Malware Cloaked as Fixes and Updates Exploit Global Crowdstrike Outage

August 5, 2024

INCIDENT

Threat actors are exploiting the massive business disruption from CrowdStrike's glitchy update on Friday to target companies with data wipers and remote access tools. As businesses are looking for assistance to fix affected Windows hosts, researchers and government agencies have spotted an increase in phishing emails trying to take advantage of the situation. CrowdStrike says it "is actively assisting customers" impacted by the recent content update that crashed millions of Windows hosts worldwide. The company advises customers to verify that they communicate with legitimate representatives through official channels since "adversaries and bad actors will try to exploit events like this."

The CrowdStrike crash was caused by human error.

Incident Date

July 30, 2024

Estimated Cost


No cost values disclosed.

Victims

Type of Malware

Threat Source

No threat source identified