CaseLearn logo
CASELEARN
Education that works
Try free
Home › Case studies › Crowdstrike
TechnologyEngineering FailureCybersecurityAdvanced2024

Crowdstrike: 8.5 Million Windows Machines Crashed by One Update

How a single faulty configuration file update caused the largest IT outage in history — crashing airlines, hospitals, banks, and broadcasters simultaneously.

The challenge

On July 19, 2024, Crowdstrike pushed a routine content configuration update to their Falcon sensor — security software installed on millions of Windows machines globally. The update contained a logic error in a configuration file. Unlike traditional software, security sensors run at the kernel level with system-level privileges.

The strategy

The configuration file update bypassed traditional software testing because it was classified as a content update, not a code update. Content updates had a faster, less rigorous validation pipeline. The update was pushed globally and simultaneously — the standard procedure for security updates which need to reach all machines quickly to protect against threats.

Want the full story, outcome and quiz?

Read how Crowdstrike executed it, the results, key lessons and test yourself with a quiz. Free on CaseLearn.

Try the full case free →

Key lessons (preview)

More Engineering Failure cases

FacebookThe 6-Hour Outage — How DNS Took Down EverythingKnight Capital$440 Million Lost in 45 Minutes — The Costliest Bug in HistoryTherac-25The Radiation Machine That Killed People Due to a Software BugLog4ShellThe Vulnerability That Broke the Internet