Original Article Text

Click to Toggle View

Crowdstrike: Delta Air Lines refused free help to resolve IT outage. The legal spars between Delta Air Lines and CrowdStrike are heating up, with the cybersecurity firm claiming that Delta’s extended IT outage was caused by poor disaster recovery plans and the airline refusing to accept free onsite help in restoring Windows devices. After CrowdStrike pushed out a faulty update for its Falcon cybersecurity software, over 8.5 million Windows devices suddenly crashed and would no longer boot into the operating system. To fix the issues, IT staff were required to manually remove the bad update from Windows devices, leading to extended IT outages for companies with thousands of devices. Delta's outages lasted for five days as the company attempted to restore servers, leaving airline passengers stranded as thousands of flights were disrupted. Last week, Delta Air Lines CEO Ed Bastian appeared on CNBC where he explained that the airline lost $500 million dollars due to the IT outages, stating that CrowdStrike offered nothing but "free consulting advice to help us." Due to the massive revenue loss, Bastian said they had no choice but to sue CrowdStrike to protect their shareholders, customers, and employees. "So anyway, we have to protect our shareholders. We have to protect our customers, our employees--for the damage, not just to the cost, but the brand, the reputational damage, and the physical challenge," Bastian said in an interview on CNBC's SquawkBox. Delta hired litigator David Boies, who reportedly sent letters to CrowdStrike and Microsoft warning the companies to prepare for litigation around these outages. CrowdStrike's counsel Michael Carlinsky responded Sunday, rejecting the claims that the cybersecurity firm "was grossly negligent or committed willful misconduct" in regards to the faulty update or is solely responsible for Delta's extended IT outage. In the letter shared with BleepingComputer, the cybersecurity firm said they offered Delta free onsite assistance to help recover Windows devices and was ultimately told that it was not needed. "Within hours of the incident, CrowdStrike reached out to Delta to offer assistance and ensure Delta was aware of an available remediation," reads the letter from CrowdStrike's counsel, Michael Carlinsky. "Additionally, CrowdStrike's CEO personally reached out to Delta's CEO to offer onsite assistance, but received no response. CrowdStrike followed up with Delta on the offer for onsite support and was told that the onsite resources were not needed." CrowdStrike also questioned why Delta's competitors, who faced similar challenges, could restore operations quicker, implicating that faulty procedures and infrastructure were partly responsible for the airline's lengthy outages. The cybersecurity firm is now calling on Delta to "reconsider its approach". However, in light of the legal threats, CrowdStrike is now asking Delta to preserve data, emails, and communications related to the Falcon incident to be used in potential discovery during a lawsuit. When asked about CrowdStrike's letter, Delta referred us to Bastian's interview on CNBC. CrowdStrike shared the following statement with BleepingComputer about the letter from its lawyers. "The letter speaks for itself. We have expressed our regret and apologies to all of our customers for this incident and the disruption that resulted," CrowdStrike told BleepingComputer. "Public posturing about potentially bringing a meritless lawsuit against CrowdStrike as a long-time partner is not constructive to any party. We hope that Delta will agree to work cooperatively to find a resolution." CrowdStrike was recently sued by its investors in a class-action lawsuit claiming that the cybersecurity company knowingly made false statements about the quality of its products and procedures.

Daily Brief Summary

CYBERCRIME // Delta Sues CrowdStrike After Costly IT Outage and Rejected Help

CrowdStrike's software update caused over 8.5 million Windows devices to crash, preventing them from booting.

Delta Air Lines experienced a five-day IT outage, significantly disrupting flights and stranding passengers.

Delta's CEO claimed the outage resulted in a $500 million loss, leading to a lawsuit against CrowdStrike to protect stakeholders.

CrowdStrike offered Delta free onsite help to resolve the issue, which Delta reportedly declined.

Delta has hired high-profile litigator David Boies, signaling readiness for intense legal proceedings against CrowdStrike and possibly Microsoft.

CrowdStrike insists on its lack of gross negligence and disputes sole responsibility for Delta's prolonged outage.

The cybersecurity firm urged Delta to preserve all related communications for potential use in court, indicating escalating legal tensions.

Aside from Delta, CrowdStrike faces a class-action lawsuit from its investors, accusing the firm of making false claims about its product's reliability.