← Back to the 100 Software Failures Timeline
Case Study #32 — Top 100 Software Failures

CrowdStrike Falcon update causes global IT outage

About 8.5 million Windows devices worldwide crashed simultaneously, disrupting airlines, hospitals, banks, broadcasters and emergency services; total global losses were estimated at over $10 billion, making it one of the largest IT outages in history.

2024-07-19
When it happened
Cybersecurity Software / Cross-Sector IT
Sector
#32 of 100
Ranked by documented impact
01 — What Happened

The damage was public. The root cause was preventable.

About 8.5 million Windows devices worldwide crashed simultaneously, disrupting airlines, hospitals, banks, broadcasters and emergency services; total global losses were estimated at over $10 billion, making it one of the largest IT outages in history.

Cybersecurity Software
Sector affected
2024-07-19
Date of the event
#32
Rank in the Top 100 Software Failures
2
Distinct root-cause clauses identified below
02 — The Root Cause

What the software actually got wrong

A faulty content-validation logic update to CrowdStrike's Falcon Sensor security software passed internal testing but caused an out-of-bounds memory read on Windows systems, triggering an immediate crash (blue screen) on boot. Not an attack — a flawed software update from a security vendor.

01Root Cause

A faulty content-validation logic update to CrowdStrike's Falcon Sensor...

What Happened

A faulty content-validation logic update to CrowdStrike's Falcon Sensor security software passed internal testing but caused an out-of-bounds memory read on Windows systems, triggering an immediate crash (blue screen) on boot.

How Requs AI Catches This

Requs AI Edge Case flags this exact pattern at the requirements and architecture stage — before a single line of code implementing it exists — so the assumption behind it gets challenged while it is still cheap to fix.

02Root Cause

Not an attack — a flawed software update from...

What Happened

Not an attack — a flawed software update from a security vendor.

How Requs AI Catches This

Requs AI Software FMEA traces this failure mode back to the system-level hazard it feeds, tagging it against the Common Defect Enumeration so it surfaces in review instead of in the field.

03 — How This Gets Caught Before It Happens

Beyond code coverage and "shall" testing

Root causes like this one rarely show up in code coverage or requirements-compliance testing, because nobody wrote a requirement anticipating the specific edge case that broke. Requs AI Edge Case and Requs AI Software FMEA are built to surface exactly this class of overlooked failure mode — before the software is written.

Requs AI Edge Case

Surfaces this before code exists

Identifies edge cases like this one at requirements and architecture time, using the Common Defect Enumeration to catalog failure patterns seen across hundreds of real-world software failures — including this one.

Requs AI Software FMEA

Connects the failure mode to the hazard

Traces this class of root cause directly to the system-level hazard it can produce, so a defect pattern like this one gets flagged during design review instead of after it ships.

Find the overlooked root causes before they ship.

Schedule a demonstration, or explore how Requs AI Edge Case and Software FMEA use the Common Defect Enumeration.