We finally know what caused the global tech outage - and how much it cost | CNN Business (2024)

We finally know what caused the global tech outage - and how much it cost | CNN Business (1)

After multiple cancelled flights to Washington D.C., Delta Airlines passengers Patty (L) and Alice Crump get ticketing assistance from an agent at Hartsfield-Jackson Atlanta International Airport.

CNN

Insurers have begun calculating the financial damage caused by last week’s devastating CrowdStrike software glitch that crashed computers, canceled flights and disrupted hospitals all around the globe — and the picture isn’t pretty.

What’s been described as the largest IT outage in history will costFortune 500 companies alone more than $5 billion in direct losses, according to one insurer’s analysis of the incident published Wednesday.

The new figures put into stark relief how a single automated software update brought much of the global economy to a sudden halt — revealing the world’s overwhelming dependence on a key cybersecurity company — and what it will take to recover.

Theestimates come the same day that CrowdStrike issued a preliminary report on how it inadvertently caused the widespread IT meltdown. It is the most detailed technical analysis to date of the outage.

Businesses are scrambling to recover – especially Delta Air Lines. Delta is still dealing with fallout from the glitch, as thousands of flights have been canceled. The Department of Transportation is investigating.

Numerous Fortune 500 companies use CrowdStrike’s cybersecurity software to detect and block hacking threats. But when CrowdStrike issued an update last week to its signature cybersecurity software, known as Falcon, millions of computers around the world running Microsoft Windows crashed because of the way that the update interacted with Windows.

The health care and banking sectors were the hardest hit by CrowdStrike’s mishap, with estimated losses of $1.94 billion and $1.15 billion, respectively, said Parametrix, the cloud monitoring and insurance firm behind Wednesday’s analysis.

Fortune 500 airlines such as American and United were the next most affected, losing a collective $860 million, Parametrix said.

All told, the outage may have cost Fortune 500 companies as much as $5.4 billion in revenues and gross profit, Parametrix said, not counting any secondary losses that may be attributed to lost productivity or reputational damage. Only a small portion, around 10% to 20%, may be covered by cybersecurity insurance policies, Parametrix added.

Fitch Ratings, one of the largest US credit ratings agencies, said Monday that the types of insurance likely to see the most claims stemming from the outage include business interruption insurance, travel insurance and event cancellation insurance.

“This incident highlights a growing risk of single points of failure,” Fitch said in a blog post, warning that such single points of failure “are likely to increase as companies seek consolidation to take advantage of scale and expertise, resulting in fewer vendors with higher market shares.”

The eye-popping damage estimates underscore how a preventable mistake at one of the world’s most dominant cybersecurity firms has had cascading effects for the global economy — and may prompt more calls for CrowdStrike to be held accountable.

What went wrong

On Wednesday, CrowdStrike released a report outlining the initial results of its investigation into the incident, which involved a file that helps CrowdStrike’s security platform look for signs of malicious hacking on customer devices.

The company routinely tests its software updates before pushing them out to customers, CrowdStrike said in the report. But on July 19, a bug in CrowdStrike’s cloud-based testing system —specifically,the part that runs validation checks on new updates prior to release — ended up allowing the software to be pushed out “despite containing problematic content data.”

The bad release was published just after midnight Eastern time on July 19, and rolled back an hour and a half later, at 1:27 a.m. Eastern, CrowdStrike said. But by then millions of computers had already automatically downloaded the faulty update. The issue affected only Windows devices, not Mac or Linux machines, and only those that were switched on and able to receive updates during those early morning hours.

Thanks to the timing of the incident, organizations in Europe and Asia “had more of their work day affected by the outage, unlike the Americas,” Fitch wrote in its blog post.

When Windows devices using CrowdStrike’s cybersecurity tools tried to access the flawed file, it caused an “out-of-bounds memory read” that “could not be gracefully handled, resulting in a Windows operating system crash,” CrowdStrike said.

That’s the Blue Screen of Death that many people reported seeing on their machines, and that only a manual intervention to delete the bad file could fix — a slow, painstaking process when you consider that as many as 8.5 million individual devices will need to be reset this way.

That figure is small as a percentage of the wider Windows ecosystem, said Microsoft — a company that played no direct role in the outage. Still, Microsoft said in a blog post, it “demonstrates the interconnected nature of our broad ecosystem.”

CrowdStrike said that the testing and validation system that approved the bad software update had appeared to function normally for other releases made earlier in the year. But it pledged Wednesday to keep software glitches like last week’s from happening again, and to publicly release a more detailed analysis when it becomes available.

The company added that it is developing a new check for its validation system “to guard against this type of problematic content from being deployed in the future.”

And CrowdStrike said it also plans to move to a staggered approach to releasing content updates so that not everyone receives the same update at once, and to give customers more fine-grained control over when the updates are installed.

CNN’s Sean Lyngaas contributed to this report

We finally know what caused the global tech outage - and how much it cost | CNN Business (2024)

FAQs

We finally know what caused the global tech outage - and how much it cost | CNN Business? ›

Costs from the global outage could top $1 billion – but who pays the bill is harder to understand. The world learned relatively quickly that cybersecurity firm CrowdStrike

CrowdStrike
CrowdStrike Holdings, Inc. is an American cybersecurity technology company based in Austin, Texas. It provides endpoint security, threat intelligence, and cyberattack response services.
https://en.wikipedia.org › wiki › CrowdStrike
was behind a crippling global tech outage on Friday.

What caused the CrowdStrike outage? ›

CrowdStrike blamed the recent outage on an issue in its testing software, which allowed a bug to be released, causing Falcon to malfunction. Cable said 5,000 Microsoft support engineers had been working around the clock since the outage “to help bring critical services back online”.

What is the CrowdStrike issue? ›

A CrowdStrike update caused a massive IT outage, crashing millions of Windows systems. Critical services and business operations were disrupted, revealing tech reliance risks.

Why is CrowdStrike down so much? ›

CrowdStrike shares (CRWD) have lost 28% since a bad software update from the cybersecurity company triggered a global information-technology outage.

Who is suing CrowdStrike? ›

The lawsuit led by the Plymouth County Retirement Association of Plymouth, Mass., seeks unspecified damages for holders of CrowdStrike Class A shares between Nov. 29, 2023 and July 29, 2024.

Who owns CrowdStrike? ›

The ownership structure of CrowdStrike Holdings (CRWD) stock is a mix of institutional, retail and individual investors. Approximately 45.23% of the company's stock is owned by Institutional Investors, 2.19% is owned by Insiders and 52.58% is owned by Public Companies and Individual Investors.

Why did CrowdStrike crash? ›

CrowdStrike crash caused by supply chain vulnerability similar to SolarWinds attack. So far, what we know about the CrowdStrike crash is that it was caused by human error and not a cyberattack or malicious intent. But the crash highlights the same vulnerabilities we saw during the SolarWinds attack in 2019.

Will CrowdStrike recover? ›

While CrowdStrike will see an impact to new recurring revenue during the second half of the year in the wake of the historic Windows outage caused by its faulty update, the security vendor is poised to largely bounce back over the longer term, according to Morgan Stanley analysts.

What is incident in CrowdStrike? ›

The CrowdStrike Incident Response (IR) team brings control, stability and organization to what can be a confusing and chaotic situation. Given the current threat landscape, most organizations will likely encounter a cyber incident, at some point that they will have to respond to and manage effectively.

What is the prediction for CrowdStrike? ›

The average price target for CrowdStrike Holdings is $365.94. This is based on 37 Wall Streets Analysts 12-month price targets, issued in the past 3 months. The highest analyst price target is $450.00 ,the lowest forecast is $275.00.

Is CrowdStrike a virus? ›

CrowdStrike is a web/cloud based anti-virus which uses very little storage space on your machine. CrowdStrike installs a lightweight sensor on your machine that is less than 5MB and is completely invisible to the end user.

How does CrowdStrike stop breaches? ›

CrowdStrike is the leader in next-generation endpoint protection, threat intelligence and response services. CrowdStrike's core technology, the Falcon platform, stops breaches by preventing and responding to all types of attacks — both malware and malware-free.

References

Top Articles
baby food for sick bearded dragon
Neil Diamond - Shiloh Lyrics Meaning
Davita Internet
Week 2 Defense (DEF) Streamers, Starters & Rankings: 2024 Fantasy Tiers, Rankings
1movierulzhd.fun Reviews | scam, legit or safe check | Scamadviser
Videos De Mexicanas Calientes
Localfedex.com
Mohawkind Docagent
Wfin Local News
Buckaroo Blog
Infinite Campus Parent Portal Hall County
Yesteryear Autos Slang
Guardians Of The Galaxy Vol 3 Full Movie 123Movies
What Is Njvpdi
Discover Westchester's Top Towns — And What Makes Them So Unique
Jc Post News
Lima Funeral Home Bristol Ri Obituaries
Guilford County | NCpedia
Peraton Sso
Arboristsite Forum Chainsaw
91 East Freeway Accident Today 2022
Kountry Pumpkin 29
Aps Day Spa Evesham
Allybearloves
Reptile Expo Fayetteville Nc
Phoebus uses last-second touchdown to stun Salem for Class 4 football title
Best Boston Pizza Places
Mdt Bus Tracker 27
Radical Red Ability Pill
Craigslist Fort Smith Ar Personals
Grave Digger Wynncraft
Miller Plonka Obituaries
Lilpeachbutt69 Stephanie Chavez
Lininii
Experity Installer
Willys Pickup For Sale Craigslist
The Menu Showtimes Near Amc Classic Pekin 14
What Time Does Walmart Auto Center Open
Mississippi State baseball vs Virginia score, highlights: Bulldogs crumble in the ninth, season ends in NCAA regional
Natashas Bedroom - Slave Commands
Vision Source: Premier Network of Independent Optometrists
Mvnt Merchant Services
Best Restaurants West Bend
Post A Bid Monticello Mn
Courtney Roberson Rob Dyrdek
Ghareeb Nawaz Texas Menu
Deezy Jamaican Food
Actress Zazie Crossword Clue
Plumfund Reviews
Diario Las Americas Rentas Hialeah
Superecchll
BYU Football: Instant Observations From Blowout Win At Wyoming
Latest Posts
Article information

Author: The Hon. Margery Christiansen

Last Updated:

Views: 5910

Rating: 5 / 5 (70 voted)

Reviews: 93% of readers found this page helpful

Author information

Name: The Hon. Margery Christiansen

Birthday: 2000-07-07

Address: 5050 Breitenberg Knoll, New Robert, MI 45409

Phone: +2556892639372

Job: Investor Mining Engineer

Hobby: Sketching, Cosplaying, Glassblowing, Genealogy, Crocheting, Archery, Skateboarding

Introduction: My name is The Hon. Margery Christiansen, I am a bright, adorable, precious, inexpensive, gorgeous, comfortable, happy person who loves writing and wants to share my knowledge and understanding with you.