The Times Australia
Fisher and Paykel Appliances
Business and Money

The CrowdStrike outage caused chaos for business – could we see a class action?

  • Written by Michael Adams, Professor of Corporate Law & Academic Director of UNE Sydney campus, University of New England
Graphic showing 'terms of use' floating above a laptop screen

Until last Friday, many businesses hadn’t really dealt with anything quite like the speed and severity of the CrowdStrike IT outage.

Being forced to stop operations is costly. Some estimates[1] put the damage bill from the outage at more than A$1 billion in Australia alone.

As they continue to tally the losses, it’s only natural that affected businesses will be asking who is legally responsible, and whether there’ll be any compensation.

These are great questions, but from a legal point of view the answers will be complex.

Both CrowdStrike and various government cybersecurity authorities were quick to declare[2] that the event was not the result of any criminal behaviour such as a cyberattack or other hacking.

This means the laws relating to these matters fall within the jurisdiction of civil law – in particular, the law of contracts and the law of torts.

Exclusion clauses

CrowdStrike’s security software is used by a wide range of companies and other large organisations. Microsoft, whose tech ecosystem was impacted, estimated[3] the CrowdStrike update affected 8.5 million Windows devices globally.

But as with many other technology products, there is a clear contractual relationship between the consumer (the end user of the product) and the manufacturer (CrowdStrike).

Graphic showing 'terms of use' floating above a laptop screen
Many software providers add ‘exclusion clauses’ to their terms of use. MMD Creative/Shutterstock[4]

This contract – the sometimes overlooked “terms and conditions” – has to be “signed” electronically by organisations using the software. Signing binds them to these terms – regardless of whether they’ve actually read them or not.

Deep in the fine print of many software product terms and conditions are a series of exclusion clauses. Tech companies often rely on these to protect themselves from litigation for any damage that arises if their software malfunctions.

In the case of CrowdStrike’s Falcon security software, the relevant terms[5] limit liability to “fees paid”. Put more plainly, customers are entitled to no more than a simple refund.

Read more: What is CrowdStrike Falcon and what does it do? Is my computer safe?[6]

Contract law vs tort law

As you can see, businesses’ options for seeking redress under contract law may be severely limited. This has led some law firms to raise the possibility[7] of pursuing class action under other claims, such as negligence. In a note to clients[8] about the outage, New Zealand-based law firm Russell McVeagh said:

Further, if any lack of readiness on the part of affected organisations exacerbated the scale or duration of the impact that the outage had on them, shareholder claims against those organisations, or their directors, are also a possibility.

To understand how such a class action might be framed, you need to understand some important legal basics surrounding what’s called “tort law” in common law.

Australia and New Zealand follow the legal system known as common law, which was developed in Britain in the 11th century. At a high level, it simply means that courts follow precedents set by the highest court in the jurisdiction.

And the word “tort” simply means a civil wrong. Many legal actions – such as allegations of defamation, trespass, nuisance or negligence – fall under the umbrella of torts.

‘Snail in the bottle’

In 1932, the UK House of Lords heard a case that would forever change the landscape of the common law world – “Donoghue v Stevenson[9]”.

This case is known by its nickname: “the snail in the bottle” case. The simple facts of it involved two friends having an ice cream float made with ginger beer in a Scottish cafe. After one of them had already consumed some of the dessert, they discovered a dead snail in the ginger beer bottle.

Snail sliding over the top of a glass bottle
The snail in the bottle case set an important precedent in tort law. Oleg Troino/Shutterstock[10]

The cafe owner could not have known that inside the commercially produced brown bottle of ginger beer was a dead snail. So a tort of negligence was brought by the consumer against the manufacturer of the bottle of ginger beer, Stevenson & Co.

The plaintiff, the bringer of the civil case, had to prove three things for Stevenson, the defendant, to be found liable. First, that a duty of care was owed between the manufacturer and the final consumer. Second, that there was a breach of the duty of care. And finally, that it was reasonably foreseeable that harm would occur from that negligence, resulting in actual damage.

The House of Lords decided in favour of Mrs Donoghue, which extended the notion of duty of care outside of contracts.

Over the next 50 years these tests were refined, and “remoteness of damage” was added to the requirements for proving a case. This meant that in some instances, entities couldn’t be found liable if they were found to be too remote from any harm that occurred.

So could there be a class action?

In Australia, most consumers are protected by legislation known as the Australian Consumer Law[11]. This legislation provides different remedies and requirements of proof than the common law tortious requirements. But the common law principles of the tort of negligence still apply in tandem.

Close up of blue screen error message
Many users encountered the dreaded ‘blue screen of death’ during the outage. QINQIE99/Shutterstock[12]

However, any businesses and organisations looking to pursue class action against CrowdStrike on the tort grounds of negligence would face an extremely complex situation. The outage affected customers in a wide variety of countries, and CrowdStrike itself is headquartered in the United States.

This means such class actions would likely have to be filed in a variety of US states and other countries.

Class action lawyers would charge a percentage of the final settlement, which could be between 30% and 80% of any payout. But they would also take on the risk and pay all the costs, such as for expert witnesses and lawyer preparation.

The scope and scale of the outage mean that if any class actions are eventually launched, it could become one of the largest litigation matters in the world and drag on for many years.

Whatever happens, major insurance companies will continue watching the situation closely[13], with many businesses now looking closely at what they are covered for under any cyber insurance policies they’d taken out.

Read more: The Crowdstrike outage showed that risk management is essential. Why are so many businesses reluctant to do it?[14]

References

  1. ^ estimates (www.abc.net.au)
  2. ^ declare (www.crowdstrike.com)
  3. ^ estimated (blogs.microsoft.com)
  4. ^ MMD Creative/Shutterstock (www.shutterstock.com)
  5. ^ terms (www.businessinsider.com)
  6. ^ What is CrowdStrike Falcon and what does it do? Is my computer safe? (theconversation.com)
  7. ^ raise the possibility (www.nzherald.co.nz)
  8. ^ note to clients (www.russellmcveagh.com)
  9. ^ Donoghue v Stevenson (www.bailii.org)
  10. ^ Oleg Troino/Shutterstock (www.shutterstock.com)
  11. ^ Australian Consumer Law (consumer.gov.au)
  12. ^ QINQIE99/Shutterstock (www.shutterstock.com)
  13. ^ watching the situation closely (www.theaustralian.com.au)
  14. ^ The Crowdstrike outage showed that risk management is essential. Why are so many businesses reluctant to do it? (theconversation.com)

Authors: Michael Adams, Professor of Corporate Law & Academic Director of UNE Sydney campus, University of New England

Read more https://theconversation.com/the-crowdstrike-outage-caused-chaos-for-business-could-we-see-a-class-action-235215

Business Times

Partnership repaints approach to tradie mental health crisis

Haymes Paint Shop has supercharged its commitment to blue-collar counselling service TIACS to encourage Aussie tradies to ‘...

YepAI Emerges as AI Dark Horse, Launches V3 SuperAgent to Revolut…

November 24, 2025 – YepAI today announced the launch of its V3 SuperAgent, an enhanced AI platform designed to streamlin...

What SMEs Should Look For When Choosing a Shared Office in 2026

Small and medium-sized enterprises remain the backbone of Australia’s economy. As of mid-2024, small businesses accounted f...

The Times Features

The way Australia produces food is unique. Our updated dietary guidelines have to recognise this

You might know Australia’s dietary guidelines[1] from the famous infographics[2] showing the typ...

Why a Holiday or Short Break in the Noosa Region Is an Ideal Getaway

Few Australian destinations capture the imagination quite like Noosa. With its calm turquoise ba...

How Dynamic Pricing in Accommodation — From Caravan Parks to Hotels — Affects Holiday Affordability

Dynamic pricing has quietly become one of the most influential forces shaping the cost of an Aus...

The rise of chatbot therapists: Why AI cannot replace human care

Some are dubbing AI as the fourth industrial revolution, with the sweeping changes it is propellin...

Australians Can Now Experience The World of Wicked Across Universal Studios Singapore and Resorts World Sentosa

This holiday season, Resorts World Sentosa (RWS), in partnership with Universal Pictures, Sentosa ...

Mineral vs chemical sunscreens? Science shows the difference is smaller than you think

“Mineral-only” sunscreens are making huge inroads[1] into the sunscreen market, driven by fears of “...

Here’s what new debt-to-income home loan caps mean for banks and borrowers

For the first time ever, the Australian banking regulator has announced it will impose new debt-...

Why the Mortgage Industry Needs More Women (And What We're Actually Doing About It)

I've been in fintech and the mortgage industry for about a year and a half now. My background is i...

Inflation jumps in October, adding to pressure on government to make budget savings

Annual inflation rose[1] to a 16-month high of 3.8% in October, adding to pressure on the govern...