Segment courtesy of NBC10 Philadelphia.

Quick answer

On July 19, 2024, cybersecurity vendor CrowdStrike pushed a faulty update (Channel File 291) to its Falcon software, crashing roughly 8.5 million Windows devices worldwide with the "Blue Screen of Death" and boot loops. It was not a cyberattack - it was a defective software update. SEVN-X CEO Matt Barnett broke down what happened, and why it will happen again, live on NBC10 Philadelphia.

When millions of people turned on their computers on the morning of Friday, July 19, 2024, they were met with the dreaded Blue Screen of Death. Flights were grounded, hospitals rescheduled procedures, banks and broadcasters went dark, and businesses in nearly every industry ground to a halt. SEVN-X CEO Matt Barnett sat down with NBC10 Philadelphia as the chaos was still unfolding to explain what was happening and what it meant.

What happened in the CrowdStrike outage?

CrowdStrike Falcon is endpoint protection software that runs deep inside the Windows operating system to watch for malicious activity. Several times a day, CrowdStrike ships small configuration updates to that software. On July 19, one of those updates - Channel File 291 - contained a logic error. When the Falcon sensor tried to read it, the error crashed Windows itself, sending machines into a Blue Screen of Death and, in many cases, an endless reboot loop.

Because Falcon runs at such a privileged level, one bad file was enough to take down the entire machine. Around 8.5 million Windows devices were affected - less than 1% of all Windows machines, but concentrated in the enterprises that run critical services, which is why the real-world impact was so severe. Mac and Linux systems were untouched.

Incident timeline

When What happened
Jul 19, 2024 - 04:09 UTC CrowdStrike pushes the faulty Channel File 291 update to Falcon sensors on Windows.
Within minutes Roughly 8.5 million Windows devices crash into the Blue Screen of Death and boot loops worldwide.
Jul 19, 2024 - 05:27 UTC CrowdStrike identifies the error and reverts it - but machines that already pulled the update stay down.
Hours to days later Teams remediate machine by machine - booting into Safe Mode, deleting the bad file, wrestling with BitLocker recovery keys.
Aftermath Widely called the largest IT outage in history. CISA warns of phishing campaigns exploiting the event; CrowdStrike later testifies before Congress.

What Matt Barnett told NBC10

Matt's core message was that bugs like this are expected in software - but not at this scale. Modern software goes through rigorous testing so new bugs are not introduced, and occasionally one slips through anyway. In this case, the defect was severe enough to freeze machines outright or trap them in a reboot loop.

"As the world of vendors shrinks and people consolidate under these giant organizations, the potential for this is going to continue to increase. I think you're going to see more of these in the future." - Matt Barnett, CEO, SEVN-X

He also flagged a second-order risk that most people were not thinking about yet: attackers exploiting the confusion. Matt warned viewers to watch for phishing scams posing as official fixes. That call aged well - within hours, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued its own alert about threat actors using the outage as phishing bait. When your CEO calls the follow-on attack on live television before the federal warning lands, that is not luck - that is knowing the playbook.

Why could one update take down the world?

The uncomfortable answer is concentration. A small number of vendors now sit underneath a huge share of the world's critical systems. When everyone runs the same software at the same privileged level, a single flawed file can cascade across airlines, hospitals, and banks at the same moment. That is not a CrowdStrike problem specifically - it is the structural risk of a consolidated technology supply chain, and it is exactly the trend Matt pointed to on air. The outage was a preview, not a one-off.

How can your organization prepare for the next one?

You cannot control your vendors' release process, but you can control how hard the next bad update hits you. Practical steps:

  • Stage rollouts where you can. Where a vendor allows phased or delayed update rings, use them so a bad release hits a test group first, not your whole fleet.
  • Know your vendor concentration. Map which single points of failure sit under your critical systems, so a vendor incident does not surprise you.
  • Test your recovery, do not assume it. The pain here was the manual, machine-by-machine cleanup. A documented and tested recovery plan is the difference between hours and days. (See our breakdown of the NIST CSF Recover function.)
  • Expect the phishing wave. Every major outage is followed by scammers offering "fixes." Brief your team before it happens.
  • Rehearse the decision-making. A tabletop exercise surfaces the gaps in your response before a real event does.

Frequently asked questions

Was the CrowdStrike outage a cyberattack?

No. It was a defective software update, not malware or a hack. A logic error in a CrowdStrike Falcon configuration file (Channel File 291) crashed the Windows machines running it.

How many devices were affected?

Microsoft estimated roughly 8.5 million Windows devices - less than 1% of all Windows machines, but heavily concentrated in enterprises running critical services, which magnified the impact.

Why did recovery take so long?

CrowdStrike reverted the update quickly, but machines that had already crashed needed hands-on repair - booting into Safe Mode or the Windows Recovery Environment to delete the bad file. Encrypted drives requiring BitLocker recovery keys made it slower still.

Could an outage like this happen again?

Yes. As Matt Barnett noted on NBC10, vendor consolidation means more of the world depends on the same handful of providers, so the potential for large-scale outages keeps rising. Preparation - not prevention alone - is the realistic defense.

Key takeaways

  • A faulty CrowdStrike update - not a cyberattack - crashed ~8.5 million Windows devices on July 19, 2024.
  • One privileged file was enough to trigger a global outage, exposing the risk of vendor concentration.
  • SEVN-X CEO Matt Barnett predicted both repeat outages and phishing fallout on NBC10, ahead of the federal warning.
  • Tested recovery plans and rehearsed response are what limit the damage next time.

Is your business ready for the next outage?

The next bad update or vendor incident is a matter of when, not if. SEVN-X helps organizations pressure-test their resilience through incident response planning, tabletop exercises, and ransomware readiness. Our goal is to help you Achieve Better Cybersecurity.

Meet with an expert

Featuring Matt Barnett, CEO of SEVN-X. Original segment aired on NBC10 Philadelphia.