HOME

TheInfoList



OR:

CrowdStrike Holdings, Inc. is an American
cybersecurity Computer security (also cybersecurity, digital security, or information technology (IT) security) is a subdiscipline within the field of information security. It consists of the protection of computer software, systems and networks from thr ...
technology company based in
Austin, Texas Austin ( ) is the List of capitals in the United States, capital city of the U.S. state of Texas. It is the county seat and most populous city of Travis County, Texas, Travis County, with portions extending into Hays County, Texas, Hays and W ...
. It provides
endpoint security Endpoint security or endpoint protection is an approach to the protection of computer networks that are remotely bridged to client devices. The connection of endpoint devices such as laptops, tablets, mobile phones, and other wireless devices t ...
, threat intelligence, and
cyberattack A cyberattack (or cyber attack) occurs when there is an unauthorized action against computer infrastructure that compromises the confidentiality, integrity, or availability of its content. The rising dependence on increasingly complex and inte ...
response services. The company has been involved in investigations of several high-profile cyberattacks, including the 2014
Sony Pictures hack On November 24, 2014, the hacker group " Guardians of Peace" leaked confidential data from the film studio Sony Pictures Entertainment (SPE). The data included employee emails, personal and family information, executive salaries, copies of th ...
, the 2015–16 cyberattacks on the Democratic National Committee (DNC), and the 2016 email leak involving the DNC. On July 19, 2024, it issued a faulty update to its security software that caused global computer outages that disrupted air travel, banking, broadcasting, and other services.


History

CrowdStrike was co-founded in 2011 by
George Kurtz George Kurtz (born October 14, 1970) is an American businessman. He is a co-founder and chief executive officer of CrowdStrike, a cybersecurity technology company. He founded Foundstone, a security products and anti-virus software company, an ...
(CEO),
Dmitri Alperovitch Dmitri Alperovitch (; born 1980) is an American think-tank founder, author, philanthropist, podcast host and former computer security industry executive. He is the chairman of Silverado Policy Accelerator, a geopolitics think-tank in Washingto ...
(former CTO), and Gregg Marston (CFO, retired). The following year, they hired Shawn Henry, a former
Federal Bureau of Investigation The Federal Bureau of Investigation (FBI) is the domestic Intelligence agency, intelligence and Security agency, security service of the United States and Federal law enforcement in the United States, its principal federal law enforcement ag ...
(FBI) official, to lead the subsidiary CrowdStrike Services, Inc., which offered security and response services. The company launched CrowdStrike Falcon, an
antivirus Antivirus software (abbreviated to AV software), also known as anti-malware, is a computer program used to prevent, detect, and remove malware. Antivirus software was originally developed to detect and remove computer viruses, hence the name ...
package, as its first product in June 2013. In May 2014, CrowdStrike's reports helped the
United States Department of Justice The United States Department of Justice (DOJ), also known as the Justice Department, is a United States federal executive departments, federal executive department of the U.S. government that oversees the domestic enforcement of Law of the Unite ...
to charge five Chinese military hackers with economic cyber espionage against U.S. corporations. CrowdStrike also uncovered the activities of Energetic Bear, a group connected to
Russia Russia, or the Russian Federation, is a country spanning Eastern Europe and North Asia. It is the list of countries and dependencies by area, largest country in the world, and extends across Time in Russia, eleven time zones, sharing Borders ...
's
Federal Security Service The Federal Security Service of the Russian Federation �СБ, ФСБ России (FSB) is the principal security agency of Russia and the main successor agency to the Soviet Union's KGB; its immediate predecessor was the Federal Counterin ...
that conducted intelligence operations against global targets, primarily in the
energy sector The energy industry refers to all of the industries involved in the production and sale of energy, including fuel extraction, manufacturing, refining and distribution. Modern society consumes large amounts of fuel, and the energy industry is a cr ...
. After the
Sony Pictures hack On November 24, 2014, the hacker group " Guardians of Peace" leaked confidential data from the film studio Sony Pictures Entertainment (SPE). The data included employee emails, personal and family information, executive salaries, copies of th ...
, CrowdStrike uncovered evidence implicating the government of
North Korea North Korea, officially the Democratic People's Republic of Korea (DPRK), is a country in East Asia. It constitutes the northern half of the Korea, Korean Peninsula and borders China and Russia to the north at the Yalu River, Yalu (Amnok) an ...
and demonstrated how the attack was carried out. In 2014, CrowdStrike helped identify members of Putter Panda, the state-sponsored Chinese group of hackers also known as
PLA Unit 61486 PLA Unit 61486 (also known as Putter Panda or APT2) is a People's Liberation Army unit dedicated to cyberattacks on American, Japanese, and European corporations focused on satellite and communications technology. It is a unit that takes part in C ...
. In May 2015, the company released information about
VENOM Venom or zootoxin is a type of toxin produced by an animal that is actively delivered through a wound by means of a bite, sting, or similar action. The toxin is delivered through a specially evolved ''venom apparatus'', such as fangs or a sti ...
, a critical flaw in an open-source
hypervisor A hypervisor, also known as a virtual machine monitor (VMM) or virtualizer, is a type of computer software, firmware or hardware that creates and runs virtual machines. A computer on which a hypervisor runs one or more virtual machines is called ...
called Quick Emulator (QEMU) that allowed attackers to access sensitive personal information. In October 2015, CrowdStrike announced that it had identified Chinese hackers attacking technology and pharmaceutical companies around the time that
U.S. President The president of the United States (POTUS) is the head of state and head of government of the United States. The president directs the Federal government of the United States#Executive branch, executive branch of the Federal government of t ...
Barack Obama Barack Hussein Obama II (born August 4, 1961) is an American politician who was the 44th president of the United States from 2009 to 2017. A member of the Democratic Party, he was the first African American president in American history. O ...
and China's leader
Xi Jinping Xi Jinping, pronounced (born 15 June 1953) is a Chinese politician who has been the general secretary of the Chinese Communist Party (CCP) and Chairman of the Central Military Commission (China), chairman of the Central Military Commission ...
publicly agreed not to conduct economic espionage against each other. The alleged hacking would have been in violation of that agreement. In July 2015,
Google Google LLC (, ) is an American multinational corporation and technology company focusing on online advertising, search engine technology, cloud computing, computer software, quantum computing, e-commerce, consumer electronics, and artificial ...
invested in the company's Series C funding round, which was followed by Series D and Series E, raising a total of $480 million as of May 2019. In 2017, the company reached a valuation of more than $1 billion with an estimated annual revenue of $100 million. In June 2018, the company said it was valued at more than $3 billion. Investors include
Telstra Telstra Group Limited is an Australian telecommunications company that builds and operates telecommunications networks and markets related products and services. It is a member of the S&P/ASX 20 stock index, and is Australia's largest telecomm ...
, March Capital Partners,
Rackspace Rackspace Technology, Inc. is an American cloud computing company based in San Antonio, Texas. It also has offices in Blacksburg, Virginia, Blacksburg, Virginia and Austin, Texas, as well as in Australia, Canada, United Kingdom, India, Dubai, Sw ...
,
Accel Partners Accel, formerly known as Accel Partners, is a global venture capital firm. Accel works with startups in seed, early and growth-stage investments. The company has offices in Palo Alto, California and San Francisco, California, with additional ope ...
and
Warburg Pincus Warburg Pincus LLC is a global private equity firm, headquartered in New York City, with offices in the United States, Europe, Brazil, China, Southeast Asia and India. Warburg has been a private equity investor since 1966. As of April 2024 the f ...
. In June 2019, the company made an
initial public offering An initial public offering (IPO) or stock launch is a public offering in which shares of a company are sold to institutional investors and usually also to retail (individual) investors. An IPO is typically underwritten by one or more investm ...
on the
Nasdaq The Nasdaq Stock Market (; National Association of Securities Dealers Automated Quotations) is an American stock exchange based in New York City. It is the most active stock trading venue in the U.S. by volume, and ranked second on the list ...
. CrowdStrike expanded its identity security offerings with Falcon Identity Threat Protection, initially available in 2020, which later evolved into a managed service integrating with Falcon Complete in 2022, and a Cloud Threat Hunting Service in July 2022."CrowdStrike launches Falcon Identity Threat Protection Complete,"
''Techzine'', March 2, 2022, retrieved March 3, 2025.
"CrowdStrike introduces a new cloud threat hunting service,"
''VentureBeat'', July 26, 2022, retrieved March 3, 2025.
In December 2021, the company moved its headquarters location from
Sunnyvale, California Sunnyvale () is a city located in the Santa Clara Valley in northwestern Santa Clara County, California, United States. Sunnyvale lies along the historic El Camino Real (California), El Camino Real and U.S. Route 101 in California, Highway 1 ...
, to Austin, Texas. In 2023, CrowdStrike introduced CrowdStream service in collaboration with Cribl.io. Charlotte AI, CrowdStrike's generative AI security analyst, was launched in May 2023 as part of Falcon's AI-driven security updates, enhancing automated threat triaging and response."CrowdStrike adds generative AI assistant to security tools,"
''Axios'', May 30, 2023, retrieved March 6, 2025.
In September 2023, CrowdStrike launched Falcon Foundry, a no-code application development platform directed at a wider audience,
''CSO'', September 19, 2023, retrieved March 3, 2025.
and in September 2024, the company launched CrowdStrike Financial Services, which offers payment solutions and financing to improve access to the Falcon platform."CrowdStrike Unveils Financial Services, AI Tools at Fal.Con 2024,"
''Channel Insider'', September 23, 2024, retrieved March 6, 2025.
CrowdStrike joined the
S&P 500 The Standard and Poor's 500, or simply the S&P 500, is a stock market index tracking the stock performance of 500 leading companies listed on stock exchanges in the United States. It is one of the most commonly followed equity indices and in ...
index in June 2024. As of 2024, CrowdStrike spent more than $360,000 on federal lobbying in the first half of 2024, according to OpenSecrets, and $620,000 during 2023. The company has also focused on working with the U.S. government and selling its services to government agencies.


Acquisitions

In November 2017, CrowdStrike acquired Payload Security, a firm that developed automated malware analysis sandbox technology. In September 2020, the company acquired
zero trust Zero trust architecture (ZTA) or perimeterless security is a design and implementation strategy of IT systems. The principle is that users and devices should not be trusted by default, even if they are connected to a privileged network such as a ...
and
conditional access Conditional access (CA) is a term commonly used in relation to software and to digital television systems. Conditional access is an evaluation to ensure the person who is seeking access to content is authorized to access the content. Access is man ...
technology provider Preempt Security for $96 million. In February 2021, CrowdStrike acquired Danish
log management Log management is the process for generating, transmitting, storing, accessing, and disposing of log data. A log data (or ''logs'') is composed of entries (records), and each entry contains information related to a specific event that occur within ...
platform Humio for $400 million with plans to integrate Humio's log aggregation into CrowdStrike's XDR offering. Later that November, CrowdStrike acquired SecureCircle, a SaaS-based cybersecurity service that extends zero trust endpoint security to include data. In October 2022, CrowdStrike acquired Reposify, an external attack surface management vendor for risk management. In 2023, CrowdStrike acquired
Israel Israel, officially the State of Israel, is a country in West Asia. It Borders of Israel, shares borders with Lebanon to the north, Syria to the north-east, Jordan to the east, Egypt to the south-west, and the Mediterranean Sea to the west. Isr ...
i cybersecurity startup Bionic.ai. In 2024, CrowdStrike acquired Israeli
cloud security Cloud computing security or, more simply, cloud security, refers to a broad set of policies, technologies, applications, and controls utilized to protect virtualized IP, data, applications, services, and the associated infrastructure of cloud com ...
startups Flow Security for $200 million and Adaptive Shield for $300 million.


Earnings

In 2024, total revenue was $3.06 billion, a 36% increase.


Russian hacking investigations

CrowdStrike helped investigate the Democratic National Committee cyberattacks and a connection to Russian intelligence services. On 20 March 2017,
James Comey James Brien Comey Jr. (; born December 14, 1960) is an American lawyer who was the seventh director of the Federal Bureau of Investigation (FBI) from 2013 until Dismissal of James Comey, his termination in May 2017. Comey was a registered Repub ...
testified before congress stating:
CrowdStrike,
Mandiant Mandiant, Inc. is an American cybersecurity firm and a subsidiary of Google. Mandiant received attention in February 2013 when it released a report directly implicating China in cyber espionage. In December 2013, Mandiant was acquired by FireE ...
, and
ThreatConnect ThreatConnect is a cyber-security firm based in Arlington, Virginia. They provide a Threat Intelligence Platform for companies to aggregate and act upon threat intelligence. History The firm was founded in 2011 as Cyber Squared Inc. by Adam Vinc ...
review dthe evidence of the hack and conclude with high certainty that it was the work of APT 28 and APT 29 who are known to be Russian intelligence services.
Comey previously testified in January 2017 that a request for
FBI The Federal Bureau of Investigation (FBI) is the domestic Intelligence agency, intelligence and Security agency, security service of the United States and Federal law enforcement in the United States, its principal federal law enforcement ag ...
forensics investigators to access the DNC servers was denied, saying "Ultimately what was agreed to is the private company rowdStrikewould share with us what they saw." In December 2016, CrowdStrike released a report stating that Russian government-affiliated group
Fancy Bear Fancy Bear is a Russian cyber espionage group. American cybersecurity firm CrowdStrike has stated with a medium level of confidence that it is associated with the Russian military intelligence agency GRU. The UK's Foreign and Commonwealth Offic ...
had hacked a Ukrainian artillery app. They concluded that Russia had used the hack to cause large losses to Ukrainian artillery units. The app (called ArtOS) is installed on tablet PCs and used for fire-control. CrowdStrike also found a hacked variation of POPR-D30 being distributed on Ukrainian military forums that utilized an X-Agent implant. The
International Institute for Strategic Studies The International Institute for Strategic Studies (IISS) is an international research institute or think tank focusing on defence and security issues. Since 1997, its headquarters have been at Arundel House in London. It has offices on four co ...
rejected CrowdStrike's assessment that claimed hacking caused losses to Ukrainian artillery units, saying that their data on Ukrainian D30 howitzer losses was misused in CrowdStrike's report. The Ukrainian Ministry of Defense also rejected the CrowdStrike report, stating that actual artillery losses were much smaller than what was reported by CrowdStrike and were not associated with Russian hacking. Prior to this, CrowdStrike had published a report claiming that malware used in Ukraine and against the
Democratic National Committee The Democratic National Committee (DNC) is the principal executive leadership board of the United States's Democratic Party (United States), Democratic Party. According to the party charter, it has "general responsibility for the affairs of the ...
(DNC) appeared to be unique and identical, further evidence for a Russian origin of the DNC attack. Cybersecurity firm SecureWorks discovered a list of email addresses targeted by Fancy Bear in phishing attacks. The list included the email address of Yaroslav Sherstyuk, the developer of ArtOS. Additional
Associated Press The Associated Press (AP) is an American not-for-profit organization, not-for-profit news agency headquartered in New York City. Founded in 1846, it operates as a cooperative, unincorporated association, and produces news reports that are dist ...
research supports CrowdStrike's conclusions about Fancy Bear.
Radio Free Europe Radio Free Europe/Radio Liberty (RFE/RL) is a media organization broadcasting news and analyses in 27 languages to 23 countries across Eastern Europe, Central Asia, the Caucasus, and the Middle East. Headquartered in Prague since 1995, RFE/RL ...
notes that the AP report "lends some credence to the original CrowdStrike report, showing that the app had, in fact, been targeted." In the Trump–Ukraine scandal,
Donald Trump Donald John Trump (born June 14, 1946) is an American politician, media personality, and businessman who is the 47th president of the United States. A member of the Republican Party (United States), Republican Party, he served as the 45 ...
, then the
president of the United States The president of the United States (POTUS) is the head of state and head of government of the United States. The president directs the Federal government of the United States#Executive branch, executive branch of the Federal government of t ...
, held a phone call with
Volodymyr Zelensky Volodymyr Oleksandrovych Zelenskyy (born 25 January 1978) is a Ukrainian politician and former entertainer who has served as the sixth and current president of Ukraine since 2019. He took office five years after the start of the Russo-Ukraini ...
, the
president of Ukraine The president of Ukraine (, ) is the head of state of Ukraine. The president represents the nation in international relations, administers the foreign political activity of the state, conducts negotiations and concludes international treaties. ...
, on 25 July 2019, in which Trump asked Zelensky to look into a conspiracy theory that was being promoted on
far-right Far-right politics, often termed right-wing extremism, encompasses a range of ideologies that are marked by ultraconservatism, authoritarianism, ultranationalism, and nativism. This political spectrum situates itself on the far end of the ...
websites such as ''
Breitbart News ''Breitbart News Network'' (; known commonly as ''Breitbart News'', ''Breitbart'', or ''Breitbart.com'') is an Radical right (United States), American far-rightMultiple sources: * * * * * * * * * * * * syndicated news, opinion, and commentar ...
'' and Russian state media outlets such as
Russia Today RT, formerly Russia Today (), is a Russian state-controlled international news television network funded by the Russian government. It operates pay television and free-to-air channels directed to audiences outside of Russia, as well as pro ...
and
Sputnik Sputnik 1 (, , ''Satellite 1''), sometimes referred to as simply Sputnik, was the first artificial Earth satellite. It was launched into an elliptical low Earth orbit by the Soviet Union on 4 October 1957 as part of the Soviet space progra ...
. The theory held that namely, that the Ukrainian government used CrowdStrike to hack into the Democratic National Committee's servers in 2016 and frame Russia for the crime to undermine Trump in the 2016 presidential election. The conspiracy theory has been repeatedly debunked.


2024 incident

On 19 July 2024, CrowdStrike released a software configuration file update to the Falcon
endpoint detection and response Endpoint detection and response (EDR), also known as endpoint threat detection and response (ETDR), is a cybersecurity technology that continually monitors an "endpoint" (e.g. a client device such as a mobile phone, laptop, Internet of things devi ...
agent. Flaws in the update caused
blue screens of death The blue screen of death (BSoD) or blue screen error, blue screen, fatal error, bugcheck, and officially known as a stop erroris a fatal system error, critical error screen displayed by the Microsoft Windows operating systems to indicate a cr ...
on
Microsoft Windows Windows is a Product lining, product line of Proprietary software, proprietary graphical user interface, graphical operating systems developed and marketed by Microsoft. It is grouped into families and subfamilies that cater to particular sec ...
machines, disrupting millions of Windows computers worldwide. Affected machines were forced into a bootloop, making them unusable. This was caused by an update to a configuration file, Channel File 291, which CrowdStrike says triggered a
logic error In computer programming, a logic error is a Software bug, bug in a program that causes it to operate incorrectly, but not to terminate abnormally (or crash (computing), crash). A logic error produces unintended or undesired output or other behav ...
and caused the operating system to crash. The downtime caused a widespread global impact, grounding commercial airline flights, temporarily taking
Sky News Sky News is a British free-to-air television news channel, live stream news network and news organisation. Sky News is distributed via an English-language radio news service, and through online channels. It is owned by Sky Group, a division of ...
and other broadcasters offline, and disrupting banking and healthcare services as well as
911 911, 9/11 or Nine Eleven may refer to: Dates * AD 911 * 911 BC * September 11 ** The 2001 September 11 attacks on the United States by al-Qaeda, commonly referred to as 9/11 ** 11 de Septiembre, Chilean coup d'état in 1973 that ousted the ...
emergency call centers. By the end of the day, CrowdStrike shares closed trading at a price of $304.96, down $38.09 or 11.10%. Although CrowdStrike issued a patch to fix the error, computers stuck in a bootloop were unable to connect to the Internet to download the patch before Falcon would be loaded and crash the device again. The recommended solution from CrowdStrike was to boot into
safe mode Safe mode is a diagnosis, diagnostic mode of a computer operating system (OS). It can also refer to a mode of operation by application software. ''Safe mode'' is intended to help fix most, if not all, problems within an operating system. It is a ...
or Windows Recovery Mode and manually delete Channel File 291. This requires local administrator access and if the device was encrypted by
BitLocker BitLocker is a full volume encryption feature included with Microsoft Windows versions starting with Windows Vista. It is designed to protect data by providing encryption for entire volumes. By default, it uses the Advanced Encryption Standard ...
, also required a recovery key. Microsoft reported that some customers were able to remediate the issue solely by rebooting impacted devices up to 15 times. On 22 July 2024, CrowdStrike shares closed the trading day at a price of $263.91, with a loss of $41.05 or 13.46%. On 24 July 2024, five days after the incident, CrowdStrike published a Post-Incident Review. That same day, CrowdStrike reportedly contacted affected channel partners with apology emails containing
Uber Eats Uber Eats is an online food ordering and delivery platform launched by the company Uber in 2014. It is operational in over 6,000 cities in 45 countries as of 2021. History Uber Eats' parent company Uber was founded in 2009 by Garrett ...
gift cards worth $10. On 6 August 2024, Crowdstrike published a Root Cause Analysis to explain the causes of the Channel File 291 Incident, and the mitigation steps the company took to eliminate future incidents. CrowdStrike made several process improvements in response to the 19 July incident. These include: adding new content configuration test procedures; implementing additional deployment layers and acceptance checks for its content configuration system; engaging two third-party vendors to review Falcon sensor code, and the company's quality control and release processes; and staggering update rollout in which users can select their preferred timing for updates. The CrowdStrike incident cost Fortune 500 companies $5.4 billion.


See also

*
Operating system An operating system (OS) is system software that manages computer hardware and software resources, and provides common daemon (computing), services for computer programs. Time-sharing operating systems scheduler (computing), schedule tasks for ...
s *
Chinese intelligence activity abroad The government of the People's Republic of China is engaged in espionage overseas, directed through diverse methods via the Ministry of State Security (MSS), the Ministry of Public Security (MPS), the United Front Work Department (UFWD), People' ...
*
Chinese espionage in the United States The United States has often accused the People's Republic of China (PRC) of attempting to unlawfully acquire U.S. military technology and classified information as well as trade secrets of U.S. companiesFinkle, J. Menn, J., Viswanatha, J''U.S. ...
*
Timeline of Russian interference in the 2016 United States elections This is a timeline of events related to Russian interference in the 2016 United States elections. It includes events described in investigations into the myriad links between Trump associates and Russian officials and spies until July 2016, w ...
*
Timeline of investigations into Donald Trump and Russia (January–June 2017) A timeline is a list of events displayed in chronological order. It is typically a graphic design showing a long bar labelled with dates paralleling it, and usually contemporaneous events. Timelines can use any suitable scale representing t ...


References


External links

* * {{NASDAQ-100 2011 establishments in California 2019 initial public offerings 2019 Trump–Ukraine scandal American companies established in 2011 Business services companies established in 2011 Business services companies of the United States Companies based in Austin, Texas Companies based in Sunnyvale, California Companies listed on the Nasdaq Computer companies established in 2011 Computer companies of the United States Computer security companies Internet technology companies of the United States Organizations associated with Russian interference in the 2016 United States elections Science and technology in Texas Security companies of the United States Technology companies based in the San Francisco Bay Area Warburg Pincus companies