A faulty content update for CrowdStrike‘s Falcon endpoint security software caused Windows computers worldwide to crash and fail to restart, in what was widely described as the largest IT outage in history. Microsoft estimated that 8.5 million Windows devices, less than one per cent of the total, were affected.
What happened
- The update, a sensor configuration file known as Channel File 291, was released at 04:09 UTC on 19 July and reverted at 05:27 UTC, 78 minutes later, but affected machines needed manual repair.
- Airlines cancelled thousands of flights, and banks, payment systems, GP systems in England, and broadcasters including Sky News were disrupted.
- CrowdStrike said the incident was not a cyber attack. Its root-cause analysis blamed a mismatch between the number of input fields the sensor expected and those supplied, which its testing had not caught.
- Recovery took days for many organisations because of encrypted disks and the scale of manual fixes.
Why it mattered
The outage showed how a single trusted security vendor with deep system access can become a global single point of failure.
Lessons for organisations
Business continuity plans should cover the failure of trusted IT and security suppliers, not only attacks. Ask critical vendors how updates are tested and staged, and keep recovery keys and procedures accessible offline.
Sources: CrowdStrike, Microsoft
Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.