CrowdStrike's Role In the Microsoft IT Outage, Explained (2024)

The major Microsoft IT outage on Friday that grounded flights, sent TV stations off air, and disrupted online hospital systems has been linked to a third party—a cybersecurity technology firm named CrowdStrike.

CrowdStrike’s CEO George Kurtz has spoken out about the outage, apologizing for the disruption caused.

As the fallout from the event continues to impact people worldwide, here’s a breakdown of how exactly CrowdStrike is involved and what transpired.

Read More: How to Protect Yourself From Scams Following the CrowdStrike Microsoft IT Outage

What caused the Microsoft outage?

Early Friday, companies in Australia running Microsoft’s Windows operating system started reporting devices showing, what is commonly referred to as, “blue screens of death.” According to Microsoft’s website, this happens “if a serious problem causes Windows to shut down or restart unexpectedly.”

These disruptions then spread rapidly, impacting companies and communities around the world. The U.K., India, Germany, the Netherlands, and the U.S., reported disruptions. Meanwhile, United, Delta, and American Airlines issued a “global ground stop” on all flights.

The cause of this outage came from a faulty update from CrowdStrike, deployed to computers running Microsoft Windows. The issue was specifically linked to Falcon, one of the companies main products, which does not impact Mac or Linux operating systems.

Launched in 2012 CrowdStrike’s cybersecurity software is now used by 298 of Fortune 500 companies, including banks, energy companies, healthcare companies, and food companies.

According to David Brumley, professor of electrical and computer engineering at Carnegie Mellon University, this was a perfect storm of issues. “Their code is buggy, and it was sitting there as a ticking time bomb,” Brumley says.

He says there are three steps cybersecurity teams should typically implement when rolling out an update. First, there should have been rigorous software testing to catch bugs; second, there should have been testing on different types of machines; and third, the roll out should have been slow with smaller sets of users to screen for negative ramifications.

“Companies like Google will roll out updates incrementally so if the update is bad, at least it will have limited damage,” says Brumley, adding that the issue may only get more pronounced.

“What we’re seeing and what we’ll continue to see is a huge consolidation in the cybersecurity department, and that’s why we're seeing so many people affected at once,” says Brumley. “We need to be asking, ‘What choices can we give people if companies mess up?’”

How has CrowdStrike responded to the outage felt worldwide?

Appearing via a video link on The Today Show on Friday, CrowdStrike’s CEO delivered an apology to the public:

“We're deeply sorry for the impact that we've caused to customers, to travelers, to anyone affected by this, including our companies,” Kurtz said. “That update had a software bug in it and caused an issue with the Microsoft operating system...we identified this very quickly and remediated the issue.”

Kurtz was clear that this was not a cybersecurity issue nor an attack of any kind, but an issue coming from inside the company.

Though they’ve deployed the changes necessary to help remedy the issue, customers are still having issues, and it may be some time before systems across the globe are all fully operational.

In a statement emailed to TIME, CrowdStrike said that they are “actively working with customers impacted by a defect found in a single content update for Windows hosts.”

They also clarified, once more, for those concerned that the issue is not a security incident, and that the problem has been “identified, isolated, and a fix has been deployed.”

Kurtz has also shared this information on his personal X (formerly Twitter) account.

CrowdStrike is actively working with customers impacted by a defect found in a single content update for Windows hosts. Mac and Linux hosts are not impacted. This is not a security incident or cyberattack. The issue has been identified, isolated and a fix has been deployed. We…

— George Kurtz (@George_Kurtz) July 19, 2024

According to Forbes, Kurtz’s net worth had dropped $300 million as of Friday afternoon—from $3.2 billion to $2.9 billion–amid fallout from the IT outage.The CEO’s wealth is enmeshed with CrowdStrike shares, which dropped drastically following the incident.

On The Today Show segment, Kurtz said that CrowdStrike has been on the phone with customers all night, and that the issue was resolved for many when they rebooted their systems.However, he says the company will not “relent until we get every customer back to where they were and keep the bad guys out of their systems.”

If hosts are still crashing and unable to stay online to download CrowdStrike’s fix, the company has provided a workaround to the issue on its blog.

How has Microsoft responded to the IT outage?

On Thursday night, Microsoft 365 posted on X that the company was “working on rerouting the impacted traffic to alternate systems to alleviate impact” and that they were “observing a positive trend in service availability.”

As the disruption continued on Saturday, David Weston, Vice President of Enterprise and OS Security at Microsoft, published a blog post titled, “Helping our customers through the CrowdStrike outage.”

In the blog post, Weston said that Microsoft estimates “CrowdStrike’s update affected 8.5 million Windows devices, or less than one percent of all Windows machines.” Still, he goes on to say that the outage “demonstrates the interconnected nature of our broad ecosystem—global cloud providers, software platforms, security vendors and other software vendors, and customers.”

Weston also stated that Microsoft is “working around the clock” to help customers. He referenced the steps they are taking with CrowdStrike to mediate the effects of the outage, the company’s own post demonstrating manual fixes of the issue. Customers can also track the status of the incident through the “Azure Status Dashboard.”

TIME has reached out to Microsoft 365 for further comment.

CrowdStrike's Role In the Microsoft IT Outage, Explained (2024)

FAQs

CrowdStrike's Role In the Microsoft IT Outage, Explained? ›

As CrowdStrike immediately explained to customers and the world, the problem was not a cyberattack but an error in the software update. Because the bug was in CrowdStrike's Falcon platform update for Microsoft Windows, computers using other operating systems (e.g. Mac and Linux) were not impacted.

What caused the CrowdStrike outage? ›

The CrowdStrike outage was caused by a coding update that went wrong. This incident highlights the dangers of poor IT and cyber security practices. Businesses are becoming focused on pushing out updates faster, particularly to address dynamic cyber threats, and reducing IT costs.

What is the CrowdStrike issue? ›

The company says the problem occurred when it deployed a faulty update to computers running Microsoft Windows, noting that the issue behind the outage was not a security incident or cyberattack. CrowdStrike has said a fix is on the way. Still, chaos deepened hours after the problem was first detected.

How many computers were affected by CrowdStrike? ›

Microsoft Says 8.5 Million PCs Were Hit by the CrowdStrike Bug--and Fallout Still Ripples.

Does Microsoft use CrowdStrike internally? ›

The problem originated with an Austin, Texas-based cybersecurity firm called CrowdStrike, relied upon by much of the global technology industry, including Microsoft, for its Falcon program, which blocks the execution of malware and cyber-attacks.

Why is CrowdStrike down so much? ›

The chaos was triggered by a defect in a single content update for Microsoft Corporation's MSFT Windows hosts within CrowdStrike's Falcon platform. The update caused system malfunctions for about 8.5 million or less than 1% of the total Windows devices, leading to severe disruptions for clients globally.

What is CrowdStrike incident response? ›

CrowdStrike® Incident Response Services delivers immediate threat visibility and active threat containment to eject adversaries from your network and recover your systems with speed and precision.

Does CrowdStrike monitor browsing history? ›

The data security tools being used to protect your system, including CrowdStrike, are not designed to open and read your files or to track and report details of your online activity unless they specifically pose a threat to your system.

What big companies use CrowdStrike? ›

Customers of Crowdstrike
CustomersEmployee RangeCountry
Amazon Web Services10,000+United States
Home Depot, Inc.10,000+United States
OSI Group LLC10,000+United States
iQor10,000+United States
6 more rows

How do I remove CrowdStrike from my computer? ›

Uninstall from Control Panel
  1. Open the Windows Control Panel.
  2. Click Uninstall a Program.
  3. Choose CrowdStrike Windows Sensor and uninstall it.

Does the US government use CrowdStrike? ›

The extent of the impact on federal government operations is still not known. Crowdstrike is in wide use across federal agencies and it is a key vendor on the governmentwide Continuous Diagnostics and Mitigation cybersecurity support services contract.

Who owns CrowdStrike? ›

The ownership structure of CrowdStrike Holdings (CRWD) stock is a mix of institutional, retail and individual investors. Approximately 45.00% of the company's stock is owned by Institutional Investors, 2.19% is owned by Insiders and 52.80% is owned by Public Companies and Individual Investors.

What caused Global IT outage? ›

What caused the outage. The disruption was caused by a flawed update to a cloud-based security software of CrowdStrike, one of the global top cybersecurity companies. The update to the Falcon software triggered a malfunction that disabled parts of the computer systems and software like Microsoft Windows.

What is the prediction for CrowdStrike? ›

Average Price Target

Based on 36 Wall Street analysts offering 12 month price targets for CrowdStrike Holdings in the last 3 months. The average price target is $368.26 with a high forecast of $450.00 and a low forecast of $275.00. The average price target represents a 43.76% change from the last price of $256.16.

Is CrowdStrike a virus? ›

CrowdStrike is a web/cloud based anti-virus which uses very little storage space on your machine. CrowdStrike installs a lightweight sensor on your machine that is less than 5MB and is completely invisible to the end user.

How does CrowdStrike stop breaches? ›

CrowdStrike's core technology, the Falcon platform, stops breaches by preventing and responding to all types of attacks — both malware and malware-free.

Does the government use CrowdStrike? ›

The extent of the impact on federal government operations is still not known. Crowdstrike is in wide use across federal agencies and it is a key vendor on the governmentwide Continuous Diagnostics and Mitigation cybersecurity support services contract.

References

Top Articles
These White Elephant Gift Ideas Will Be a Hit
50 White Elephant Gift Ideas for Present-Stealing Fun
Epguides Succession
Culver's Flavor Of The Day Ann Arbor
Is Jennifer Coffindaffer Married
Provider Connect Milwaukee
404-459-1280
Www.myschedule.kp.org
Dayton Overdrive
Mashle: Magic And Muscles Gogoanime
50 budget recipes to feed a large crowd
Red Wing Boots Dartmouth Ma
Subject Guides: Business: Exchange Rates: Historical Foreign Exchange Rate
Nook Glowlight 3 Case
Bank Of America Operating Hours Today
Peanut Oil Can Be Part Of A Healthy Diet — But Only If It's Used This Way
8 Internet Celebrities who fell prey to Leaked Video Scandals
Great Clips Coupons → 20% Off | Sep 2024
How To Get Father, Son or Grandmother Tokens in Warframe?
Mobile Maher Terminal
Craigslist Cars For Sale By Owner Oklahoma City
Sunday Td Bank
8 of the best things to do in San Diego: get a taste of nature near a laid-back city
Eztv Ig
Best Amsterdam Neighborhoods for Expats: Top 9 Picks
Troy Bilt Belt Diagram
Walmart Com Careers Jobs
Norte Asesores Nanda
Elanco Rebates.com 2022
Selfservice Bright Lending
Funny Shooter Unblocked
Geritol Complete - Gebrauchsanweisung, Dosierung, Zusammensetzung, Analoga, Nebenwirkungen / Pillintrip
Ny Trapping Forum
Quarante ans après avoir arrêté, puis changé le temps
Craigs List Waco
Best Hs Bball Players
Phun.celeb
Stephen King's The Boogeyman Movie: Release Date, Trailer And Other Things We Know About The Upcoming Adaptation
No title - PDF Free Download
Robin Herd: 1939-2019
Hood County Buy Sell And Trade
8 Common Things That are 7 Centimeters Long | Measuringly
Prodigy Login For Students
11526 Lake Ave Cleveland Oh 44102
Epaper Dunya
102Km To Mph
What Does Wmt Contactless Mean
Ds Cuts Saugus
Caldo Tlalpeño de Pollo: Sabor Mexicano - Paulina Cocina
Fantasy Football News, Stats and Analysis
Craigslist Boats Rochester
Lenscrafters Westchester Mall
Latest Posts
Article information

Author: Neely Ledner

Last Updated:

Views: 5552

Rating: 4.1 / 5 (42 voted)

Reviews: 89% of readers found this page helpful

Author information

Name: Neely Ledner

Birthday: 1998-06-09

Address: 443 Barrows Terrace, New Jodyberg, CO 57462-5329

Phone: +2433516856029

Job: Central Legal Facilitator

Hobby: Backpacking, Jogging, Magic, Driving, Macrame, Embroidery, Foraging

Introduction: My name is Neely Ledner, I am a bright, determined, beautiful, adventurous, adventurous, spotless, calm person who loves writing and wants to share my knowledge and understanding with you.