A defective CrowdStrike Falcon sensor content update on 19 July 2024 caused Windows systems to enter crash loops globally, disrupting aviation, finance, healthcare, education, government services and other sectors, including multiple organizations in the Netherlands. The faulty channel file was identified as C-00000291*.sys stamped 0409 UTC; versions stamped 0527 UTC or later were valid. The incident prevented an estimated 8.5 million computers from booting and demonstrated how a failure in a widely deployed security product can create systemic disruption without a malicious attack.
Organizations were advised to restart affected hosts to obtain the corrected channel file, while crash-looping devices required recovery-mode or Safe Mode remediation to remove or rename the faulty CrowdStrike driver, with separate considerations for BitLocker-protected and RAID-configured systems. Cloud providers including AWS, Microsoft Azure and Google Cloud issued recovery guidance for affected Windows virtual machines. Dutch authorities cited the outage in the 2024 Cyber Security Assessment as evidence of digital-monoculture risk and the need to prepare for major disruptions caused by technical failures and human error as well as cyberattacks.

See attribution, scope, and your downstream exposure.
6 events from the most recent confirmed update back to the earliest known activity.
The NCSC identified the faulty channel file as C-00000291*.sys with a 0409 UTC timestamp and advised restarting affected hosts to obtain a corrected file. For systems in crash loops, it directed administrators to boot into Safe Mode and delete or rename the driver file, while cloud providers issued recovery guidance for affected virtual machines.
On July 19, a faulty CrowdStrike Windows sensor/agent update caused widespread outages across organizations worldwide, including Dutch organizations and sectors such as finance, healthcare, education, government services, and aviation. The outage caused affected systems to crash or fail to boot and led to major flight delays; CSBN 2024 later reported that 8.5 million computers were unable to boot.
The Dutch cabinet presented the National Cybersecurity Strategy (NLCS), intended to create a digitally secure and resilient Netherlands.
The Dutch government submitted an NLCS progress report to the House of Representatives alongside the Cyber Security Assessment Netherlands 2024 (CSBN 2024). The assessment warned that state actors were intensifying and broadening cyber operations and that digital monocultures could magnify the effects of technical failures or attacks.
The Netherlands conducted the public-private ISIDOOR IV exercise to strengthen preparedness for large-scale outages and digital incidents.
The Netherlands published information about advanced malware that China used to spy on computer networks at the Dutch Ministry of Defence.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
3 references tracked. Mallory keeps watching after this page renders.
oligo.security
Open sourcencsc.nl
Open sourcencsc.nl
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.