CrowdStrike IT outage affected 8.5 million Windows devices, Microsoft says

0
220

Microsoft has estimated that 8.5 million computers worldwide were disabled by the recent global IT outage, marking it as possibly the worst cyber event in history. This is the first time a figure has been put on the incident, which stemmed from a corrupted software update sent out by the security company CrowdStrike to its vast number of customers.

In a blog post, David Weston, vice-president at Microsoft, stated, “We currently estimate that CrowdStrike’s update affected 8.5 million Windows devices.” While this number represents less than 1% of all Windows machines globally, the broad economic and societal impacts are significant due to the critical services run by enterprises using CrowdStrike.

CrowdStrike IT outage affected 8.5 million Windows devices, Microsoft says
(Credit: Shutterstock / Alex Photo Stock)

Microsoft can accurately determine how many devices were disabled due to its performance telemetry, which monitors many devices through their internet connections. The tech giant emphasized that this was not an issue with its software and highlighted the importance of quality control checks on updates by companies like CrowdStrike before distribution.

Weston noted, “It’s also a reminder of how important it is for all of us across the tech ecosystem to prioritize operating with safe deployment and disaster recovery using the mechanisms that exist.” The fallout from the IT glitch has been enormous, already ranking as one of the worst cyber incidents in history.

The estimated impact of 8.5 million devices makes this likely the largest cyber event ever, surpassing all previous hacks and outages. The closest comparison is the WannaCry cyber-attack in 2017, which affected around 300,000 computers in 150 countries, followed by the NotPetya attack a month later. Another significant event was a major six-hour outage in 2021 at Meta, which impacted Instagram, Facebook, and WhatsApp, but was largely contained to the social media giant and some linked partners.

The massive outage has prompted warnings from cybersecurity experts and agencies worldwide about a wave of opportunistic hacking attempts linked to the IT outage. Cyber agencies in the UK and Australia have urged people to be vigilant against fake emails, calls, and websites pretending to be official.

CrowdStrike CEO George Kurtz advised users to ensure they were communicating with official representatives from the company before downloading fixes. “We know that adversaries and bad actors will try to exploit events like this,” he said in a blog post. During major news events, especially those related to technology, hackers often adapt their methods to exploit the associated fear and uncertainty.

Researchers at Secureworks have already observed a sharp increase in CrowdStrike-themed domain registrations, indicating that hackers are creating new websites to look official, potentially tricking IT managers or the public into downloading malicious software or divulging private details. Cybersecurity agencies globally have urged IT responders to use only CrowdStrike’s official website for information and assistance.

This advice is primarily aimed at IT managers working to restore their organizations’ systems, but individuals might also be targeted. Experts warn everyone to be hyper-vigilant and only act on information from official CrowdStrike channels to avoid falling victim to scams.

More Microsoft news →

EntrelligenceFree guide
Your First 10 AI Skills

Your First 10 AI Skills

10 practical AI skills, copy-paste prompts and a 7-day plan to start using AI with confidence.

Download the guide →
0 0 votes
Article Rating
Subscribe
Notify of
guest
0 Comments
Oldest
Newest Most Voted