We finally know what caused the global tech outage - and how much it cost | CNN Business (2024)

We finally know what caused the global tech outage - and how much it cost | CNN Business (1)

After multiple cancelled flights to Washington D.C., Delta Airlines passengers Patty (L) and Alice Crump get ticketing assistance from an agent at Hartsfield-Jackson Atlanta International Airport.

CNN

Insurers have begun calculating the financial damage caused by last week’s devastating CrowdStrike software glitch that crashed computers, canceled flights and disrupted hospitals all around the globe — and the picture isn’t pretty.

What’s been described as the largest IT outage in history will costFortune 500 companies alone more than $5 billion in direct losses, according to one insurer’s analysis of the incident published Wednesday.

The new figures put into stark relief how a single automated software update brought much of the global economy to a sudden halt — revealing the world’s overwhelming dependence on a key cybersecurity company — and what it will take to recover.

Theestimates come the same day that CrowdStrike issued a preliminary report on how it inadvertently caused the widespread IT meltdown. It is the most detailed technical analysis to date of the outage.

Businesses are scrambling to recover – especially Delta Air Lines. Delta is still dealing with fallout from the glitch, as thousands of flights have been canceled. The Department of Transportation is investigating.

Numerous Fortune 500 companies use CrowdStrike’s cybersecurity software to detect and block hacking threats. But when CrowdStrike issued an update last week to its signature cybersecurity software, known as Falcon, millions of computers around the world running Microsoft Windows crashed because of the way that the update interacted with Windows.

The health care and banking sectors were the hardest hit by CrowdStrike’s mishap, with estimated losses of $1.94 billion and $1.15 billion, respectively, said Parametrix, the cloud monitoring and insurance firm behind Wednesday’s analysis.

Fortune 500 airlines such as American and United were the next most affected, losing a collective $860 million, Parametrix said.

All told, the outage may have cost Fortune 500 companies as much as $5.4 billion in revenues and gross profit, Parametrix said, not counting any secondary losses that may be attributed to lost productivity or reputational damage. Only a small portion, around 10% to 20%, may be covered by cybersecurity insurance policies, Parametrix added.

Fitch Ratings, one of the largest US credit ratings agencies, said Monday that the types of insurance likely to see the most claims stemming from the outage include business interruption insurance, travel insurance and event cancellation insurance.

“This incident highlights a growing risk of single points of failure,” Fitch said in a blog post, warning that such single points of failure “are likely to increase as companies seek consolidation to take advantage of scale and expertise, resulting in fewer vendors with higher market shares.”

The eye-popping damage estimates underscore how a preventable mistake at one of the world’s most dominant cybersecurity firms has had cascading effects for the global economy — and may prompt more calls for CrowdStrike to be held accountable.

What went wrong

On Wednesday, CrowdStrike released a report outlining the initial results of its investigation into the incident, which involved a file that helps CrowdStrike’s security platform look for signs of malicious hacking on customer devices.

The company routinely tests its software updates before pushing them out to customers, CrowdStrike said in the report. But on July 19, a bug in CrowdStrike’s cloud-based testing system —specifically,the part that runs validation checks on new updates prior to release — ended up allowing the software to be pushed out “despite containing problematic content data.”

The bad release was published just after midnight Eastern time on July 19, and rolled back an hour and a half later, at 1:27 a.m. Eastern, CrowdStrike said. But by then millions of computers had already automatically downloaded the faulty update. The issue affected only Windows devices, not Mac or Linux machines, and only those that were switched on and able to receive updates during those early morning hours.

Thanks to the timing of the incident, organizations in Europe and Asia “had more of their work day affected by the outage, unlike the Americas,” Fitch wrote in its blog post.

When Windows devices using CrowdStrike’s cybersecurity tools tried to access the flawed file, it caused an “out-of-bounds memory read” that “could not be gracefully handled, resulting in a Windows operating system crash,” CrowdStrike said.

That’s the Blue Screen of Death that many people reported seeing on their machines, and that only a manual intervention to delete the bad file could fix — a slow, painstaking process when you consider that as many as 8.5 million individual devices will need to be reset this way.

That figure is small as a percentage of the wider Windows ecosystem, said Microsoft — a company that played no direct role in the outage. Still, Microsoft said in a blog post, it “demonstrates the interconnected nature of our broad ecosystem.”

CrowdStrike said that the testing and validation system that approved the bad software update had appeared to function normally for other releases made earlier in the year. But it pledged Wednesday to keep software glitches like last week’s from happening again, and to publicly release a more detailed analysis when it becomes available.

The company added that it is developing a new check for its validation system “to guard against this type of problematic content from being deployed in the future.”

And CrowdStrike said it also plans to move to a staggered approach to releasing content updates so that not everyone receives the same update at once, and to give customers more fine-grained control over when the updates are installed.

CNN’s Sean Lyngaas contributed to this report

We finally know what caused the global tech outage - and how much it cost | CNN Business (2024)

FAQs

What is the cause of the global tech outage? ›

When Windows devices using CrowdStrike's cybersecurity tools tried to access the flawed file, it caused an “out-of-bounds memory read” that “could not be gracefully handled, resulting in a Windows operating system crash,” CrowdStrike said.

How much is the outage going to cost in CrowdStrike? ›

Insurers have estimated that the overall cost of CrowdStrike's recent outage, caused by a faulty Falcon sensor update, is billions of dollars. The massive outage that affected millions of Microsoft devices globally is predicted to cost Fortune 500 companies approximately $5.4 billion in direct financial losses.

How much did the global outage cost? ›

The global technology outage sparked by CrowdStrike's faulty update will cost US Fortune 500 companies $5.4bn, insurers estimated, as the cybersecurity firm vowed to make changes to prevent it from happening again.

How much did the CrowdStrike incident cost? ›

CrowdStrike outage will cost Fortune 500 companies $5.4 billion in damages. A screen at Gatwick Airport displays an announcement on possible travel delays due to a global IT outage on July 19.

What has caused the Global IT outage? ›

A bug in a software update by cybersecurity firm CrowdStrike has caused global travel chaos, scrambled 911 lines in the US, and put news channels including Sky News temporarily off-air. The outage affected computer systems using Microsoft Windows.

How much money was lost because of CrowdStrike? ›

Insured losses from the incident are likely to range from $0.54 billion to $1.08 billion, Parametrix estimated, assuming the ratio of insured loss to financial losses at 10-15%. The estimate is somewhat supported by cyber-risk intelligence firm CyberCube.

What is the root cause of the CrowdStrike outage? ›

The main issue was a mismatch between the input fields expected by CrowdStrike's Falcon driver and the ones supplied in a content update. CrowdStrike is now promising to better test updates and is using two independent third-party software security vendors to review its sensor code and release processes.

Is Google affected by CrowdStrike? ›

While Google Cloud services were not directly impacted, Google Cloud continues to work with CrowdStrike to help our customers recover from any remaining impact. If your Windows VM continues to experience issues after a reboot, manual patching. Please contact Google Cloud Customer Support.

Why is CrowdStrike falling? ›

While investors were sleeping, CrowdStrike released a defective update to its software that caused Microsoft-based IT systems to go down. The outage was perhaps most notable for airlines, which were forced to cancel and delay flights.

Is global tech outage fixed? ›

The global tech outage that forced local airlines, hospitals and banks to a standstill on Friday was caused by a faulty update from a cybersecurity company delivered to Microsoft Windows customers.

What is outage cost? ›

You can estimate the cost to your business of your customer-facing database system being unavailable to process customer transactions. For example, you can calculate an average cost in lost sales revenue for every hour or minute during which that database system is unavailable.

How much does an IT outage cost? ›

Industry statistics for the cost of IT downtime

In late 2022, Information Technology Intelligence Consulting (ITIC) published a survey on server reliability that put the cost of IT downtime at a minumum of $5,000 a minute. About 44% of those polled put costs at $16,700 per server/per minute or $1 million an hour.

Could CrowdStrike outage cost $5.4 B? ›

CrowdStrike Outage Could Cost Fortune 500 Companies $5.4B CrowdStrike Outage Could Cost Fortune 500 Companies $5.4B. The global IT outage caused by CrowdStrike's faulty software update could cost Fortune 500 companies $5.4 billion, according to figures from insurer Parametrix.

How much does CrowdStrike prevent cost? ›

Pricing starts at $59.99 per endpoint per year for our CrowdStrike Falcon Prevent Next Generation Antivirus product.

How much did CrowdStrike pay? ›

As of Aug 30, 2024, the average hourly pay for a Crowdstrike in the United States is $56.46 an hour.

What has caused the global outage? ›

The global outage stems from an update CrowdStrike made to its marquee cybersecurity platform, a cloud-based software product called Falcon.

What caused global software outage? ›

What we know about the global Microsoft outage. A massive outage was caused by what was supposed to be a routine update from the cybersecurity company CrowdStrike. A routine software update caused cascading chaos Friday that has engulfed global businesses from airports and banks to retail and law enforcement.

What caused the global tech meltdown? ›

The chaos stemmed from an update sent by CrowdStrike, a cybersecurity company based in Austin, Texas, to businesses that use its software to protect against hackers and online intruders. But when CrowdStrike's new code reached computers that run Microsoft Windows software, the machines began to crash.

What was the cause of the Microsoft global outage? ›

What are the reasons for the global IT outage? CrowdStrike had pushed an update on Friday for Microsoft applications and devices but it turned out to be faulty in nature and caused a 'blue screen of death' to appear on user's screens, instead of the Windows OS booting up.

References

Top Articles
Developing an Internal Control Manual
Private Company Guide to Effective Internal Controls
Spasa Parish
Rentals for rent in Maastricht
159R Bus Schedule Pdf
Sallisaw Bin Store
Black Adam Showtimes Near Maya Cinemas Delano
Espn Transfer Portal Basketball
Pollen Levels Richmond
11 Best Sites Like The Chive For Funny Pictures and Memes
Things to do in Wichita Falls on weekends 12-15 September
Craigslist Pets Huntsville Alabama
Paulette Goddard | American Actress, Modern Times, Charlie Chaplin
Red Dead Redemption 2 Legendary Fish Locations Guide (“A Fisher of Fish”)
What's the Difference Between Halal and Haram Meat & Food?
R/Skinwalker
Rugged Gentleman Barber Shop Martinsburg Wv
Jennifer Lenzini Leaving Ktiv
Justified - Streams, Episodenguide und News zur Serie
Epay. Medstarhealth.org
Olde Kegg Bar & Grill Portage Menu
Cubilabras
Half Inning In Which The Home Team Bats Crossword
Amazing Lash Bay Colony
Juego Friv Poki
Dirt Devil Ud70181 Parts Diagram
Truist Bank Open Saturday
Water Leaks in Your Car When It Rains? Common Causes & Fixes
What’s Closing at Disney World? A Complete Guide
New from Simply So Good - Cherry Apricot Slab Pie
Fungal Symbiote Terraria
modelo julia - PLAYBOARD
Poker News Views Gossip
Abby's Caribbean Cafe
Joanna Gaines Reveals Who Bought the 'Fixer Upper' Lake House and Her Favorite Features of the Milestone Project
Tri-State Dog Racing Results
Navy Qrs Supervisor Answers
Trade Chart Dave Richard
Lincoln Financial Field Section 110
Free Stuff Craigslist Roanoke Va
Wi Dept Of Regulation & Licensing
Pick N Pull Near Me [Locator Map + Guide + FAQ]
Crystal Westbrooks Nipple
Ice Hockey Dboard
Über 60 Prozent Rabatt auf E-Bikes: Aldi reduziert sämtliche Pedelecs stark im Preis - nur noch für kurze Zeit
Wie blocke ich einen Bot aus Boardman/USA - sellerforum.de
Infinity Pool Showtimes Near Maya Cinemas Bakersfield
Dermpathdiagnostics Com Pay Invoice
How To Use Price Chopper Points At Quiktrip
Maria Butina Bikini
Busted Newspaper Zapata Tx
Latest Posts
Article information

Author: Lilliana Bartoletti

Last Updated:

Views: 6436

Rating: 4.2 / 5 (53 voted)

Reviews: 84% of readers found this page helpful

Author information

Name: Lilliana Bartoletti

Birthday: 1999-11-18

Address: 58866 Tricia Spurs, North Melvinberg, HI 91346-3774

Phone: +50616620367928

Job: Real-Estate Liaison

Hobby: Graffiti, Astronomy, Handball, Magic, Origami, Fashion, Foreign language learning

Introduction: My name is Lilliana Bartoletti, I am a adventurous, pleasant, shiny, beautiful, handsome, zealous, tasty person who loves writing and wants to share my knowledge and understanding with you.