CrowdStrike Faces Legal Battles After Major Outage

CrowdStrike is facing lawsuits after a major outage disrupted services, potentially causing over $5 billion in losses. However, a limitation of liability clause may protect CrowdStrike from paying significant damages.

CrowdStrike Faces Legal Battles After Major Outage

Key Takeaways: 

  • CrowdStrike is facing multiple lawsuits after a massive outage disrupted services for major companies, including Delta Air Lines.
  • The outage is estimated to have caused more than $5 billion in losses, The Guardian reports.
  • CrowdStrike's limitation of liability clause may save it from having to pay massive damages.

CrowdStrike, a leading cybersecurity firm, is facing a wave of lawsuits following a significant service outage on July 19, 2024. 

The incident, which lasted several hours, disrupting operations for several high-profile clients, including airlines, financial services, healthcare providers and more, was caused by a faulty software update that crashed millions of Microsoft Windows computers. The outage is believed to have caused more than $5 billion in losses, according to The Guardian.

The Lawsuits

  • Delta Air Lines: On July 29, Delta informed CrowdStrike and Microsoft of its intent to sue over the $500 million it claims to have lost as a result of the outage. Delta was meanwhile hit with a proposed class action alleging the company failed to properly refund fliers or provide passengers with promised meal, hotel, and transportation vouchers after the outage.

  • Shareholder Class Action: A class action lawsuit has been filed by law firm Labaton Keller Sucharow on behalf of CrowdStrike shareholders, claiming they were misled over the company’s software testing practices. 

  • Small Business Class Action: Another law firm, Gibbs Law Group, has announced it is looking into bringing a class action on behalf of small businesses affected by the outage.

CrowdStrike's Response

CrowdStrike has issued a public statement acknowledging the outage and the impact on its clients. The company emphasized that it worked swiftly to restore services and has taken steps to prevent similar incidents in the future. 

  • On the shareholder class action: “We believe this case lacks merit, and we will vigorously defend the company,” CrowdStrike told WIRED.

  • On the Deta lawsuit: In a letter to Delta’s legal counsel, a legal representative for CrowdStrike said that the company “strongly rejects any allegation that it was grossly negligent or committed willful misconduct.”  Kevin Benacci, senior director of corporate communications at CrowdStrike, told WIRED that Delta’s legal threats should be seen as “public posturing” that “is not constructive to any party.”

The Limitation of Liability Clause

CrowdStrike's contracts with its clients likely include a limitation of liability clause, which could significantly cap its financial responsibility for the damages claimed by the plaintiffs. Such clauses are designed to protect service providers from excessive financial exposure in the event of unforeseen incidents, such as the recent outage.

However, the enforceability of these clauses can be contentious, especially when the outage causes widespread damage or is seen as a result of gross negligence. Plaintiffs may argue that the severity of the outage and its impact on critical infrastructure like air travel should override the contractual limitations.

Those hoping to recover financial losses will need to find creative ways to frame their cases against CrowdStrike, and “the amount of money they could recover is likely to be severely limited by the limitation clause,” Paul MacMahon, associate professor of law at the London School of Economics and Political Science, told WIRED. 

To recover a more significant sum, Delta and other customers would have to convince a court that the clause is inherently unfair and therefore unenforceable, McMahon said.

Legal and Financial Implications

For the broader cybersecurity industry, this case could have far-reaching implications, especially regarding how contracts are structured and the extent to which service providers can limit their liability in the event of significant outages.

Although CrowdStrike has conceded to causing the outage and billions of dollars’ worth of damage, the cost may be ultimately borne predominantly by its customers and other affected businesses. 

To prevent software providers from shifting liability for coding blunders onto customers and the businesses that depend on them, members of the IT industry are calling for regulatory reform. 

Brian Fox, CTO at software supply chain company Sonatype, told WIRED, “Reform around liability is probably the only thing that is going to make businesses sit up and pay attention to things that engineers have been highlighting forever: We need to do a better job with architecture, testing, and security.” 

Customer Stories

See how leading enterprise in-house teams have scaled smarter with Legal.io's high-caliber flex talent.

More from Legal.io


Non-Disclosure Agreement Checklist
Non-Disclosure Agreement Checklist

This checklist provides an overview of issues to take into account when preparing a non-­‐disclosure agreement. It provides an easy way to ensure that no important issues are overlooked.

Nov 13, 2017
Read More
Wilson Sonsini Divests Legal Tech Subsidiary SixFifty to HR Sector Buyer

Wilson Sonsini sells its legal tech arm SixFifty to an unnamed human capital firm, with Paychex rumored as the buyer. Terms undisclosed.

Jul 30, 2025
Read More
New York Attorney General Files Lawsuit Against Crypto Firms for Fraud
New York Attorney General Files Lawsuit Against Crypto Firms for Fraud

Lawsuit filed against cryptocurrency companies for allegedly defrauding investors of more than $1 billion.

Oct 17, 2023
Read More
NetDocuments to Acquire OpenText’s eDOCS Legal Document Platform

NetDocuments will acquire OpenText’s eDOCS system, expanding its cloud-based legal DMS portfolio. The deal, pending regulatory approval, is expected to close in early 2026.

Oct 07, 2025
Read More
California Passes AI Training Data Transparency Bill
California Passes AI Training Data Transparency Bill

The California legislature has passed Bill AB 2013, mandating developers of artificial intelligence systems to disclose the data used to train their models. The bill is now going to Gov. Gavin Newsom for approval.

Aug 29, 2024
Read More
Ready to hire?

Schedule a free consultation to discuss your hiring needs.

Free 15-min consultation
Legal.io Platform
5 star reviews
Hiring made smarter

Easy-to-use platform for hiring legal talent, managing spend, and optimizing your panel — plus an average savings of 50%.

Need Immediate Help?

Submit a hiring request and let our experts handle the entire process for you.