity.” The cybersecurity agency did not provide more specifics, but warned organizations to stay vigilant.

Malicious actors can and will exploit confusion and chaos to carry out cyberattacks on their own. Rachel Tobac, a social engineering expert and founder of cybersecurity firm SocialProof Security, said in a series of posts on X to “verify people are who they say they are before taking sensitive actions.”

“Criminals will attempt to use this IT outage to pretend to be IT to you or you to IT to steal access, passwords, codes, etc.,” Tobac said.

What do we know about misinformation so far?

It’s easy to understand why some might have thought that this outage was a cyberattack. Sudden outages, blue screens at airports, office computers filled with error messages, and chaos and confusion. As you might expect, a fair amount of misinformation is already flying around, even as social media sites incorrectly flag trending topics like “cyberattack.”

Remember to check official sources of news and information, and if something seems too good to be true, it might just well be.

TechCrunch will keep this report updated throughout the day.

TechCrunch’s Ram Iyer contributed reporting.

What we know about CrowdStrike's update fail that's causing global outages and travel chaos | TechCrunch (2024)

FAQs

What we know about CrowdStrike's update fail that's causing global outages and travel chaos | TechCrunch? ›

CrowdStrike said the outage was not caused by a cyberattack, but was the result of a “defect” in a software update for its flagship security product, Falcon Sensor. The defect caused any Windows computers that Falcon is installed on to crash without fully loading.

How did CrowdStrike cause outage? ›

There was a logic flaw in Falcon sensor version 7.11 and above, causing it to crash. Due to CrowdStrike Falcon's tight integration into the Microsoft Windows kernel, it resulted in a Windows system crash and BSOD. The flaw in CrowdStrike Falcon was inside of a sensor configuration update.

What caused global outage? ›

Last week's global tech outage has been traced back to a bug in U.S. cybersecurity firm CrowdStrike's quality control system. The outage's impacts have been far-reaching, affecting roughly 8.5 million Windows devices and disrupting banks, emergency call centers and airlines.

When was the CrowdStrike issue? ›

The world just experienced a widespread technical outage linked to a company called CrowdStrike. What exactly happened on Friday, July 19, 2024? Cybersecurity firm CrowdStrike pushed out a routine software update that inadvertently crashed customers' Windows systems.

What computers were affected by CrowdStrike? ›

The problem affected systems running Windows 10 and Windows 11 running the CrowdStrike Falcon software. Most personal Windows PCs were unaffected, as CrowdStrike's software is primarily used by organizations. The CrowdStrike software did not provide a way for subscribers to delay the installation of its content files.

What did the CrowdStrike update do? ›

SAN FRANCISCO, July 19 (Reuters) - Security experts said CrowdStrike's (CRWD.O) , opens new tab routine update of its widely used cybersecurity software, which caused clients' computer systems to crash globally on Friday, apparently did not undergo adequate quality checks before it was deployed.

Why is CrowdStrike falling? ›

Shares of CrowdStrike (CRWD) are still falling after a faulty update caused a global outage on Friday, sending the cybersecurity firm's shares plummeting, but some investors—including Cathie Wood's ARK Invest—are trying to buy the dip.

Is United affected by CrowdStrike? ›

The CrowdStrike bug hit United's systems hard, leading the airline to cancel 694 flights Friday. IT outages grounded an additional 713 United planes during the weekend, which Kirby characterized as one of the busiest travel times of the year.

How much did the CrowdStrike outage cost? ›

The massive CrowdStrike outage that affected millions of Microsoft devices is predicted to cost U.S. Fortune 500 companies $5.4 billion in total direct financial loss, with an average loss of $44 million per Fortune 500 company, according to new data from cloud monitoring and insurance firm Parametrix.

Which airlines were not affected by CrowdStrike? ›

Some airlines, including Southwest and Alaska, do not use CrowdStrike, the provider of cybersecurity software whose faulty upgrade to Microsoft Windows triggered the outages. Those carriers saw relatively few cancellations.

Does the US government use CrowdStrike? ›

The extent of the impact on federal government operations is still not known. Crowdstrike is in wide use across federal agencies and it is a key vendor on the governmentwide Continuous Diagnostics and Mitigation cybersecurity support services contract.

How do I know if CrowdStrike is updated? ›

Once CrowdStrike is installed, it actively scans for threats on your machine without having to manually run virus scans. Updates for CrowdStrike should also come through automatically, so there is no need to update manually.

What is the future outlook for CrowdStrike? ›

Based on 36 Wall Street analysts offering 12 month price targets for CrowdStrike Holdings in the last 3 months. The average price target is $368.26 with a high forecast of $450.00 and a low forecast of $275.00. The average price target represents a 44.59% change from the last price of $254.69.

Did CrowdStrike cause Microsoft outage? ›

Was the Microsoft outage caused by CrowdStrike? Yes, the global outage experienced by Microsoft on Thursday was triggered by an issue with CrowdStrike's Falcon Sensor software. This problem led to widespread disruptions and caused the 'Blue Screen of Death' to appear on Windows PCs.

What caused Global IT outage? ›

What caused the outage. The disruption was caused by a flawed update to a cloud-based security software of CrowdStrike, one of the global top cybersecurity companies. The update to the Falcon software triggered a malfunction that disabled parts of the computer systems and software like Microsoft Windows.

What big companies use CrowdStrike? ›

Customers of Crowdstrike
CustomersEmployee RangeCountry
Amazon Web Services10,000+United States
Home Depot, Inc.10,000+United States
OSI Group LLC10,000+United States
iQor10,000+United States
6 more rows

How do I remove CrowdStrike from my computer? ›

Uninstall from Control Panel
  1. Open the Windows Control Panel.
  2. Click Uninstall a Program.
  3. Choose CrowdStrike Windows Sensor and uninstall it.

Does Microsoft use CrowdStrike internally? ›

The problem originated with an Austin, Texas-based cybersecurity firm called CrowdStrike, relied upon by much of the global technology industry, including Microsoft, for its Falcon program, which blocks the execution of malware and cyber-attacks.

When did Microsoft's outage start? ›

The global IT outage on 19 July serves as a stark reminder of our vulnerability to technological failures.

Top Articles
Steamboat Natchez Sunday Jazz Brunch Cruise In New Orleans
The Impact of Remote Work on Physical Health in Off-Off-Broadway at Lighthouse Repertory Theatre Company 2024
AMC Theatre - Rent A Private Theatre (Up to 20 Guests) From $99+ (Select Theaters)
It’s Time to Answer Your Questions About Super Bowl LVII (Published 2023)
Jefferey Dahmer Autopsy Photos
Air Canada bullish about its prospects as recovery gains steam
Shorthand: The Write Way to Speed Up Communication
DENVER Überwachungskamera IOC-221, IP, WLAN, außen | 580950
Best Private Elementary Schools In Virginia
Athens Bucket List: 20 Best Things to Do in Athens, Greece
The fabulous trio of the Miller sisters
Gma Deals And Steals Today 2022
Ts Lillydoll
Michael Shaara Books In Order - Books In Order
Aldi Süd Prospekt ᐅ Aktuelle Angebote online blättern
The Ultimate Style Guide To Casual Dress Code For Women
Northeastern Nupath
E22 Ultipro Desktop Version
ZURU - XSHOT - Insanity Mad Mega Barrel - Speelgoedblaster - Met 72 pijltjes | bol
97226 Zip Code
Metro Pcs.near Me
Puss In Boots: The Last Wish Showtimes Near Cinépolis Vista
Euro Style Scrub Caps
Wisconsin Volleyball Team Boobs Uncensored
Living Shard Calamity
European Wax Center Toms River Reviews
My Reading Manga Gay
Askhistorians Book List
Nikki Catsouras: The Tragic Story Behind The Face And Body Images
Pay Stub Portal
Account Now Login In
'Conan Exiles' 3.0 Guide: How To Unlock Spells And Sorcery
Kristen Hanby Sister Name
Workboy Kennel
Log in or sign up to view
Naya Padkar Newspaper Today
Watchseries To New Domain
ATM Near Me | Find The Nearest ATM Location | ATM Locator NL
Craigslist Summersville West Virginia
Troy Gamefarm Prices
Wisconsin Women's Volleyball Team Leaked Pictures
Zasilacz Dell G3 15 3579
Felix Mallard Lpsg
Pay Entergy Bill
877-292-0545
Seven Rotten Tomatoes
Todd Gutner Salary
Ratchet And Clank Tools Of Destruction Rpcs3 Freeze
Walmart Listings Near Me
Diamond Desires Nyc
Cognitive Function Test Potomac Falls
Olay Holiday Gift Rebate.com
Latest Posts
Article information

Author: The Hon. Margery Christiansen

Last Updated:

Views: 6576

Rating: 5 / 5 (50 voted)

Reviews: 89% of readers found this page helpful

Author information

Name: The Hon. Margery Christiansen

Birthday: 2000-07-07

Address: 5050 Breitenberg Knoll, New Robert, MI 45409

Phone: +2556892639372

Job: Investor Mining Engineer

Hobby: Sketching, Cosplaying, Glassblowing, Genealogy, Crocheting, Archery, Skateboarding

Introduction: My name is The Hon. Margery Christiansen, I am a bright, adorable, precious, inexpensive, gorgeous, comfortable, happy person who loves writing and wants to share my knowledge and understanding with you.