Jefferies analyst Joseph Gallo wrote on July 31, 2024, that CrowdStrike was unlikely to be held liable for Delta Air Lines’ estimated $500 million loss from the July 19 software outage. That was an analyst forecast—not a court ruling. Delta filed suit in Georgia on October 25, 2024, and CrowdStrike reported in an April 30, 2026 SEC filing that discovery was still ongoing after a court dismissed some claims and allowed others to proceed.
What happened in the July 19, 2024 outage?
CrowdStrike distributed a faulty content update for its Falcon cybersecurity platform. A validation error allowed the problematic update to reach Windows systems, causing crashes and widespread operational disruption. The event was a defective software-update incident, not a malicious cyberattack.
CrowdStrike said approximately 8.5 million Windows devices were affected worldwide. Airlines, hospitals, emergency services, financial institutions and other organizations reported interruptions. Delta said the disruption cost it approximately $500 million, including lost revenue, canceled flights, hotels and customer compensation. That figure is Delta’s estimate, not a court-determined damages award. Contemporaneous reporting said Delta canceled nearly 7,000 flights over five days.
CRN’s account of the analyst note and outage also cited a Parametrix estimate of about $5.4 billion in direct losses for Fortune 500 companies. That was an outside estimate, not a judicial finding.
#1 Best Overall
What did the Jefferies analyst predict?
Gallo’s July 31 note addressed a possible Delta action before Delta had filed one. He argued that CrowdStrike was unlikely to be held liable and probably would not have to reimburse customers for the outage. His reasoning centered on expected contractual protections and the difficulty of proving that all of Delta’s claimed losses were legally recoverable.
Gallo did not suggest the incident would be cost-free. He expected litigation expense, management distraction, headline risk and possible pressure on customer relationships. He also thought other affected companies might consider claims, in part to show their own customers that they were seeking compensation. Jefferies expected “little churn” based on customer checks but reduced its CrowdStrike annual recurring-revenue estimates by 1% for fiscal 2025 and fiscal 2026.
Those were equity-research opinions, not legal advice and not an assessment based on a publicly disclosed copy of the complete Delta-CrowdStrike contract.
What Delta actually sued CrowdStrike for
Delta filed its complaint in Fulton County Superior Court, Georgia, on October 25, 2024. According to CrowdStrike’s SEC disclosure, Delta alleged:
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Rank #2
- computer trespass;
- trespass to personalty;
- breach of contract;
- intentional misrepresentation or fraud by omission;
- strict-liability product defect;
- gross negligence; and
- deceptive and unfair business practices.
Delta sought monetary damages in an unspecified amount, attorneys’ fees and unspecified punitive damages. In public accounts and its complaint, Delta alleged that CrowdStrike distributed an inadequately tested update, failed to use appropriate safeguards, caused a catastrophic outage and did not provide adequate recovery assistance. Those are Delta’s allegations, not established facts. The Associated Press summarized the complaint; the filed pleading is available at this PDF.
Why a $500 million recovery would be difficult
The contract may limit available damages
Enterprise technology agreements often disclaim warranties, cap liability at a multiple of fees paid and exclude consequential losses such as lost profits, lost revenue, business interruption and reputational harm. They may also contain forum, dispute-resolution, indemnity and customer-mitigation terms.
The decisive issue is the operative Delta-CrowdStrike agreement: what it promised, which law governs, whether a cap applies and whether exceptions exist for fraud, gross negligence or willful misconduct. It would be inaccurate to say the contract definitively protected CrowdStrike without the agreement and the court’s interpretation of its clauses.
Causation must be proved in detail
Delta would need to connect the defective update to each category of loss. CrowdStrike can argue that the update was the initial trigger but not the sole cause of the airline’s prolonged disruption. Possible issues include Delta’s recovery procedures, crew scheduling, system redundancy, operational decisions and mitigation efforts.
Recommended Free Tools
Rank #3
Technical analysis identified Delta’s crew-scheduling problems and recovery delays as important contributors to the length of the disruption. That is operational context, not a judicial finding that Delta caused its own losses. The legal question is how a court allocates responsibility between the triggering software failure and the events that followed.
Economic-loss and tort theories complicate the case
Delta pleaded tort claims alongside contract claims. The court may have to consider whether Georgia law permits tort recovery where the relationship is fundamentally contractual, whether alleged fraud or gross negligence can avoid contractual limits, whether strict product liability fits a cloud-delivered cybersecurity service, and whether purely financial losses are recoverable under each theory.
Ordinary negligence, gross negligence, intentional misconduct and breach of an express contractual promise carry different proof requirements. Punitive damages likewise require more than showing an ordinary breach.
What CrowdStrike has argued
CrowdStrike has publicly said it offered Delta assistance during the outage and that Delta did not accept or sufficiently use some of the help offered. It has also disputed claims about how the update interacted with the Windows kernel and challenged Delta’s legal theories.
Rank #4
The extent and timing of assistance are disputed factual matters. They require discovery rather than a conclusion that either side’s account is correct. CrowdStrike moved to dismiss Delta’s state-court complaint on December 16, 2024.
Procedural timeline
| Date | Event |
|---|---|
| July 19, 2024 | A faulty CrowdStrike content update causes widespread Windows failures. |
| July 31, 2024 | Jefferies analyst Joseph Gallo says CrowdStrike is unlikely to be liable in a potential Delta action. |
| August 2024 | Delta signals it will seek compensation and hires attorney David Boies, according to contemporaneous reporting. |
| October 25, 2024 | Delta files its Georgia state-court complaint. CrowdStrike separately files a federal declaratory-judgment action against Delta. |
| November 25, 2024 | CrowdStrike voluntarily dismisses its federal action without prejudice. |
| December 16, 2024 | CrowdStrike files its motion to dismiss Delta’s state-court case. |
| May 16, 2025 | The Georgia court grants the motion in part and denies it in part. |
| April 30, 2026 | CrowdStrike’s SEC filing says discovery is ongoing. |
The latest procedural account appears in CrowdStrike’s April 30, 2026 SEC filing. The earlier federal case’s dismissal without prejudice was not a merits ruling clearing CrowdStrike; it was CrowdStrike’s separate declaratory action. The docket is available at Justia.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What the partial dismissal means
A motion to dismiss tests whether pleaded claims can proceed, assuming the complaint’s well-pleaded allegations for that stage. Granting the motion in part and denying it in part means some theories were dismissed while others survived. It does not establish that Delta proved a breach, causation or damages, and it does not establish that CrowdStrike escaped liability.
Discovery can change the factual record by producing the contract, update-testing records, internal communications, assistance logs, system data and detailed damages calculations. No final liability ruling or damages award was identified in the latest company filing.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problemsBest Value
Why Delta’s prolonged disruption matters
The initial technical failure affected many companies, but Delta experienced an unusually prolonged operational disruption. That distinction matters financially and legally. A court could separate direct restoration and response costs from lost ticket revenue, refunds, hotels, customer payments, crew and aircraft repositioning, IT remediation, reputational harm and other consequential categories.
Delta would likely need granular evidence for each category, while CrowdStrike could challenge remoteness, duplication, mitigation and the inclusion of losses excluded by contract. The fact that Delta’s recovery took longer than that of some other airlines does not, by itself, resolve responsibility.
What the case means for software buyers and investors
Contracts deserve operational scrutiny
Customers should examine liability caps, consequential-damage exclusions, service commitments, update obligations, rollback rights, indemnities, insurance requirements, audit rights and dispute forums before signing a critical-security contract.
Update governance is a resilience issue
Staged deployment, independent validation, rollback capability, recovery playbooks and offline or redundant systems can reduce the business impact of a vendor update. They may also become evidence in a later dispute over mitigation and comparative responsibility.
Vendor concentration creates correlated risk
A widely deployed endpoint-security platform can create simultaneous exposure across industries. Cyber, technology-errors-and-omissions, business-interruption and contingent-business-interruption insurance may affect who ultimately bears losses, but insurance does not determine whether CrowdStrike is legally liable.
Other customers will have different cases
Any additional claims would depend on each customer’s contract, jurisdiction, deployment choices, operational losses and evidence. The Delta case cannot automatically establish a rule for every organization affected by the update.
Bottom line on the analyst’s forecast
Gallo may have been directionally right that contractual limits, consequential-damage exclusions and difficult causation proof could make a $500 million recovery hard to obtain. But “unlikely to be liable” was a July 2024 prediction, not a legal conclusion. Delta did sue, some claims survived CrowdStrike’s dismissal motion, and the latest verified disclosure said discovery was continuing. The outcome remained unresolved.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




