The Times Australia
Business and Money
The Times Real Estate

.

The CrowdStrike outage caused chaos for business – could we see a class action?

  • Written by Michael Adams, Professor of Corporate Law & Academic Director of UNE Sydney campus, University of New England
Graphic showing 'terms of use' floating above a laptop screen

Until last Friday, many businesses hadn’t really dealt with anything quite like the speed and severity of the CrowdStrike IT outage.

Being forced to stop operations is costly. Some estimates[1] put the damage bill from the outage at more than A$1 billion in Australia alone.

As they continue to tally the losses, it’s only natural that affected businesses will be asking who is legally responsible, and whether there’ll be any compensation.

These are great questions, but from a legal point of view the answers will be complex.

Both CrowdStrike and various government cybersecurity authorities were quick to declare[2] that the event was not the result of any criminal behaviour such as a cyberattack or other hacking.

This means the laws relating to these matters fall within the jurisdiction of civil law – in particular, the law of contracts and the law of torts.

Exclusion clauses

CrowdStrike’s security software is used by a wide range of companies and other large organisations. Microsoft, whose tech ecosystem was impacted, estimated[3] the CrowdStrike update affected 8.5 million Windows devices globally.

But as with many other technology products, there is a clear contractual relationship between the consumer (the end user of the product) and the manufacturer (CrowdStrike).

Graphic showing 'terms of use' floating above a laptop screen
Many software providers add ‘exclusion clauses’ to their terms of use. MMD Creative/Shutterstock[4]

This contract – the sometimes overlooked “terms and conditions” – has to be “signed” electronically by organisations using the software. Signing binds them to these terms – regardless of whether they’ve actually read them or not.

Deep in the fine print of many software product terms and conditions are a series of exclusion clauses. Tech companies often rely on these to protect themselves from litigation for any damage that arises if their software malfunctions.

In the case of CrowdStrike’s Falcon security software, the relevant terms[5] limit liability to “fees paid”. Put more plainly, customers are entitled to no more than a simple refund.

Read more: What is CrowdStrike Falcon and what does it do? Is my computer safe?[6]

Contract law vs tort law

As you can see, businesses’ options for seeking redress under contract law may be severely limited. This has led some law firms to raise the possibility[7] of pursuing class action under other claims, such as negligence. In a note to clients[8] about the outage, New Zealand-based law firm Russell McVeagh said:

Further, if any lack of readiness on the part of affected organisations exacerbated the scale or duration of the impact that the outage had on them, shareholder claims against those organisations, or their directors, are also a possibility.

To understand how such a class action might be framed, you need to understand some important legal basics surrounding what’s called “tort law” in common law.

Australia and New Zealand follow the legal system known as common law, which was developed in Britain in the 11th century. At a high level, it simply means that courts follow precedents set by the highest court in the jurisdiction.

And the word “tort” simply means a civil wrong. Many legal actions – such as allegations of defamation, trespass, nuisance or negligence – fall under the umbrella of torts.

‘Snail in the bottle’

In 1932, the UK House of Lords heard a case that would forever change the landscape of the common law world – “Donoghue v Stevenson[9]”.

This case is known by its nickname: “the snail in the bottle” case. The simple facts of it involved two friends having an ice cream float made with ginger beer in a Scottish cafe. After one of them had already consumed some of the dessert, they discovered a dead snail in the ginger beer bottle.

Snail sliding over the top of a glass bottle
The snail in the bottle case set an important precedent in tort law. Oleg Troino/Shutterstock[10]

The cafe owner could not have known that inside the commercially produced brown bottle of ginger beer was a dead snail. So a tort of negligence was brought by the consumer against the manufacturer of the bottle of ginger beer, Stevenson & Co.

The plaintiff, the bringer of the civil case, had to prove three things for Stevenson, the defendant, to be found liable. First, that a duty of care was owed between the manufacturer and the final consumer. Second, that there was a breach of the duty of care. And finally, that it was reasonably foreseeable that harm would occur from that negligence, resulting in actual damage.

The House of Lords decided in favour of Mrs Donoghue, which extended the notion of duty of care outside of contracts.

Over the next 50 years these tests were refined, and “remoteness of damage” was added to the requirements for proving a case. This meant that in some instances, entities couldn’t be found liable if they were found to be too remote from any harm that occurred.

So could there be a class action?

In Australia, most consumers are protected by legislation known as the Australian Consumer Law[11]. This legislation provides different remedies and requirements of proof than the common law tortious requirements. But the common law principles of the tort of negligence still apply in tandem.

Close up of blue screen error message
Many users encountered the dreaded ‘blue screen of death’ during the outage. QINQIE99/Shutterstock[12]

However, any businesses and organisations looking to pursue class action against CrowdStrike on the tort grounds of negligence would face an extremely complex situation. The outage affected customers in a wide variety of countries, and CrowdStrike itself is headquartered in the United States.

This means such class actions would likely have to be filed in a variety of US states and other countries.

Class action lawyers would charge a percentage of the final settlement, which could be between 30% and 80% of any payout. But they would also take on the risk and pay all the costs, such as for expert witnesses and lawyer preparation.

The scope and scale of the outage mean that if any class actions are eventually launched, it could become one of the largest litigation matters in the world and drag on for many years.

Whatever happens, major insurance companies will continue watching the situation closely[13], with many businesses now looking closely at what they are covered for under any cyber insurance policies they’d taken out.

Read more: The Crowdstrike outage showed that risk management is essential. Why are so many businesses reluctant to do it?[14]

References

  1. ^ estimates (www.abc.net.au)
  2. ^ declare (www.crowdstrike.com)
  3. ^ estimated (blogs.microsoft.com)
  4. ^ MMD Creative/Shutterstock (www.shutterstock.com)
  5. ^ terms (www.businessinsider.com)
  6. ^ What is CrowdStrike Falcon and what does it do? Is my computer safe? (theconversation.com)
  7. ^ raise the possibility (www.nzherald.co.nz)
  8. ^ note to clients (www.russellmcveagh.com)
  9. ^ Donoghue v Stevenson (www.bailii.org)
  10. ^ Oleg Troino/Shutterstock (www.shutterstock.com)
  11. ^ Australian Consumer Law (consumer.gov.au)
  12. ^ QINQIE99/Shutterstock (www.shutterstock.com)
  13. ^ watching the situation closely (www.theaustralian.com.au)
  14. ^ The Crowdstrike outage showed that risk management is essential. Why are so many businesses reluctant to do it? (theconversation.com)

Authors: Michael Adams, Professor of Corporate Law & Academic Director of UNE Sydney campus, University of New England

Read more https://theconversation.com/the-crowdstrike-outage-caused-chaos-for-business-could-we-see-a-class-action-235215

SME Business News

How Virtual Team Building Is Reshaping Modern Business Dynamics

In the past years, virtual team building has established itself as one of the cornerstones in building modern business strategy. With more organizations now switching to a model of remote or ...

How digital loyalty programs drive engagement in a value-conscious economy

Ongoing economic pressures are driving Australian retail businesses to rethink how they engage with increasingly value-conscious consumers. Rising living costs have shifted spending habits, p...

How Ofload and Logistics Tech Power Australia’s Biggest Shopping Month

Black Friday has evolved from a single day event into "Black November," overtaking December as Australia’s biggest shopping month. This shopping phenomenon, expected to drive $6.7 billion [1...

Kimberly-Clark Australia and Woolworths set to reduce plastic waste

Kimberly-Clark Australia, one of the nation’s leading personal care product manufacturers, has partnered with Woolworths on a packaging trial that’s set to remove tonnes of plastic waste from...

The Times Features

Energy-Efficient Roof Restoration Trends to Watch in Sydney

As climate consciousness rises and energy costs soar, energy-efficient roof restoration has become a significant focus in Sydney. Whether you're renovating an old roof or enhan...

Brisbane Water Bill Savings: Practical Tips to Reduce Costs

Brisbane residents have been feeling the pinch as water costs continue to climb. With increasing prices, it's no wonder many households are searching for ways to ease the burde...

Exploring Hybrid Heating Systems for Modern Homes

Consequently, energy efficiency as well as sustainability are two major considerations prevalent in the current market for homeowners and businesses alike. Hence, integrated heat...

Are Dental Implants Right for You? Here’s What to Think About

Dental implants are now among the top solutions for those seeking to replace and improve their teeth. But are dental implants suitable for you? Here you will find out more about ...

Sunglasses don’t just look good – they’re good for you too. Here’s how to choose the right pair

Australians are exposed to some of the highest levels[1] of solar ultraviolet (UV) radiation in the world. While we tend to focus on avoiding UV damage to our skin, it’s impor...

How to Style the Pantone Color of the Year 2025 - Mocha Mousse

The Pantone Color of the Year never fails to set the tone for the coming year's design, fashion, and lifestyle trends. For 2025, Pantone has unveiled “Mocha Mousse,” a rich a...

Business Times

How Virtual Team Building Is Reshaping Modern Business Dynamics

In the past years, virtual team building has established itself as one of the cornerstones in building modern business st...

How digital loyalty programs drive engagement in a value-consciou…

Ongoing economic pressures are driving Australian retail businesses to rethink how they engage with increasingly value-co...

How Ofload and Logistics Tech Power Australia’s Biggest Shopping …

Black Friday has evolved from a single day event into "Black November," overtaking December as Australia’s biggest shoppi...

LayBy Shopping