CrowdStrike’s July 19, 2024 Falcon content-configuration update crashed affected Windows computers and disrupted airlines, banks, hospitals, emergency services, businesses and government operations. Microsoft said more than 8 million Windows devices were affected. The legal aftermath was broad, but it did not remain one undifferentiated “onslaught”: a shareholder securities case was dismissed in January 2026, consolidated derivative suits were dismissed on April 16, 2026 according to CrowdStrike’s proxy materials, and passenger litigation required continuing procedural review. Delta Air Lines’ commercial lawsuit remained a significant unresolved proceeding in CrowdStrike’s latest surfaced filing.
What happened on July 19, 2024
CrowdStrike distributed a content-configuration update for its Falcon security sensor. On affected Windows systems, the update caused crashes that could recur in blue-screen failures. This was not described as a conventional cyberattack or malware infection; the central event was a faulty software update and the controls used to validate and deploy it.
The device count understates the practical disruption. A single failed endpoint could interrupt flights, payment operations, clinical work, emergency response or business processes. CrowdStrike’s description of the incident appears in its SEC filing, while the estimate of more than 8 million affected Windows devices was reported by Microsoft and covered in later reporting.
CrowdStrike’s annual-report filing describes the released content configuration update and resulting crashes.
Recommended Free Tools
#1 Best Overall
- Quad Core J3710 Processor: F3 firewall hardware with Pentium J3710 Processor, 4 Cores 4 Threads, 2M Cache, up to 2.64 GHz, TDP 6.5 W. Compatible with OPNsense, Linux, ESXi, Proxmox
- 4 x i225V 2.5GbE LAN: J3710 mini pc with 4 x i225V 2500Mbps LAN, can monitor network data, improve network security, powerful and widely used
- DDR3 RAM mSATA Slot: J3710 firewall pc with 1 x DDR3L SO-DIMM memory, 1 x mSATA SSD slot, 1 x SATA 3.0 slot(SATA Cable included), 1 x Mini-PCIe Slot
- HD DP Dual Display: Micro firewall appliance J3710 integrated HD Graphics, HD + DP dual display interfaces improve work efficiency
- Fanless Mini Size: Firewall appliance J3710 with aluminium alloy body, fanless quiet running without noise. Size only 11 x 10 x 3.5 cm
The litigation map
| Claimant or group | Main theories | Forum or proceeding | Latest status in the cited record |
|---|---|---|---|
| Investors | Securities fraud based on alleged misleading statements about testing and quality assurance | Federal shareholder class action | Dismissed January 14, 2026, according to reporting on the ruling |
| Officers and directors | Breach of fiduciary duty, unjust enrichment and federal securities-law violations | Consolidated derivative litigation | CrowdStrike’s 2026 proxy materials say the suits were dismissed April 16, 2026 |
| Passengers and travelers | Negligence and public nuisance; proposed class claims for disruption and expenses | Passenger class litigation, including a consolidated complaint | Still identified in CrowdStrike’s April 30, 2026 filing; class certification and other procedural issues remain material |
| Delta Air Lines | Computer trespass, trespass to personalty, contract, fraud-related claims, strict-liability product defect, gross negligence and unfair-business-practice claims | Fulton County Superior Court, Georgia | Motion to dismiss denied May 16, 2025; case continued to be disclosed as pending |
A lawsuit contains allegations, not findings of fact. A motion-to-dismiss ruling tests legal sufficiency at that stage; it does not establish negligence, fraud or the amount of any loss.
Why the update created different kinds of legal exposure
Negligence and gross negligence
Customers and travelers may argue that CrowdStrike failed to test, validate, stage, monitor or control the update adequately. Gross-negligence allegations claim conduct beyond ordinary carelessness. Whether either theory succeeds depends on evidence, governing law and the parties’ contracts.
Contract claims
Enterprise customers may rely on service commitments, warranties, indemnities, representations or operational obligations. The contract may also contain liability caps, exclusions for consequential or lost-profit damages, arbitration provisions, notice requirements and force-majeure language. The wording and enforceability of those provisions can be decisive.
Software-defect theories
Delta alleged strict-liability product-defect claims. Applying traditional product-liability rules to software is legally contestable and jurisdiction-specific, particularly where the software is supplied as part of a service rather than as a standalone physical product.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Fraud and misrepresentation
Plaintiffs alleged that statements about testing, certification or reliability were misleading. Securities-fraud claims require more than proof that a product failed: investors must satisfy demanding pleading rules, including requirements concerning materiality, loss causation and the defendant’s state of mind.
Computer-trespass claims
Delta alleged that the update improperly accessed or interfered with its systems. Whether an authorized security update can support a trespass theory will depend on the agreement, the technical facts and applicable state law.
The shareholder securities case
The proposed shareholder class action, filed July 30, 2024, targeted CrowdStrike and certain officers. Investors who bought Class A shares during the proposed class period alleged that the company’s earlier statements about software testing and quality controls concealed material risks. The complaint sought unspecified damages. The filing and its described allegations are summarized in CrowdStrike’s SEC litigation disclosure.
A federal judge dismissed the case on January 14, 2026. Reporting on the decision said the plaintiffs had not adequately shown the intent to defraud required for their securities claims. That result does not mean the outage was harmless, that CrowdStrike’s processes were adequate in every respect, or that customer contract and negligence claims fail. It means this particular securities case did not meet the legal threshold to proceed on the pleaded theory.
Free tools Windows power users keep installed
One-click scans. No signup required.
The reported dismissal should therefore be read as a ruling on investor claims, not a general exoneration from outage-related liability.
Derivative suits against directors and officers
Three derivative actions were filed in September 2024, with CrowdStrike named as the nominal defendant and claims directed at officers and directors. The suits asserted fiduciary-duty, unjust-enrichment and federal securities-law theories. Additional derivative litigation was later consolidated.
Rank #2
- Compact and Efficient Design: The FortiGate 40F is designed for small to mid-sized businesses and enterprise branch offices, featuring a compact, fanless desktop form factor that ensures quiet operation and minimizes space usage.
- Robust Connectivity Options: Equipped with 5 GE RJ45 ports, including 1 WAN port and 4 internal ports, this model provides essential connectivity and flexibility for various network configurations in a small-scale environment.
- High-Performance Security: Offers up to 1 Gbps IPS throughput and 600 Mbps threat protection throughput, using Fortinet’s purpose-built security processor technology to deliver industry-leading performance and protection for SSL encrypted traffic.
- Advanced Threat Protection: Integrated with Fortinet’s AI-powered FortiGuard Labs, the FortiGate 40F offers comprehensive cybersecurity, identifying and mitigating both known and unknown threats to maintain robust security across your network.
- Simplified Management and Deployment: Features a user-friendly management console that provides comprehensive network automation and visibility, coupled with Zero Touch Integration with Fortinet’s Security Fabric for easy deployment.
CrowdStrike’s 2026 proxy materials state that the consolidated derivative lawsuits were dismissed by court order on April 16, 2026. The cited disclosure does not, by itself, establish every procedural detail of the order, such as whether dismissal was with or without prejudice.
The proxy statement is the company’s source for that status.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →Passenger and traveler claims
Passengers affected by canceled or delayed flights filed proposed class actions seeking compensation for expenses and related losses. A Delta-customer action publicized in August 2024 alleged that travelers were stranded and incurred out-of-pocket costs. A later consolidated complaint, filed December 6, 2024, asserted negligence and public-nuisance claims and sought a nationwide class plus subclasses in California, Ohio, Pennsylvania, Iowa and Nevada.
Passenger eligibility is not automatic. Certification requires plaintiffs to satisfy commonality, typicality, adequacy and workable damages requirements. Individual itineraries, refunds, replacement tickets, hotel and meal costs, employment losses, airline contracts and proof of causation can make a single class-wide damages method difficult. A claim against an airline also is not the same as a claim against CrowdStrike.
CrowdStrike’s latest surfaced filing continues to identify this passenger litigation. Its status should be checked against the relevant court docket before relying on a definitive statement about certification, settlement or dismissal.
The April 30, 2026 SEC filing describes the consolidated passenger complaint.
Delta v. CrowdStrike: the central unresolved commercial dispute
Delta filed its Georgia complaint on October 25, 2024. It alleged computer trespass, trespass to personalty, breach of contract, intentional misrepresentation or fraud by omission, strict-liability product defect, gross negligence and deceptive and unfair business practices.
Delta’s complaint attributed more than 8.5 million crashed Windows computers worldwide to the outage and alleged that Delta’s losses exceeded $500 million. Those are Delta’s estimates and allegations, not a judgment or an established recoverable amount. Reported coverage of the filing is available from Reuters via Investing.com; the complaint itself is available at this PDF.
CrowdStrike filed a motion to dismiss on December 16, 2024. The motion was denied on May 16, 2025, allowing the case to continue. That ruling did not decide whether Delta will prevail or how much, if anything, CrowdStrike must pay.
The case differs from the shareholder litigation because Delta claims direct commercial losses arising from a customer relationship. Key questions include:
Rank #3
- ✅【Professional Firewall PC MGSRN305】MOGINSOK Firewall Appliance Mini PC--MGSRN100, with Intel Processor Alder Lake-N100 (4C/4T,up to 3.4GHz) processor Intel UHD Graphics TDP only 6W, supported AES-NI With HDMI 2.1+DP 1.4 Support Dual 4K@60Hz Display, a fanless & silent professional firewall router pc with multi-functions like AES-NI, ESXI, Watchdog, Auto power on, RTC, PXE boot, Wake-on-LAN etc. bring you a secured and encrypted network environment.
- ✅【DDR5 Ram & PCIE 3.0 SSD】MOGINSOK Micro Firewall Appliance MGSRN100 with Barebone No Ram(1x Single slot support maximum 32GB DDR5 4800MHz) and No SSD(1*M.2 PICE 3.0 slot) configurations, you can install your own ram and ssd for DIY depends on your application.
- ✅【Professional OS installed】MGSRN305 Pre-installed pfsense plus 23.0X OS and you can install OPNsense, OpenWrt, Unbutun, windows 10 or 11 and other popular open-source software solutions on this Firewall Router. Which you can use it as an Firewall, Netgate, Softrouting, NAS, Firewall, ESXI, PVEvirtualization platform(support VT-X,VT-D).
- ✅【Intel I226 2.5GbE Network Card】This Firewall Router equipped with 4*Intel I226 Network card maximum up to 2.5GbE, bring you more faster and professional network usage(some system suppliers maybe have not released compatible driver to match yet, suggest to install newest version of following systems: pfSense 23.01(or 2.7.0), Untangle( via virtual machine) OPNsense 22.1, OpenWrt, ROS7, ESXI, Proxmox, CentOS etc).
- ✅【Quality With Warranty】If you have any questions on MOGINSOK Firewall Appliance MGSRN100, feel free to contact us(if you want to get the latest bios update, you can send us message via Amazon). We offered 12 Months warranty for it and WE'LL REPLY YOUR Questions within 12 hours(during Workdays).
- What the customer agreement permits, requires or excludes;
- Whether liability caps, warranty terms, indemnities or consequential-damage exclusions apply;
- Whether the update was authorized under the agreement;
- Which losses were proximately caused by the update rather than Delta’s own recovery decisions or other systems; and
- How refunds, passenger assistance, lost revenue, remediation, reputational harm and alleged future losses should be calculated.
CrowdStrike’s April 30, 2026 filing still listed the Delta proceeding among legal matters arising from the incident.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Defenses and obstacles that will shape recovery
- Contractual limits: A damages cap or exclusion may narrow recovery, although scope and enforceability can be contested.
- Causation: Claimants must connect specific losses to the update, separating direct effects from general disruption, third-party actions and recovery choices.
- Comparative fault: CrowdStrike may argue that a customer’s systems, procedures or response contributed to the claimed losses.
- Economic-loss rules: Some jurisdictions restrict tort recovery for purely financial losses, especially where a contract governs.
- Class certification: Travelers must show that common issues and a workable damages methodology predominate over individual questions.
- Standing and damages: Investors must link actionable statements to a compensable market loss and satisfy securities-law pleading standards.
- Choice of law: Contract-selected law and the laws of states connected to the parties or conduct may produce different outcomes.
- Insurance and indemnity: Cyber, business-interruption and vendor-indemnity arrangements may shift losses without resolving the underlying liability dispute.
What CrowdStrike has said and done
CrowdStrike acknowledged the faulty update and said it invested in software resilience, testing and customer-control improvements. It also described customer-commitment packages and settlement offers intended to address some impacts.
Its filings say those enhancements cannot guarantee the elimination of all future defects, errors or vulnerabilities. The company disclosed an immaterial amount of settlement offers to certain customers as of the quarter ended April 30, 2026. That does not mean all outage claims were settled or that every affected customer was compensated. CrowdStrike has disputed or defended claims and argued that some cases should be dismissed.
The company’s quarterly filing is available at this Form 10-Q PDF.
What the episode means for enterprise software risk
The litigation highlights governance questions for any widely deployed security platform:
- Can updates be staged by customer group, operating system and risk tier?
- Are validation, canary deployment, rollback and emergency-disable controls independent enough to catch a bad configuration?
- Can customers delay, approve or isolate updates without disabling essential protection?
- Do contracts allocate outage, consequential-loss, indemnity and business-interruption risk clearly?
- Do continuity plans include recovery when the security tool itself prevents endpoints from booting?
- Does insurance respond to vendor-caused interruption, and what waiting periods or exclusions apply?
- Does concentration in one security supplier create a systemic operational risk?
These are risk-management implications, not findings that any particular control failed beyond the facts alleged or disclosed in the proceedings.
What affected businesses and travelers should preserve
Anyone assessing a potential claim should preserve contemporaneous evidence and obtain advice about deadlines, forum and contract terms. Useful records include:
- Original bookings, cancellation notices, boarding records and refund documentation;
- Hotel, meal, transport, replacement-ticket and other expense receipts;
- Lost-work, payroll, revenue and customer-service records;
- Customer contracts, service-level agreements, warranties, indemnities and limitation clauses;
- Internal incident timelines, system logs, remediation records and decision approvals;
- Communications with CrowdStrike, airlines, vendors, insurers and brokers; and
- Evidence separating losses caused by the update from broader market or operational disruption.
This is general information, not legal advice. Limitation periods and available remedies vary by jurisdiction, contract and claim type.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Current bottom line
The 2024 outage produced distinct investor, director-and-officer, passenger and customer disputes. According to the latest cited disclosures, the shareholder case and consolidated derivative suits were dismissed. Passenger proceedings remained subject to procedural developments, while Delta’s commercial lawsuit remained an active, significant dispute after its motion-to-dismiss defeat. None of those procedural outcomes establishes a final liability amount, and the fact that more than 8 million devices were affected does not translate into 8 million plaintiffs.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




