Ed Donohue Analyzes CrowdStrike Outage and Potential Liabilities in CLM Magazine
In The News | 1 min read
Jul 26, 2024
In a new article published by Claims Litigation Management (CLM) Magazine, Hinshaw partner Ed Donohue was among a group of professionals who analyzed the business impacts of a global Microsoft Windows outage triggered by a CrowdStrike software update distributed on July 19, 2024.
Donohue said the CrowdStrike "Blue Screen of Death" incident was comparable to a 2010 McAfee outage and likely resulted from a lack of proper quality assurance processes.
He then addressed whether CrowdStrike was vulnerable to lawsuits and if insurance policies might cover business interruption losses.
Donohue's full commentary is below:
The CrowdStrike shutdown was caused by an update intended to enhance Microsoft customer malicious activity sensors. It is relatively unusual for an error like this to remain undetected before it impacts end-user machines. A logic error such as this is generally caught sooner and resolved with a simple customer reboot. Here, the error affected individual Windows PCs, causing the so-called ‘Blue Screen of Death.’ That fix is manual and tedious, requiring the entry of a 48-character BitLocker Code.
A similar large shutdown was caused by a 2010 McAfee virus update. In both instances, the error was blamed on a lack of adequate internal quality assurance testing before launching the update.
However, CrowdStrike’s direct legal liability for the resulting economic loss is far from clear. CrowdStrike’s ‘Terms and Conditions’ (TAC) are robust in limiting its product warranties. ‘Click Wrap’ customer agreement forms such as this are generally upheld by the courts. The TAC disclaims any warranty for failures in its malware search products. The company agrees only to make best efforts to work around errors once detected. Though this TAC may be tested by some customers in court, the better initial strategy is for businesses to review their contingent business interruption insurance. Many contemporary commercial policies cover losses caused by such an incident.
- “CrowdStrike Event Cyber Losses Could Reach Into Billions” was published by Claims Litigation Management Magazine on July 25, 2024.
Featured Insights

Healthcare Alert
Aug 3, 2026
Fixing the Emergency Refill Trap: What California’s AB 1587 Means for Pharmacies

Consumer Crossroads: Where Financial Services and Litigation Intersect
Jul 30, 2026
Should Text Messages be Considered “Calls” Under the TCPA? The Seventh Circuit Says No

Healthcare Alert
Jul 30, 2026
California Courts Sharply Curtail the MICRA Damages Cap in Nursing Home Litigation

Insights for Insurers Alert
Jul 30, 2026
Analyzing a Couple of Cases Involving Exclusions in D&O Policies

In The News
Jul 29, 2026
Hinshaw Authors Contribute Two Articles in Latest Edition of the CCFL Quarterly Report

Webinar
Jul 28, 2026
Cathy Mulrow-Peattie and Sabrina Janeiro Present on Legal AI Technology

In The News
Jul 27, 2026
Scott Seaman Discusses How the Insurance Industry Contributed to the 2026 FIFA World Cup

Privacy, Cyber & AI Decoded Alert
Jul 27, 2026
Compliance Guidance for the New Vermont Data Privacy and Online Surveillance Act (VDPOSA)

Healthcare Alert
Jul 24, 2026
Q&A: Right to Electronic Monitoring Extended to Illinois Assisted and Shared Living Facilities

Press Release
Jul 23, 2026
Insurance Partner Christophe Burusco Joins Hinshaw in Los Angeles

In The News
Jul 16, 2026
Jennifer Driscoll Anticipates Epic Battle Between “Titans of the Antitrust Bar”

