The Question of Liability

When the CrowdStrike outage hit on July 19, 2024, one thing was established quickly: this wasn't a cyberattack. CrowdStrike and government cybersecurity authorities across multiple countries confirmed early on that the failure came from CrowdStrike's own update process, not from any outside intrusion. That distinction mattered legally, since it moved the entire question of who bears responsibility out of criminal law and into the much narrower territory of contract and tort law. In Australia alone, business leaders estimated the financial hit at more than A$1 billion, a figure widely reported at the time and repeated in legal commentary on the incident.

Once criminal conduct was ruled out, the first place affected businesses would naturally look is their contract with CrowdStrike itself. That search runs into a wall quickly. Like most enterprise software vendors, CrowdStrike's terms and conditions include a limitation of liability clause capping the company's exposure at the fees the customer actually paid, which for many organizations meant the maximum possible recovery through contract law was a refund, regardless of how much the outage actually cost them.

Looking Beyond Contract Law

With contractual redress limited, legal commentary in the days after the outage pointed toward tort claims, particularly negligence, as a more promising avenue. Writing in The Conversation shortly after the incident, legal academic Michael Adams laid out the case: negligence claims trace back to the 1932 case Donoghue v Stevenson, which established that a duty of care can exist independent of any contract between the parties. That principle is what would let an affected business argue CrowdStrike owed it a duty of care even without a direct contractual relationship, such as a company harmed through a supplier that used CrowdStrike's software rather than through its own direct account.

Adams also cited a client note from the New Zealand law firm Russell McVeagh, which raised a further angle: organizations whose own lack of preparedness made the outage worse for them could face claims from their own shareholders or face liability through their own directors, separate from any claim against CrowdStrike itself. In other words, the outage created potential legal exposure running in more than one direction at once, toward CrowdStrike from its customers, and toward some of those customers from their own investors.

What Actually Happened Next

In the time since, several of the legal paths raised in that early commentary have actually played out, with mixed results. CrowdStrike's own investors filed a securities class action, led by New York State Comptroller Thomas DiNapoli, alleging the company concealed inadequate software testing practices ahead of the outage. The suit pointed to a 32% drop in CrowdStrike's stock over the 12 days following the incident, wiping out roughly 25 billion dollars in market value. In January 2025, a federal judge dismissed the case, ruling that the shareholders had not plausibly shown CrowdStrike or its executives acted with intent to defraud investors.

Delta Air Lines pursued a separate and still-active claim directly against CrowdStrike, seeking more than 500 million dollars in damages, a case covered in more detail in Kraken IO's companion piece on the outage itself. Between the dismissed shareholder suit and Delta's ongoing negligence claim, the practical picture a year on is that direct contractual limitation clauses have held up well for CrowdStrike. In contrast, claims requiring proof of intent or fraud have struggled, and negligence-based claims outside the contract remain the more contested and unresolved terrain.

The Insurance Gap

The economic scale of the outage exposed a similar gap on the insurance side. Cyber insurance analytics firm Parametrix estimated the outage cost Fortune 500 companies alone 5.4 billion dollars in direct losses. Separate estimates from reinsurance broker Guy Carpenter and risk analytics firm CyberCube put total insured losses across that same population at somewhere between 300 million and 1.5 billion dollars, meaning the large majority of the financial damage went uncovered by any policy. Traditional business interruption coverage is often written around malicious events, and a non-malicious software failure like this one didn't cleanly fit many existing policies, a mismatch that has since prompted insurers and policyholders to revisit how these policies are worded.

Conclusion

The legal aftermath of the CrowdStrike outage turned out to be less about any single sweeping lawsuit and more about a patchwork of separate claims, each running into the specific limits of the legal theory behind it. Contractual limitation clauses did their job for CrowdStrike. A fraud-based claim from shareholders didn't survive scrutiny. A negligence-based claim from one of its largest affected customers is still working through the courts. That pattern is likely to repeat with future incidents of this kind: the type of claim matters as much as the scale of the damage in determining whether anyone actually recovers anything.

Sources

Adams, Michael. "The CrowdStrike outage caused chaos for business – could we see a class action?" The Conversation. theconversation.com/the-crowdstrike-outage-caused-chaos-for-business-could-we-see-a-class-action-235215

Russell McVeagh, "The largest IT outage in history: CrowdStrike's routine software update." russellmcveagh.com/insights-news/the-largest-it-outage-in-history-crowdstrikes-routine-software-update

Reuters, "CrowdStrike defeats shareholder lawsuit over huge software outage." reuters.com/legal/litigation/crowdstrike-defeats-shareholder-lawsuit-over-huge-software-outage-2025-01-14

BBC News, "CrowdStrike sued by shareholders over global outage." bbc.com/news/articles/cy08ljxndr4o

Bloomberg, "Billions in Damages From CrowdStrike Outage to Go Uninsured." bloomberg.com/news/articles/2024-08-02/billions-in-damages-from-crowdstrike-outage-to-go-uninsured

Axios, "Fortune 500 lost an estimated $5.4B in CrowdStrike outage." axios.com/2024/07/24/fortune-500-crowdstrike-outage-impact