Ed Donohue Analyzes CrowdStrike Outage and Potential Liabilities in CLM Magazine
In The News | 1 min read
Jul 26, 2024
In a new article published by Claims Litigation Management (CLM) Magazine, Hinshaw partner Ed Donohue was among a group of professionals who analyzed the business impacts of a global Microsoft Windows outage triggered by a CrowdStrike software update distributed on July 19, 2024.
Donohue said the CrowdStrike "Blue Screen of Death" incident was comparable to a 2010 McAfee outage and likely resulted from a lack of proper quality assurance processes.
He then addressed whether CrowdStrike was vulnerable to lawsuits and if insurance policies might cover business interruption losses.
Donohue's full commentary is below:
The CrowdStrike shutdown was caused by an update intended to enhance Microsoft customer malicious activity sensors. It is relatively unusual for an error like this to remain undetected before it impacts end-user machines. A logic error such as this is generally caught sooner and resolved with a simple customer reboot. Here, the error affected individual Windows PCs, causing the so-called ‘Blue Screen of Death.’ That fix is manual and tedious, requiring the entry of a 48-character BitLocker Code.
A similar large shutdown was caused by a 2010 McAfee virus update. In both instances, the error was blamed on a lack of adequate internal quality assurance testing before launching the update.
However, CrowdStrike’s direct legal liability for the resulting economic loss is far from clear. CrowdStrike’s ‘Terms and Conditions’ (TAC) are robust in limiting its product warranties. ‘Click Wrap’ customer agreement forms such as this are generally upheld by the courts. The TAC disclaims any warranty for failures in its malware search products. The company agrees only to make best efforts to work around errors once detected. Though this TAC may be tested by some customers in court, the better initial strategy is for businesses to review their contingent business interruption insurance. Many contemporary commercial policies cover losses caused by such an incident.
- “CrowdStrike Event Cyber Losses Could Reach Into Billions” was published by Claims Litigation Management Magazine on July 25, 2024.
Featured Insights

In The News
Aug 24, 2026
David Schultz Reviews a Humorous—But Important—FDCPA Procedural Ruling

Press Release
Aug 20, 2026
115 Hinshaw Lawyers Recognized in 2027 Editions of The Best Lawyers in America® and Ones to Watch®

Press Release
Aug 20, 2026
Hinshaw’s Landmark Tower Client Project Receives 2026 Top Projects Award

Press Release
Aug 19, 2026
Fernando Rivera-Maissonet Elected as HNBA Region II Governor and Board of Governors Member

Employment Law Observer
Aug 17, 2026
Massachusetts’ First Paid Family Medical Leave Act Verdict Yields $4.75 Million Award

Press Release
Aug 13, 2026
Lauren Campisi Recognized as a 2026 BTI Client Service All-Star by BTI Consulting Group

Consumer Crossroads: Where Financial Services and Litigation Intersect
Aug 13, 2026
How Will Banks Be Impacted by the Proposed Regulation O Amendments?

Press Release
Aug 12, 2026
William Cook Honored With the Distinguished Service Award by the Chicago Bar Association

Webinar
Aug 12, 2026
John Ryan Presents on "Understanding what is Covered Under the TCPA Today"

In The News
Aug 12, 2026
Scott Seaman Analyzes California’s New Pleading Standards for Excess Insurance Policy Claims


