How a software update from cyber firm CrowdStrike caused one of the world’s biggest IT blackouts (2024)

In this article

  • CRWD

George Kurtz, co-founder and CEO of CrowdStrike Inc., speaks during the Montgomery Summit in Santa Monica, California.

Patrick T. Fallon | Bloomberg | Getty Images

A fault with an update issued by cybersecurity company CrowdStrike led to a cascade effect among global IT systems Friday, with industries ranging from banking to airlines facing outages.

Banks and health-care providers saw their services disrupted and TV broadcasters went offline as businesses worldwide grappled with the ongoing outage. Air travel has been hit hard, too, with planes grounded and services delayed.

At the heart of the issue is Texas-based cybersecurity vendor CrowdStrike. On Friday, the cybersecurity firm experienced a major disruption following an issue with a software update.

So what happened, exactly? CNBC takes a look.

What is CrowdStrike and what does it do?

CrowdStrike is a cybersecurity vendor that develops software to help companies detect and block hacks. It is used by many of the world's Fortune 500 companies, including major global banks, health-care and energy companies.

How a software update from cyber firm CrowdStrike caused one of the world’s biggest IT blackouts (1)

watch now

VIDEO6:1106:11

Major technical outages worldwide: Here's what to know

Squawk Box

CrowdStrike is what's known as an "endpoint security" firm as it uses cloud technology to apply cyber protections to devices that are connected to the internet.

This differs from alternative approaches used by other cyber firms, which involve applying protection directly to back-end server systems.

"Many companies use [CrowdStrike software] and install it on all of their machines across their organization," Nick France, chief technology officer at IT security firm Sectigo, told CNBC's "Squawk Box Europe" on Friday.

"So when an update happens that maybe has problems with it, it causes this problem where the machines reboot, and people can't get back into their computers."

What happened on Friday?

On Friday, people around the world began encountering an error screen known as the "blue screen of death."

This issue — a common problem among PCs, for example if a machine overheats — was the result of an update from CrowdStrikeconcerning its Falcon product.

Falcon is a platform developed by the company that's designed to stop cyber breaches using cloud technology — it is at the heart of the firm's focus on endpoints. CrowdStrike said Friday it is in the process of rolling back the update globally.

CrowdStrike's software requires deep access to a computer's operating system to scan for threats. In the case of Friday's outage, machines running Microsoft's Windows operating system crashed due to a fault in the way a software update issued by CrowdStrike interacted with Windows.

"We have been made aware of an issue impacting Virtual Machines running Windows Client and Windows Server, running the CrowdStrike Falcon agent, which may encounter a bug check (BSOD [blue screen of death]) and get stuck in a restarting state. We approximate impact started around 19:00 UTC on the 18th of July," Microsoft said in an update at 5:40 a.m. ET.

"We can confirm the affected update has been pulled by CrowdStrike. Customers that are continuing to experience issues should reach out to CrowdStrike for additional assistance," the company added.

Satnam Narang, senior staff researcher at Tenable, told CNBC on Friday that the outage was "very unprecedented."

"The challenge here is that security software — because it's doing its job to protect organizations — it has to have more privileged access to these machines," he said.

So, while people may be seeing their IT issues as a problem with Windows, "it's not actually a Windows issue, it's related to a faulty or bad update from those security software," Narang added.

A fix has been issued

Earlier, Microsoft said its cloud services had been restored after an outage that affected its Azure services and Microsoft 365 suite of apps in the central U.S. region. A company spokesperson said these are two different and nonrelated issues — one issue relates to Azure, the other is linked to CrowdStrike.

How a software update from cyber firm CrowdStrike caused one of the world’s biggest IT blackouts (2)

watch now

VIDEO3:4703:47

Major global cyber outage hits airlines, banks and media outlets, impacting millions

Squawk Box Europe

They added that they "anticipate a resolution is forthcoming," in respect to the CrowdStrike problem.

CrowdStrike is "actively working with customers impacted by a defect found in a single content update for Windows hosts," CEO George Kurtz said Friday in a update on social media platform X. He added that Mac and Linux hosts are not affected.

"This is not a security incident or cyberattack. The issue has been identified, isolated and a fix has been deployed,"Kurtz said.

That fix could be hard to implement, though. Andy Grayland, chief information and security officer at threat intelligence firmSilobreaker, said that in order to implement a fix, engineers would have to go into each individual data center running windows.

They'd then have to log in, navigate to a certain CrowdStrike file, delete it and then reboot the entire system, he said.

"Where machines are encrypted, complex encryption keys also need to be entered manually. Unless Microsoft and CrowdStrike (if they are involved) pull something miraculous out of the bag, this could be painful to recover from."

Don’t miss these insights from CNBC PRO

  • The 60/40 portfolio excelled during the market storm — and Vanguard sees a strong decade ahead
  • Veteran investor Mark Mobius says this 'historically significant' factor could set back U.S. stocks
  • Jefferies names 3 chip stocks to buy after the sell-off, giving all over 50% upside
  • Novo Nordisk vs. Eli Lilly: Analysts weigh in as the obesity-drug battle heats up

How a software update from cyber firm CrowdStrike caused one of the world’s biggest IT blackouts (3)

Get a weekly round up of the top tech stories from around the world in your inbox every Friday.

Subscribe
How a software update from cyber firm CrowdStrike caused one of the world’s biggest IT blackouts (2024)

FAQs

How a software update from cyber firm CrowdStrike caused one of the world’s biggest IT blackouts? ›

CrowdStrike's Falcon product was the culprit, and Windows operating systems took the hit. CrowdStrike acknowledged fault, with CEO George Kurtz issuing a public apology. Kurtz stated that the update “had a software bug in it” that caused an issue with the Microsoft operating system.

Did the CrowdStrike update cause the outage? ›

What might be considered the largest IT outage in history was triggered by a botched software update from security vendor CrowdStrike, affecting millions of Windows systems around the world. Insurers estimate the outage will cost U.S. Fortune 500 companies $5.4 billion.

How did the CrowdStrike update get pushed out? ›

The outage was caused by a defect found in a Falcon content update for Windows hosts. Mac and Linux hosts are not impacted. This was not a cyberattack. We are working closely with impacted customers and partners to ensure that all systems are restored, so you can deliver the services your customers rely on.

What is the global issue with CrowdStrike? ›

But this was not a Microsoft issue. It was all to do with a U.S. cybersecurity firm called CrowdStrike which sent out a buggy software update that crashed Windows. Industries across the board were hit, with airlines cancelling flights, broadcasters not able to go to air and shops not being able to open.

What did CrowdStrike do wrong? ›

A software update from cybersecurity company CrowdStrike appears to have inadvertently disrupted IT systems globally. Two internet infrastructure disasters collided on Friday to produce disruptions around the world in airports, train systems, banks, health care organizations, hotels, television stations, and more.

What is the root cause of the CrowdStrike outage? ›

CrowdStrike has published its root cause analysis about the update crash that turned off millions of Microsoft Windows devices globally. The crash occurred because there was a mismatch between the 21 inputs passed to the CrowdStrike content validator and the 20 supplied to the content interpreter.

What caused the worldwide IT outage? ›

It wasn't a cyberattack, but was caused by one of the world's largest cybersecurity companies deploying a flawed update while trying to keep their customers safe from hackers.

How could CrowdStrike's update do so much damage? ›

The very purpose of the update involved a core cybersecurity mission of detecting emerging threats and, specifically, gathering data “on possible novel threat techniques.” Instead, an error in the software update triggered a problem that gave customers the Window's “Blue Screen of Death.”

Why did CrowdStrike drop so much? ›

Shares of CrowdStrike (CRWD) are still falling after a faulty update caused a global outage on Friday, sending the cybersecurity firm's shares plummeting, but some investors—including Cathie Wood's ARK Invest—are trying to buy the dip.

What was the root cause of the Microsoft outage? ›

A faulty software update from CrowdStrike caused widespread disruptions, impacting critical services globally. CEO George Kurtz explains the issue and provides a fix for customers.

What caused the failure of CrowdStrike? ›

On July 24, CrowdStrike reported on the testing process lapses that led to the flawed update being pushed out to customer systems. In its post-mortem, the company blamed a hole in its testing software that caused its Content Validator tool to miss a flaw in the defective Channel File 291 content update.

Who is CrowdStrike biggest competitor? ›

CrowdStrike Competitors for 2024: Top Alternatives Reviewed
  • Palo Alto Cortex XDR: Best for advanced security capabilities.
  • Trend Micro Vision One: Best for smaller teams with advanced needs.
  • Cybereason Defense Platform: Best for visualizing incidents and threats.
  • Bitdefender GravityZone: Best for small business budgets.
23 hours ago

Does the US government use CrowdStrike? ›

Crowdstrike is in wide use across federal agencies and it is a key vendor on the governmentwide Continuous Diagnostics and Mitigation cybersecurity support services contract.

What is the worldwide outage of CrowdStrike? ›

On July 19th, 2024, Windows 7 and above systems running CrowdStrike's Falcon sensor were served a faulty channel file that caused kernel instability and would result in a Blue Screen of Death (BSOD) loop and the largest global IT outage in history. The culprit is Channel File 291 (named with a pattern 'C-00000291-*.

What made the CrowdStrike crash? ›

The update that was sent to CrowdStrike software on Friday was malformed, which caused the software to crash every time it started and tried to parse the update. Now, usually, when an application like Google Chrome or Microsoft Word crashes, only that one application crashes.

Can CrowdStrike spy on me? ›

CrowdStrike Falcon analyzes connections to and from the internet to determine if there is malicious behavior. It may record the addresses of websites visited but will not log the contents of the pages transmitted.

Why CrowdStrike went down? ›

CrowdStrike Holdings (NASDAQ: CRWD) stock was battered badly last month, losing close to 40% of its value in July after it emerged that the cybersecurity specialist's defective software update caused a massive outage.

Has the CrowdStrike issue been fixed? ›

CrowdStrike boss says 97% of crashed systems fixed

A week after a faulty update caused a global IT outage that grounded flights and knocked TV stations off-air, the boss of CrowdStrike has revealed nearly all systems are back online.

What is the current status of CrowdStrike? ›

User reports indicate no current problems at CrowdStrike.

How did CrowdStrike outage happen on Reddit? ›

Microsoft confirms the analysis done by CrowdStrike last week. The crash was due to a read-out-of-bounds memory safety error in CrowdStrike's CSagent. sys driver.

References

Top Articles
Rapper, 22, killed in shooting that left another victim dead
Shazam 2's Grace Caroline Currey Is a One-of-a-Kind Superhero (Exclusive)
Woodward Avenue (M-1) - Automotive Heritage Trail - National Scenic Byway Foundation
Tryst Utah
Access-A-Ride – ACCESS NYC
Chatiw.ib
Plaza Nails Clifton
Toyota Campers For Sale Craigslist
Craigslist Parsippany Nj Rooms For Rent
Is Csl Plasma Open On 4Th Of July
Trade Chart Dave Richard
Yi Asian Chinese Union
David Packouz Girlfriend
WK Kellogg Co (KLG) Dividends
[PDF] INFORMATION BROCHURE - Free Download PDF
Cranberry sauce, canned, sweetened, 1 slice (1/2" thick, approx 8 slices per can) - Health Encyclopedia
Turbocharged Cars
Why Is Stemtox So Expensive
Facebook Marketplace Charlottesville
Mephisto Summoners War
Insidekp.kp.org Hrconnect
Chile Crunch Original
7 Fly Traps For Effective Pest Control
Overton Funeral Home Waterloo Iowa
Khiara Keating: Manchester City and England goalkeeper convinced WSL silverware is on the horizon
Craigslist Personals Jonesboro
Form F-1 - Registration statement for certain foreign private issuers
Uncovering The Mystery Behind Crazyjamjam Fanfix Leaked
Pain Out Maxx Kratom
Lacey Costco Gas Price
Black Panther 2 Showtimes Near Epic Theatres Of Palm Coast
Ascensionpress Com Login
Tinyzonehd
Craigslist Northern Minnesota
Rgb Bird Flop
Angel del Villar Net Worth | Wife
Myra's Floral Princeton Wv
Red Sox Starting Pitcher Tonight
Ff14 Laws Order
Fox And Friends Mega Morning Deals July 2022
Compress PDF - quick, online, free
Naya Padkar Newspaper Today
Dmitri Wartranslated
Los Garroberros Menu
Fifty Shades Of Gray 123Movies
Easy Pigs in a Blanket Recipe - Emmandi's Kitchen
Gotrax Scooter Error Code E2
Natasha Tosini Bikini
Chase Bank Zip Code
All Weapon Perks and Status Effects - Conan Exiles | Game...
Portal Pacjenta LUX MED
Random Warzone 2 Loadout Generator
Latest Posts
Article information

Author: Virgilio Hermann JD

Last Updated:

Views: 6504

Rating: 4 / 5 (61 voted)

Reviews: 84% of readers found this page helpful

Author information

Name: Virgilio Hermann JD

Birthday: 1997-12-21

Address: 6946 Schoen Cove, Sipesshire, MO 55944

Phone: +3763365785260

Job: Accounting Engineer

Hobby: Web surfing, Rafting, Dowsing, Stand-up comedy, Ghost hunting, Swimming, Amateur radio

Introduction: My name is Virgilio Hermann JD, I am a fine, gifted, beautiful, encouraging, kind, talented, zealous person who loves writing and wants to share my knowledge and understanding with you.