The Times Australia
The Times World News

.
The Times Real Estate

.

The CrowdStrike outage caused chaos for business – could we see a class action?

  • Written by Michael Adams, Professor of Corporate Law & Academic Director of UNE Sydney campus, University of New England
Graphic showing 'terms of use' floating above a laptop screen

Until last Friday, many businesses hadn’t really dealt with anything quite like the speed and severity of the CrowdStrike IT outage.

Being forced to stop operations is costly. Some estimates[1] put the damage bill from the outage at more than A$1 billion in Australia alone.

As they continue to tally the losses, it’s only natural that affected businesses will be asking who is legally responsible, and whether there’ll be any compensation.

These are great questions, but from a legal point of view the answers will be complex.

Both CrowdStrike and various government cybersecurity authorities were quick to declare[2] that the event was not the result of any criminal behaviour such as a cyberattack or other hacking.

This means the laws relating to these matters fall within the jurisdiction of civil law – in particular, the law of contracts and the law of torts.

Exclusion clauses

CrowdStrike’s security software is used by a wide range of companies and other large organisations. Microsoft, whose tech ecosystem was impacted, estimated[3] the CrowdStrike update affected 8.5 million Windows devices globally.

But as with many other technology products, there is a clear contractual relationship between the consumer (the end user of the product) and the manufacturer (CrowdStrike).

Graphic showing 'terms of use' floating above a laptop screen
Many software providers add ‘exclusion clauses’ to their terms of use. MMD Creative/Shutterstock[4]

This contract – the sometimes overlooked “terms and conditions” – has to be “signed” electronically by organisations using the software. Signing binds them to these terms – regardless of whether they’ve actually read them or not.

Deep in the fine print of many software product terms and conditions are a series of exclusion clauses. Tech companies often rely on these to protect themselves from litigation for any damage that arises if their software malfunctions.

In the case of CrowdStrike’s Falcon security software, the relevant terms[5] limit liability to “fees paid”. Put more plainly, customers are entitled to no more than a simple refund.

Read more: What is CrowdStrike Falcon and what does it do? Is my computer safe?[6]

Contract law vs tort law

As you can see, businesses’ options for seeking redress under contract law may be severely limited. This has led some law firms to raise the possibility[7] of pursuing class action under other claims, such as negligence. In a note to clients[8] about the outage, New Zealand-based law firm Russell McVeagh said:

Further, if any lack of readiness on the part of affected organisations exacerbated the scale or duration of the impact that the outage had on them, shareholder claims against those organisations, or their directors, are also a possibility.

To understand how such a class action might be framed, you need to understand some important legal basics surrounding what’s called “tort law” in common law.

Australia and New Zealand follow the legal system known as common law, which was developed in Britain in the 11th century. At a high level, it simply means that courts follow precedents set by the highest court in the jurisdiction.

And the word “tort” simply means a civil wrong. Many legal actions – such as allegations of defamation, trespass, nuisance or negligence – fall under the umbrella of torts.

‘Snail in the bottle’

In 1932, the UK House of Lords heard a case that would forever change the landscape of the common law world – “Donoghue v Stevenson[9]”.

This case is known by its nickname: “the snail in the bottle” case. The simple facts of it involved two friends having an ice cream float made with ginger beer in a Scottish cafe. After one of them had already consumed some of the dessert, they discovered a dead snail in the ginger beer bottle.

Snail sliding over the top of a glass bottle
The snail in the bottle case set an important precedent in tort law. Oleg Troino/Shutterstock[10]

The cafe owner could not have known that inside the commercially produced brown bottle of ginger beer was a dead snail. So a tort of negligence was brought by the consumer against the manufacturer of the bottle of ginger beer, Stevenson & Co.

The plaintiff, the bringer of the civil case, had to prove three things for Stevenson, the defendant, to be found liable. First, that a duty of care was owed between the manufacturer and the final consumer. Second, that there was a breach of the duty of care. And finally, that it was reasonably foreseeable that harm would occur from that negligence, resulting in actual damage.

The House of Lords decided in favour of Mrs Donoghue, which extended the notion of duty of care outside of contracts.

Over the next 50 years these tests were refined, and “remoteness of damage” was added to the requirements for proving a case. This meant that in some instances, entities couldn’t be found liable if they were found to be too remote from any harm that occurred.

So could there be a class action?

In Australia, most consumers are protected by legislation known as the Australian Consumer Law[11]. This legislation provides different remedies and requirements of proof than the common law tortious requirements. But the common law principles of the tort of negligence still apply in tandem.

Close up of blue screen error message
Many users encountered the dreaded ‘blue screen of death’ during the outage. QINQIE99/Shutterstock[12]

However, any businesses and organisations looking to pursue class action against CrowdStrike on the tort grounds of negligence would face an extremely complex situation. The outage affected customers in a wide variety of countries, and CrowdStrike itself is headquartered in the United States.

This means such class actions would likely have to be filed in a variety of US states and other countries.

Class action lawyers would charge a percentage of the final settlement, which could be between 30% and 80% of any payout. But they would also take on the risk and pay all the costs, such as for expert witnesses and lawyer preparation.

The scope and scale of the outage mean that if any class actions are eventually launched, it could become one of the largest litigation matters in the world and drag on for many years.

Whatever happens, major insurance companies will continue watching the situation closely[13], with many businesses now looking closely at what they are covered for under any cyber insurance policies they’d taken out.

Read more: The Crowdstrike outage showed that risk management is essential. Why are so many businesses reluctant to do it?[14]

References

  1. ^ estimates (www.abc.net.au)
  2. ^ declare (www.crowdstrike.com)
  3. ^ estimated (blogs.microsoft.com)
  4. ^ MMD Creative/Shutterstock (www.shutterstock.com)
  5. ^ terms (www.businessinsider.com)
  6. ^ What is CrowdStrike Falcon and what does it do? Is my computer safe? (theconversation.com)
  7. ^ raise the possibility (www.nzherald.co.nz)
  8. ^ note to clients (www.russellmcveagh.com)
  9. ^ Donoghue v Stevenson (www.bailii.org)
  10. ^ Oleg Troino/Shutterstock (www.shutterstock.com)
  11. ^ Australian Consumer Law (consumer.gov.au)
  12. ^ QINQIE99/Shutterstock (www.shutterstock.com)
  13. ^ watching the situation closely (www.theaustralian.com.au)
  14. ^ The Crowdstrike outage showed that risk management is essential. Why are so many businesses reluctant to do it? (theconversation.com)

Read more https://theconversation.com/the-crowdstrike-outage-caused-chaos-for-business-could-we-see-a-class-action-235215

The Times Features

Why Melbourne Homeowners Should Invest in High-Quality Glass Repairs

If you have a home in Melbourne, then you are not new to the city’s unpredictable weather, architectural styles and demands of daily life. It doesn’t matter if you have a modern ...

Are eggs good or bad for our health?

You might have heard that eating too many eggs will cause high cholesterol levels, leading to poor health. Researchers have examined the science behind this myth again[1], a...

How to Choose the Perfect Outdoor Lift for Your Home

Choosing the right outdoor lift for your home is a decision that blends functionality, aesthetics, and safety. Outdoor lifts not only enhance mobility but also increase the value...

The Importance of Pre-Purchase Building Inspections

Purchasing a property is quite possibly one of the most significant financial decisions you'll ever make. The allure of a new home or investment can often overshadow the necessit...

The Legal Battle Against IP Theft: What Businesses Need to Know

So you've formulated that million-dollar idea and you're ready to take your business to the next level. You were so excited to publicize your supposedly next big thing that you...

Why Roof Replacement Is the Best Solution for Roofs with Major Leaks

When your roof is leaking extensively, the situation can be both frustrating and worrying. The constant drip-drip-drip of water, the potential for structural damage, and the risi...

Times Magazine

Why You Should Choose Digital Printing for Your Next Project

In the rapidly evolving world of print media, digital printing has emerged as a cornerstone technology that revolutionises how businesses and creative professionals produce printed materials. Offering unparalleled flexibility, speed, and quality, d...

What to Look for When Booking an Event Space in Melbourne

Define your event needs early to streamline venue selection and ensure a good fit. Choose a well-located, accessible venue with good transport links and parking. Check for key amenities such as catering, AV equipment, and flexible seating. Pla...

How BIM Software is Transforming Architecture and Engineering

Building Information Modeling (BIM) software has become a cornerstone of modern architecture and engineering practices, revolutionizing how professionals design, collaborate, and execute projects. By enabling more efficient workflows and fostering ...

How 32-Inch Computer Monitors Can Increase Your Workflow

With the near-constant usage of technology around the world today, ergonomics have become crucial in business. Moving to 32 inch computer monitors is perhaps one of the best and most valuable improvements you can possibly implement. This-sized moni...

Top Tips for Finding a Great Florist for Your Sydney Wedding

While the choice of wedding venue does much of the heavy lifting when it comes to wowing guests, decorations are certainly not far behind. They can add a bit of personality and flair to the traditional proceedings, as well as enhancing the venue’s ...

Avant Stone's 2025 Nature's Palette Collection

Avant Stone, a longstanding supplier of quality natural stone in Sydney, introduces the 2025 Nature’s Palette Collection. Curated for architects, designers, and homeowners with discerning tastes, this selection highlights classic and contemporary a...

LayBy Shopping