EXPLAINER | What caused the global cyber outage?

19 July 2024 - 13:14 By Martin Coulter and James Pearson
subscribe Just R20 for the first month. Support independent journalism by subscribing to our digital news package.
Subscribe now
A passenger studies flight schedule screens at Don Mueang International Airport in Bangkok, Thailand during global system outages disrupting airline operations on July 19 2024.
A passenger studies flight schedule screens at Don Mueang International Airport in Bangkok, Thailand during global system outages disrupting airline operations on July 19 2024.
Image: REUTERS/Chalinee Thirasupa

A global tech failure disrupted operations across many industries on Friday, halting flights and forcing broadcasters off-air as the outage upended everything from banking to healthcare systems.

WHAT HAPPENED?

CrowdStrike, a US cybersecurity company, is among the most popular in the world, counting more than 20,000 subscription customers globally.

According to an alert sent by CrowdStrike to its clients and reviewed by Reuters, its widely-used “Falcon Sensor” software is causing Microsoft Windows to crash and display a blue screen, known as the “blue screen of death”.

The alert, sent at 5.30 GMT on Friday, also shared a manual workaround to resolve the issue.

WHY DID IT HAPPEN?

“The damage to business processes at the global level is dramatic. The glitch is due to a software update of CrowdStrike’s EDR product,” said Omer Grossman, chief information officer at identity security firm CyberArk.

EDR, or endpoint detection and response, is a cybersecurity product companies place on their clients’ computers to help defend them against hackers. That software, which runs in the background on clients’ machines, or endpoints, is used by cybersecurity firms to monitor for signs of attack on their clients’ networks.

“It turns out that because the endpoints have crashed, 'the blue screen of death', they cannot be updated remotely and the problem must be solved manually, endpoint by endpoint. This is expected to be a process that will take days,” Grossman said.

WHO HAS BEEN IMPACTED?

The global tech outage has affected operations in different sectors internationally including at Spanish airports, US airlines and Australian media and banks.

The governments of Australia and New Zealand and some US states are facing issues, while American Airlines, Delta Airlines, United Airlines, and Allegiant Air grounded flights citing communication problems.

In Britain, Sky News, one of the country’s major television news channels, was off-air on Friday.

WHY ARE SO MANY IMPACTED?

With the move to the cloud and with companies owning huge market shares, their software is running on millions of computers around the world.

“The damage to business processes at the global level is dramatic,” Grossman said.

Reuters


subscribe Just R20 for the first month. Support independent journalism by subscribing to our digital news package.
Subscribe now

Would you like to comment on this article?
Sign up (it's quick and free) or sign in now.

Speech Bubbles

Please read our Comment Policy before commenting.