Skip to main content

CrowdStrike causes a global outage following a faulty update

An update to the CrowdStrike Falcon sensor caused widespread failures in Windows systems, affecting airlines, banks, media, healthcare, and other organisations.

CybersecuritySeintec team2-3 min read
CrowdStrike causes a global outage following a faulty update

News summary

An update to the CrowdStrike Falcon sensor caused widespread failures in Windows systems, affecting airlines, banks, media, healthcare, and other organisations. CrowdStrike clarified that it was not a cyberattack and deployed a fix; Microsoft later estimated that approximately 8.5 million Windows devices had been affected.

Continuity plans must also account for update errors, phased rollouts, rollback, and recovery when the affected component is a security tool.

Source: Reuters — 19 July 2024

What exactly happened

On 19 July 2024 CrowdStrike pushed a content update to its Falcon sensor for Windows. A faulty configuration file crashed the system at boot, leaving many machines stuck in a blue-screen loop.

In many cases the fix required manual work on each machine: booting into safe mode or the recovery environment and deleting the affected file. On BitLocker-encrypted devices, each disk's recovery key was also needed. Mac and Linux hosts were not affected by this fault.

What it teaches a mid-sized business

It wasn't an attack, but it had the effect of one: workstations and servers down at the same time. It shows that continuity planning must also cover failures of security software itself and of any tool with deep system privileges.

Organisations that recovered fastest had an up-to-date inventory, quick access to BitLocker keys stored outside the affected machines and staff able to work in parallel.

What to review

These checks apply to any security or remote-management vendor:

  • Where BitLocker recovery keys are stored and whether they can be retrieved with core systems down.
  • Whether critical agent updates can be rolled out in rings rather than to every device at once.
  • Which machines are essential to keep operating and how they are restored first.
  • Whether the continuity plan covers non-malicious vendor failures.

Frequently Asked Questions

Was it a cyberattack?
No. CrowdStrike confirmed it was a defect in a content update, not a security incident.
Why did recovery take so long for some companies?
Because the fix had to be applied machine by machine and, with BitLocker, required each device's recovery key.
Should we distrust EDR tools?
No. They remain necessary; the lesson is to manage their updates and plan recovery in case they fail.

Technology only adds value when it is well-designed, protected, and maintained. Seintec can help you implement these best practices in your company; speak with our team to assess your environment.

Contact Seintec

Related service

Cybersecurity

We shield your business so it never stops.

Next step

Would you like to implement these improvements in your company?

Speak with a Seintec expert and we will review how this applies to your infrastructure together.