CrowdStrike’s legal team has issued a strong response to Delta Air Lines following the latter’s public threats of legal action. The cybersecurity firm’s attorney, Michael Carlinsky, expressed disappointment with Delta’s insinuations that CrowdStrike behaved inappropriately, firmly rejecting any accusations of gross negligence or willful misconduct.
In the wake of a software update that led to over 8.5 million Microsoft devices crashing, CrowdStrike has apologized and conveyed its empathy for the difficulties Delta experienced. Despite this, Delta’s CEO, Ed Bastian, has spoken about the substantial financial losses and damage to the airline’s reputation, which has prompted the decision to seek legal redress to safeguard the interests of shareholders, customers, and employees.
Carlinsky’s correspondence underscores CrowdStrike’s attempts to reach out to Delta with offers of assistance, which were turned down. He also argues that Delta’s public legal threats are diverting attention from recovery efforts and fostering a false narrative regarding CrowdStrike’s role in Delta’s IT decisions and handling of the outage.
The letter also notes that any potential liability on CrowdStrike’s part is contractually limited to an amount in the single-digit millions and requests Delta to retain all pertinent documents and communications related to the outage. Carlinsky warns that while litigation would be regrettable, CrowdStrike is prepared to defend its stakeholders vigorously if necessary.
Delta has remained silent on the matter, but the airline was criticized by Transportation Secretary Pete Buttigieg during the incident. The Department of Transportation has since announced an investigation into the airline’s response to the outage.
Economists have estimated that the outage, attributed to CrowdStrike’s update, could cost Fortune 500 companies more than $5.4 billion. Additionally, CrowdStrike faces discontent from its investors, including a lawsuit from the Plymouth County Retirement Association in Texas, following a significant drop in the company’s share price due to the incident.
This situation highlights the critical need for solid cybersecurity practices, comprehensive testing of software updates, and transparent communication between companies and their service providers. The resolution of this dispute is poised to impact the cybersecurity industry and the standards for IT infrastructure and crisis management.
