T1#outage#security#regulation

The CrowdStrike Falcon Outage — The Largest IT Outage in History

Blue screens on baggage carousels at LaGuardia Airport
SourceSmishra1 (Wikimedia Commons) · CC BY-SA 4.0 · View on Commons

Metadata

Date
Decade
2020s
Tier
T1
Sources
14
Connections
02
Tags
#outage#security#regulation

On 19 July 2024, a faulty content update (Channel File 291) distributed by the cybersecurity firm CrowdStrike for its Falcon Sensor sent Windows machines worldwide into the blue screen of death (BSOD) at roughly the same instant. On 20 July Microsoft estimated the damage at 8.5 million Windows devices, "or less than one percent of all Windows machines." It is widely called the largest single IT outage on record; no authoritative global damage total exists.

One Input Field Too Many

At 04:09 UTC, CrowdStrike pushed Channel File 291 — a content-configuration file for the Falcon Sensor, not an update to the kernel driver itself. These Rapid Response Content files rewrite threat-detection logic daily, and customers had no control over which version they received. CrowdStrike reverted the push at 05:27 UTC, but machines that took delivery in those 78 minutes went down.

CrowdStrike's external Root Cause Analysis, published 6 August 2024, explains the mechanism. The IPC Template Type that interprets Channel File 291 was defined as taking 21 input fields, but at runtime only generates 20. Earlier content had always used a wildcard for the 21st field, so nothing noticed. The 19 July update introduced a non-wildcard matching criterion on the 21st input for the first time, and the Content Interpreter reached for a value that did not exist — an out-of-bounds read. CrowdStrike states explicitly that this was not an arbitrary memory write.

The Falcon Sensor's core is a driver (CSAgent.sys) running in Windows kernel space; an unhandled exception there halts the operating system. Affected machines BSOD'd in waves, and on reboot loaded the same bad file and crashed again — locked into a bootloop.

Recovery was conceptually simple but manual: boot into Safe Mode, delete the offending file, reboot normally. On BitLocker-encrypted drives the recovery key was required, and large enterprises had to perform the procedure across thousands or tens of thousands of machines in parallel.

Airlines, Hospitals, Banks, 911 Lines

By the hour after 06:00 UTC, mission-critical systems began going dark around the world simultaneously.

  • Aviation: Delta, United, and American halted operations. Delta alone cancelled around 7,000 flights over five days, affecting some 1.3 million passengers.
  • Healthcare: Hospitals in the US and UK lost electronic records, appointments, and diagnostic systems; some surgeries were postponed.
  • Finance: ATMs, branch terminals, and parts of securities-trading workstations went down.
  • Emergency services: 911 systems in several US states became intermittently unreachable.
  • Retail: POS, inventory management, online payments.
  • Broadcast: Sky News, ABC (Australia), and other broadcasters went off-air.

Full recovery took days to weeks depending on the organisation, particularly painful for remote-work fleets and store terminals requiring physical access.

Whose Damage Numbers Are These?

Round global totals — "$10 billion", "tens of billions" — circulate without a primary source behind them. Two named estimates can actually be checked.

  • The insurtech firm Parametrix put direct losses to Fortune 500 companies, excluding Microsoft, at US$5.4 billion, of which it expected only 10–20% (US$540 million to US$1.08 billion) to be recoverable through cyber insurance. Healthcare (US$1.94bn) and banking (US$1.15bn) took the largest shares.
  • For the UK, the cyber-risk quantification firm Kovrr estimated the hit to the UK economy at £1.7–2.3 billion.

Delta's US$500 million is Delta's own estimate; its SEC filing broke it into roughly US$380 million of lost revenue and US$170 million of expense.

The Delta Lawsuit and the "Kernel Privilege" Debate

The fiercest legal fight was begun by Delta Air Lines. On 25 October 2024 Delta sued CrowdStrike, Inc. in the Superior Court of Fulton County, Georgia — Microsoft was not named as a defendant, though Delta had retained David Boies and said it would pursue both companies. The complaint states that Delta "estimates that it suffered over $500 million in out-of-pocket losses" and pleads computer trespass, breach of contract, gross negligence and fraud by omission, among other counts.

Its technical core is the allegation that "CrowdStrike intentionally created and exploited an unauthorized door within the Microsoft OS through CrowdStrike's Falcon software." As a certified WHQL and ELAM driver developer, Delta argued, CrowdStrike was obliged to submit kernel-level programming and data for testing, and instead altered previously certified code with uncertified shortcuts.

CrowdStrike countersued, blaming the length of Delta's outage on Delta's own incident response and infrastructure rather than the update, pointing to the airline's recovery being slower than other major carriers' and to the limitation-of-liability and consequential-damages exclusions in their contract; press coverage of the filing described it as casting Delta's suit as a smokescreen. Several shareholder derivative suits and federal securities class actions were filed in parallel.

What the lawsuits exposed was the political dimension of kernel privilege in endpoint security. EDR (Endpoint Detection and Response) products operate in the OS kernel in order to detect threats, and a bug there can take down the entire operating system in an instant. The foundational question — whether the industry is adding vulnerabilities in the name of security — finally arrived on the public agenda.

Where the cases stand (August 2026)

CrowdStrike's Form 10-Q for the quarter ended 30 April 2026 gives the docket:

CaseStatus
Securities class action (W.D. Tex.)Dismissed 18 June 2025; Fifth Circuit affirmed the dismissal on 20 May 2026
Shareholder derivative suits (W.D. Tex. and Delaware Chancery)Dismissed across March and April 2026
Delta v. CrowdStrike (Fulton County)Motion to dismiss granted in part and denied in part, 16 May 2025; the fraud counts fell, gross negligence and others survived; discovery ongoing
DOJ / SECRequests for information received, relating to the company's revenue recognition

The investor litigation has effectively collapsed. The customer litigation has not.

Microsoft's Response — The Windows Endpoint Security Summit

On 10 September 2024, Microsoft convened the Windows Endpoint Security Ecosystem Summit at its headquarters in Redmond, Washington. Endpoint security vendors and government officials from the US and Europe attended.

Two days later, Microsoft's Corporate Vice President for Enterprise and OS Security, David Weston, published the summary. "Both our customers and ecosystem partners have called on Microsoft to provide additional security capabilities outside of kernel mode," he wrote, adding that "Windows 11's improved security posture and security defaults enable the platform to provide more security capabilities to solution providers outside of kernel mode." Not an outright kernel ban — a deliberate architectural offer that frees vendors from the requirement.

The follow-through:

  • November 2024 (Ignite). Microsoft announced the Windows Resiliency Initiative, including Quick Machine Recovery for machines stuck in the recovery environment.
  • 26 June 2025. Weston announced that "next month, we will deliver a private preview of the Windows endpoint security platform to a set of MVI partners" — Microsoft Virus Initiative members named as Bitdefender, CrowdStrike, ESET, SentinelOne, Sophos, Trellix, Trend Micro and WithSecure. The goal is that "security products like anti-virus and endpoint protection solutions can run in user mode just as apps do."
  • Summer 2025. Quick Machine Recovery reached general availability.

Why had Microsoft granted EDR vendors kernel access in the first place? Immediately after the outage, Microsoft told the Wall Street Journal that a 2009 interoperability undertaking given to the European Commission obliged it to grant third-party security vendors the same access it gave its own products. The Register's headline — "EU gave CrowdStrike the keys to the Windows kernel, claims Microsoft" (22 July 2024) — carries the important qualifier: this is Microsoft's claim, not a finding. The European Commission rejected the framing, telling Euronews that Microsoft is free to decide on its business model and that it is for Microsoft to adapt its security infrastructure to threats in line with EU competition law, and noting that Microsoft had never raised security concerns with the Commission before or after the incident.

CrowdStrike's Stock and Earnings

CrowdStrike shares closed down 11% on 19 July. The slide continued into early August, touching an intraday low just under US$201 — roughly half the July peak near US$390 — before recovering above US$300 by October 2024.

To retain customers the company introduced Customer Commitment Packages (CCP): discounts, easier payment terms, subscription extensions. In its Q2 FY2025 results (August 2024) CrowdStrike guided that CCP incentives would cut about US$30 million from subscription revenue in each remaining quarter of fiscal 2025, with a further impact in the high single-digit millions to professional-services revenue in the second half. The drag was still showing up in guidance at the June 2025 results.

Yet CrowdStrike did not fall. The set of credible EDR alternatives is small, replacement effort enormous, and most customers kept their contracts — which is why the share price was back above its pre-outage range within months while the revenue drag persisted for over a year. What the industry demonstrated was a different risk altogether: the switching cost of a concentrated security stack.

Three Lessons About Concentrated Privilege

The CrowdStrike outage left three lessons.

1. SaaS security as software supply chain. Auto-updates that bypass validation can cause incidents indistinguishable from supply-chain attacks. The debate around mandatory staged (canary) rollouts moved sharply forward.

2. Re-evaluation of kernel privilege. The premise that "a security product must live at the deepest part of the OS to do its job" finally came under genuine scrutiny. Windows, macOS, and Linux are all now exploring technical paths to push EDR back into user space.

3. A contested account of blame. The story that a 2009 commitment to the European Commission pried the kernel open and thereby made 2024 possible is Microsoft's account, and the Commission rejects it flatly. The dispute is unresolved — but it made visible that regulatory design and technical reality fifteen years later can come apart.

8.5 million BSODs were not, in the end, a single company's QA failure or a single OS vulnerability. They were the architectural philosophy of the whole industry — concentrating privilege in security products — implemented one morning by one bad data file. That is the structural shape of the event.

Questions this page answers

What caused the CrowdStrike outage?
A faulty content update, Channel File 291, shipped to the Falcon Sensor. It was not a kernel driver update but a data file the driver reads to define detection logic.
How many machines were affected?
Microsoft estimated 8.5 million devices, which it put at less than one percent of all Windows machines. No authoritative global damage total exists; Parametrix estimated US$5.4 billion in direct losses to Fortune 500 companies.

Sources

  1. Tertiary2024 CrowdStrike-related IT outages — Wikipedia

    Accessed 2026-08-03

Last updated:

Share