6:34 am today

CrowdStrike IT outage affected 8.5 million Windows devices, Microsoft says

6:34 am today

By Joe Tidy, BBC News

Departure monitors show canceled and delayed flights at Ronald Reagan Washington National Airport on July 19, 2024, in Arlington, Virginia, during a major worldwide computer systems outage. The outage has wrought havoc on computer systems worldwide, grounding flights across the globe, including in Europe and the US, derailing television broadcasts in the UK and impacting telecommunications in Australia. US carriers Delta and United Airlines grounded all their flights earlier on July 19 over communication issues, the Federal Aviation Administration said. (Photo by Mandel NGAN / AFP)

The CrowdStrike glitch crippled businesses across the globe, especially airline systems. Photo: AFP/Mandel Ngan

Microsoft says it estimates that 8.5 million computers around the world were disabled by the global IT outage.

It is the first time that a number has been put on the incident, which is still causing problems around the world.

The glitch came from a cyber security company called CrowdStrike, which sent out a corrupted software update to its huge number of customers.

Microsoft, which is helping customers recover, said in a blog post: "We currently estimate that CrowdStrike's update affected 8.5 million Windows devices."

The post by David Weston, vice-president, enterprise and OS at the firm, says this number is less than 1 percent of all Windows machines worldwide, but that "the broad economic and societal impacts reflect the use of CrowdStrike by enterprises that run many critical services".

The company can be very accurate on how many devices were disabled by the outage as it has performance telemetry to many by their internet connections.

The tech giant - which was keen to point out that this was not an issue with its software - says the incident highlights how important it is for companies such as CrowdStrike to use quality control checks on updates before sending them out.

"It's also a reminder of how important it is for all of us across the tech ecosystem to prioritise operating with safe deployment and disaster recovery using the mechanisms that exist," Weston said.

The fall-out from the IT glitch has been enormous and was already one of the worst cyber-incidents in history.

The number given by Microsoft means it is probably the largest ever cyber-event, eclipsing all previous hacks and outages.

The closest to this is the WannaCry cyber-attack in 2017, which is estimated to have impacted around 300,000 computers in 150 countries. There was a similar costly and disruptive attack called NotPetya a month later.

There was also a major six-hour outage in 2021 at Meta, which runs Instagram, Facebook and WhatsApp. But that was largely contained to the social media giant and some linked partners.

The massive outage has also prompted warnings by cyber-security experts and agencies around the world about a wave of opportunistic hacking attempts linked to the IT outage.

Cyber agencies in the UK and Australia are warning people to be vigilant to fake emails, calls and websites that pretend to be official.

And CrowdStrike head George Kurtz encouraged users to make sure they were speaking to official representatives from the company before downloading fixes.

"We know that adversaries and bad actors will try to exploit events like this," he said in a blog post.

Whenever there is a major news event, especially one linked to technology, hackers respond by tweaking their existing methods to take into account the fear and uncertainty.

According to researchers at Secureworks, there has already been a sharp rise in CrowdStrike-themed domain registrations - hackers registering new websites made to look official and potentially trick IT managers or members of the public into downloading malicious software or handing over private details.

Cyber security agencies around the world have urged IT responders to only use CrowdStrike's website to source information and help.

The advice is mainly for IT managers who are the ones being affected by this as they try to get their organisations back online.

But individuals too might be targeted, so experts are warning to be to be hyper vigilant and only act on information from the official CrowdStrike channels.

- BBC News

Get the RNZ app

for ad-free news and current affairs