A fatal program update: How CrowdStrike crashed global computer systems (2024)

A botched update from one of the world’s preeminent software security companies wreaked more havoc on global business in one day than all but the very worst of hacking groups have ever managed to inflict.

Skip to end of carousel

The global IT outage

A fatal program update: How CrowdStrike crashed global computer systems (1)A fatal program update: How CrowdStrike crashed global computer systems (2)

Last week, a botched update by CrowdStrike melted down the world’s computer systems. The global IT outage caused chaos across many businesses, including health-care systems. Experts urge users to brace for lingering problems with computer systems for the next few days.

End of carousel

CrowdStrike built its name and a more than $70 billion market value by catching and publicly identifying malicious electronic campaigns by Russian and Chinese spies and organized criminal gangs that take in hundreds of millions of dollars.

But the company depends on deep access to millions of computers to defend them against new attacks, and instructions CrowdStrike sent to those machines running Microsoft’s Windows operating system overnight rendered them useless by Friday morning.

As banking, airline and 911 emergency call systems struggled to recover, CrowdStrike apologized and blamed an error rather than a hacking attack on its internal systems.

Advertisem*nt

“This was not a cyberattack,” CrowdStrike said on its blog. The Austin-based company said it identified the problem and provided a fix for customers to help their employees get working again.

Yet the failure was so extensive and its impact so profound that not all security experts were convinced it was merely human error. CrowdStrike has grown rapidly in the last year and just last month joined the S&P 500 index of top publicly traded companies. But it has made worldwide enemies by calling out hacking operations such as those by Russian intelligence that stole emails from the Democratic National Committee and Hillary Clinton’s campaign chair in 2016.

“I doubt this was accidental. Too many shortcomings,” said Matthew Hickey, founder of Hacker House training company. He said the offending file contained random data, had not been digitally signed and had not been adequately tested.

Advertisem*nt

A U.S. federal official speaking on the condition of anonymity to discuss national security matters said there was no evidence of sabotage or foreign involvement.

GET CAUGHT UP

Stories to keep you informed

$30 million gift will fund center to push for Supreme Court overhaulSparkleSummary is AI-generated, newsroom-reviewed.
Kamala Harris had an unusual donor to her earlier campaigns: Donald TrumpSparkleSummary is AI-generated, newsroom-reviewed.
Admiral’s romance with Pentagon official could be central in bribery caseSparkleSummary is AI-generated, newsroom-reviewed.
You can forage a delicious meal almost anywhere. Here’s how.SparkleSummary is AI-generated, newsroom-reviewed.
It’s not just you. Dating apps really have gotten worse.SparkleSummary is AI-generated, newsroom-reviewed.

Some analysts said they were waiting to hear more from CrowdStrike and that the complexity of state-of-the-art hacking defenses made them dangerously fragile.

Jake Williams, a onetime hacker for the National Security Agency, said “endpoint detection” products like CrowdStrike’s Falcon tool often send out not just updated identifiers for malicious programs to block but also lines of active code to foil more complicated attack scenarios. He said it was possible that CrowdStrike’s systems for testing code before installing it everywhere might not have been “sufficiently diverse” to catch the mistake.

While computer network outages aren’t unusual, experts were stunned Friday that one company’s error rippled through so many systems.

Advertisem*nt

“We haven’t seen a cascading failure like this — maybe ever,” said Chuck Herrin, an executive with the digital security firm F5 Inc.

The sheer extent of the tech crashes around the world Friday exposed the risks inherent in the sort of security software that many see as essential for businesses to ward off ransomware and other devastating hacks.

To be effective, such programs need to be able to see everything that is happening on a machine. But that access can make their failure catastrophic, as it was Friday, and the fix the company later provided was complex: Many organizations had to manually reboot each machine one at a time and delete the bad update file.

That privileged access also makes security programs a top target for spies and ordinary hackers. Just last month, U.S. officials banned Russian anti-virus software company Kaspersky Lab from new business in the country, after it was accused of playing a role in the theft of secrets from NSA employees and others.

Advertisem*nt

Friday’s problems canceled or delayed thousands of flights and forced hospitals to postpone operations. The worst cyberattacks, such as the Russian NotPetya assault on Ukrainian businesses and the North Korean WannaCry virus, have done more lasting damage by permanently damaging computers. But not even those spread so rapidly and so far.

The extent of the financial damage from the outages, as well as who will bear those costs, will not be known for some time. Most software providers are free from legal liability for the harm caused by their programs, which are licensed instead of being sold. But they typically have service agreements with their largest customers that could require help with remediation, discounts or other compensation.

The failure at CrowdStrike is striking in part because the company’s executives have been among the industry’s most prominent voices faulting Microsoft for repeated security lapses. The software giant was blamed for recent major intrusions at U.S. agencies, including the theft of email last year from officials including Commerce Secretary Gina Raimondo. A scathing April report by the Cyber Safety Review Board, which is led by an official at the Cybersecurity and Infrastructure Security Agency, cited “corporate culture that deprioritized both enterprise security investments and rigorous risk management.”

Advertisem*nt

Beyond those lapses at Microsoft, CrowdStrike has said that company’s dominant market position in operating systems and productivity software imparts any weakness with a potentially catastrophic impact.

As one of the few top security companies, some experts are now saying the same about CrowdStrike, one of a small set of network security companies with such broad reach and power.

“Obviously this is very serious, it’s going to be weeks. You have to get hands on keyboards,” said Bryan Palma, chief executive of rival security company Trellix. “This speaks to the need for redundancy and defense in depth.”

The Cybersecurity and Infrastructure Security Agency said it was helping with recovery efforts and warned that criminals pretending to be from CrowdStrike were trying to talk customers into downloading malicious programs or giving up access to their computers.

Advertisem*nt

Marie Vasek, an assistant professor at University College London’s computer science department, said the widespread computer meltdowns showed how reliant global technology systems are on a small number of companies’ software, including that of Microsoft and CrowdStrike.

“The issue here is that Microsoft is a standard bit of software that everybody uses, and the bug in CrowdStrike is deployed to every single system,” she said.

Vasek said technology networks have become so sprawling, complex and interrelated that it increases the odds of one botched line of software code bringing down entire computer networks.

This defect only affected computers that use Windows, which powers hundreds of millions of personal computers and many back-end systems for airlines, digital payment, emergency services, call centers and much more.

Advertisem*nt

In a statement, CrowdStrike said it is “working with all impacted customers to ensure that systems are back up and they can deliver the services their customers are counting on.”

Some companies affected by the CrowdStrike glitch, including banks and emergency service centers, said Friday that they had implemented CrowdStrike’s repaired software and were starting to recover.

Vasek said both Microsoft and CrowdStrike need to examine their procedures to prevent a repeat of such widespread technology failures.

She said CrowdStrike should consider how to safely update its software to many millions of computer networks. And Microsoft, she said, needed to do more to ensure that updates to software from other companies don’t cripple Windows machines.

“Microsoft needs to think about how to check that software is as it should be,” she said.

Advertisem*nt

Microsoft didn’t directly address that criticism but said in a statement that the company is “actively supporting customers to assist in their recovery.”

The company had also reported outages with some of its popular web-connected software for corporate and government technology networks.

It wasn’t immediately clear how many of Friday’s computer network collapses resulted from the defective CrowdStrike software update and which were the result of problems that started Thursday with Microsoft online services and its corporate cloud computing service, Azure.

A spokesman for Microsoft said the company didn’t believe the CrowdStrike software bug was related to the outage that impacted a “subset of Azure customers.” It has been resolved, he said.

correction

A previous version of this article incorrectly spelled Bryan Palma’s first name as Ryan. The article has been corrected.

A fatal program update: How CrowdStrike crashed global computer systems (2024)

FAQs

What caused the CrowdStrike error? ›

CrowdStrike, in a root cause analysis report, said the Falcon sensor expected 20 input fields in a rapid response content update, but the software update actually provided 21 input fields. The mismatch resulted in an out-of-bounds memory read, leading to the system crash.

How did CrowdStrike crash? ›

On 19 July 2024, American cybersecurity company CrowdStrike distributed a faulty update to its Falcon Sensor security software that caused widespread problems with Microsoft Windows computers running the software.

Is CrowdStrike owned by Microsoft? ›

People often wonder if CrowdStrike is owned by Microsoft. In reality CrowdStrike is not owned by Microsoft. CrowdStrike and Microsoft are two different entities. Microsoft, a tech giant with a diverse portfolio, including software, hardware, and cloud services, has also made significant strides in cybersecurity.

Why is CrowdStrike down so much? ›

On July 19, U.S. investors awoke to reports of what some experts were calling the largest IT outage ever. While investors were sleeping, CrowdStrike released a defective update to its software that caused Microsoft-based IT systems to go down.

How do I remove CrowdStrike from my computer? ›

Uninstall from Control Panel
  1. Open the Windows Control Panel.
  2. Click Uninstall a Program.
  3. Choose CrowdStrike Windows Sensor and uninstall it.

When did the CrowdStrike incident start? ›

The outage that started July 19 was caused by a malformed update that was sent to a piece of security software called “CrowdStrike Falcon.” While CrowdStrike may not be a household name, it is a major enterprise security company that builds what we call Endpoint Detection and Response (EDR) software.

What is CrowdStrike incident response? ›

The CrowdStrike Incident Response (IR) team brings control, stability and organization to what can be a confusing and chaotic situation. Given the current threat landscape, most organizations will likely encounter a cyber incident, at some point that they will have to respond to and manage effectively.

How does CrowdStrike stop breaches? ›

CrowdStrike's core technology, the Falcon platform, stops breaches by preventing and responding to all types of attacks — both malware and malware-free.

Who is CrowdStrike biggest competitor? ›

Top Competitors and Alternatives of Crowdstrike

The top three of Crowdstrike's competitors in the Endpoint Protection category are McAfee ePO with 21.36%, SentinelOne with 9.57%, Duo Security with 7.72% market share.

Does the US government use CrowdStrike? ›

Crowdstrike is in wide use across federal agencies and it is a key vendor on the governmentwide Continuous Diagnostics and Mitigation cybersecurity support services contract.

Who are the largest owners of CrowdStrike? ›

According to the latest TipRanks data, approximately 49.47% of CrowdStrike Holdings (CRWD) stock is held by retail investors. Vanguard owns the most shares of CrowdStrike Holdings (CRWD).

What happened with the CrowdStrike outage? ›

The root cause of the outage was a faulty sensor configuration update that specifically affected Windows systems. The channel file 291 update was never issued to macOS or Linux systems as the update deals with named pipe execution that only occurs on the Microsoft Windows OS.

Why is my CrowdStrike sensor not connected to the cloud? ›

If your host can't connect to the CrowdStrike Cloud, check these network configuration items: Verify that your host can connect to the internet. If your host uses a proxy, verify your proxy configuration. If your host uses an endpoint firewall, configure it to permit traffic to and from the Falcon sensor.

What is CrowdStrike vulnerability? ›

Vulnerability assessment is the ongoing, regular process of defining, identifying, classifying and reporting cyber vulnerabilities across endpoints, workloads, and systems.

References

Top Articles
Meet Carson Beck, Georgia Bulldogs’ star QB and Hanna Cavinder’s boyfriend
Goodman: Time to rethink everything we know about Alabama football
Funny Roblox Id Codes 2023
Golden Abyss - Chapter 5 - Lunar_Angel
Www.paystubportal.com/7-11 Login
Joi Databas
DPhil Research - List of thesis titles
Shs Games 1V1 Lol
Evil Dead Rise Showtimes Near Massena Movieplex
Steamy Afternoon With Handsome Fernando
fltimes.com | Finger Lakes Times
Detroit Lions 50 50
18443168434
Newgate Honda
Zürich Stadion Letzigrund detailed interactive seating plan with seat & row numbers | Sitzplan Saalplan with Sitzplatz & Reihen Nummerierung
Grace Caroline Deepfake
978-0137606801
Nwi Arrests Lake County
Justified Official Series Trailer
London Ups Store
Committees Of Correspondence | Encyclopedia.com
Pizza Hut In Dinuba
Jinx Chapter 24: Release Date, Spoilers & Where To Read - OtakuKart
How Much You Should Be Tipping For Beauty Services - American Beauty Institute
Free Online Games on CrazyGames | Play Now!
Sizewise Stat Login
VERHUURD: Barentszstraat 12 in 'S-Gravenhage 2518 XG: Woonhuis.
Jet Ski Rental Conneaut Lake Pa
Unforeseen Drama: The Tower of Terror’s Mysterious Closure at Walt Disney World
Ups Print Store Near Me
C&T Wok Menu - Morrisville, NC Restaurant
How Taraswrld Leaks Exposed the Dark Side of TikTok Fame
University Of Michigan Paging System
Dashboard Unt
Access a Shared Resource | Computing for Arts + Sciences
Speechwire Login
Healthy Kaiserpermanente Org Sign On
Restored Republic
Lincoln Financial Field, section 110, row 4, home of Philadelphia Eagles, Temple Owls, page 1
Jambus - Definition, Beispiele, Merkmale, Wirkung
Ark Unlock All Skins Command
Craigslist Red Wing Mn
D3 Boards
Jail View Sumter
Birmingham City Schools Clever Login
Thotsbook Com
Funkin' on the Heights
Caesars Rewards Loyalty Program Review [Previously Total Rewards]
Vci Classified Paducah
Www Pig11 Net
Ty Glass Sentenced
Latest Posts
Article information

Author: Maia Crooks Jr

Last Updated:

Views: 5991

Rating: 4.2 / 5 (63 voted)

Reviews: 94% of readers found this page helpful

Author information

Name: Maia Crooks Jr

Birthday: 1997-09-21

Address: 93119 Joseph Street, Peggyfurt, NC 11582

Phone: +2983088926881

Job: Principal Design Liaison

Hobby: Web surfing, Skiing, role-playing games, Sketching, Polo, Sewing, Genealogy

Introduction: My name is Maia Crooks Jr, I am a homely, joyous, shiny, successful, hilarious, thoughtful, joyous person who loves writing and wants to share my knowledge and understanding with you.