Don’t do SECURITY. Do business SECURELY.

Faulty CrowdStrike update crashes millions of Windows computers

A defective CrowdStrike Falcon update crashes around 8.5 million Windows devices, grounding flights and disrupting hospitals, banks, and broadcasters.

A faulty content update for CrowdStrike‘s Falcon endpoint security software caused Windows computers worldwide to crash and fail to restart, in what was widely described as the largest IT outage in history. Microsoft estimated that 8.5 million Windows devices, less than one per cent of the total, were affected.

What happened

  • The update, a sensor configuration file known as Channel File 291, was released at 04:09 UTC on 19 July and reverted at 05:27 UTC, 78 minutes later, but affected machines needed manual repair.
  • Airlines cancelled thousands of flights, and banks, payment systems, GP systems in England, and broadcasters including Sky News were disrupted.
  • CrowdStrike said the incident was not a cyber attack. Its root-cause analysis blamed a mismatch between the number of input fields the sensor expected and those supplied, which its testing had not caught.
  • Recovery took days for many organisations because of encrypted disks and the scale of manual fixes.

Why it mattered

The outage showed how a single trusted security vendor with deep system access can become a global single point of failure.

Lessons for organisations

Business continuity plans should cover the failure of trusted IT and security suppliers, not only attacks. Ask critical vendors how updates are tested and staged, and keep recovery keys and procedures accessible offline.

Sources: CrowdStrike, Microsoft

Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.

Get our weekly insights by emailA free weekly threat and vulnerability round-up with our threat log spreadsheet, plus legal, regulatory, standards, and AI updates.
Subscribe free

More insights