20 Jul 2024

CrowdStrike glitch: What caused the global cyber outage?

7:31 am on 20 July 2024

By Martin Coulter and James Pearson, Reuters

This photograph shows screens displaying logos of "CrowdStrike" cybersecurity technology company in Munich on July 19, 2024, amid massive global IT outage. Airlines, banks, TV channels and other business across the globe were scrambling to deal with one of the biggest IT crashes in recent years on July 19, 2024, caused by an update to an antivirus program. (Photo by Michaela STACHE / AFP)

Photo: AFP/Michaela Stache

Explainer - A global tech failure disrupted operations across multiple industries on Friday, halting flights and upending everything from banking to healthcare systems.

What happened?

CrowdStrike, a U.S. cybersecurity company with a market value of about $83 billion, is among the most popular in the world, counting more than 20,000 subscribers around the world, the company's website shows.

According to an alert sent by CrowdStrike to its clients at at 5.30pm NZT and reviewed by Reuters, its widely used "Falcon Sensor" software was causing Microsoft Windows to crash and display a blue screen, known informally as the "Blue Screen of Death".

George Kurtz, CrowdStrike's CEO, said in a post on X that CrowdStrike had deployed a fix for the issue. "This is not a security incident or cyberattack," he wrote.

However, it is not clear how easily the affected systems can be fixed remotely, as the "Blue Screen of Death" is causing computers to crash on reboot before they can be updated.

"This means in this state, devices can't be updated automatically, meaning manual intervention is required," said Daniel Card, of UK-based cybersecurity consultancy PwnDefend.

Ciaran Martin, former head of the National Cyber Security Centre (NCSC), part of Britain's GCHQ intelligence agency, said the scale of the problem was huge.

"This is not unprecedented, but I'm struggling to think of an outage at quite this scale. It has happened over the years, but this is one of the biggest. I think it'll likely be short-lived because, the nature of the problem is actually quite simple.

"But it's very, very, very, very, big," he added.

Global cyber outage hits Auckland petrol station, affecting paywave services.

A sign at an Auckland petrol station. Photo: RNZ

Why did it happen?

Accelerated by the Covid-19 pandemic, governments and businesses alike have become increasingly dependent on a handful of interconnected technology companies over the past two decades.

Experts say the cyber outage revealed the risks of an increasingly online world.

To protect their computer networks from being breached by hackers, many businesses use a cybersecurity product known as Endpoint Detection and Response, or EDR, which runs in the background of corporate machines, or "endpoints".

Firms like CrowdStrike are able to use their EDR products as early warning systems for potential digital attacks, scan for viruses, and prevent hackers from gaining unauthorised access to corporate networks.

But, in this case, something in CrowdStrike's code is conflicting with something in the code that makes Windows work, and causing those systems to crash, even after rebooting.

"With the move to the cloud and with companies like CrowdStrike owning huge market shares, their software is running on millions of computers around the world," said Card.

Who has been impacted?

The global tech outage has affected operations in different sectors internationally including at Spanish airports, U.S. airlines and Australian media and banks.

The governments of Australia, New Zealand, and a number of U.S. states are facing issues, while American Airlines, Delta Airlines, United Airlines (UAL.O), and Allegiant Air (ALGT.O grounded flights citing communication problems.

In Britain, Sky News, one of the country's major television news channels, was off air for hours on Friday before service was restored.

- Reuters

Get the RNZ app

for ad-free news and current affairs