Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
Short answer: CrowdStrike alleged in October 2024 court filings that Delta failed to meet a TSA cybersecurity requirement designed to keep airline operations running safely when information-technology systems are compromised. TSA declined to say whether Delta complied or whether the agency had checked. That silence did not confirm a violation, clear Delta, or establish that the agency had investigated the claim.
What happened during the CrowdStrike outage?
On July 19, 2024, CrowdStrike distributed a faulty content-configuration update that caused crashes and other failures on some Windows systems. The incident was widely treated as a software-update failure, not a cyberattack or data breach. The Congressional Research Service said Microsoft estimated that about 8.5 million Windows devices were affected—less than 1% of Windows devices worldwide.
The disruption spread across airlines, banks, health-care providers, retailers, emergency services and government systems. Most affected organizations began recovering after the initial outage, but Delta’s problems continued for several days.
Why Delta became the focus
Delta reported approximately 7,000 canceled flights over five days, affecting about 1.4 million customers. The airline estimated a $380 million direct revenue impact for the September 2024 quarter and $170 million in additional non-fuel expenses, including customer reimbursements, compensation and crew-related recovery costs. Delta also said it was seeking at least $500 million in damages.
#1 Best Overall
Those figures establish the scale of Delta’s disruption. They do not, by themselves, establish why recovery took so long or whether Delta violated a cybersecurity regulation.
The Delta Form 10-Q and its SEC filing describing the outage document the airline’s reported cancellations, customer impact and financial estimates.
What CrowdStrike alleged
According to reporting on CrowdStrike’s court filing, the company argued that Delta’s recovery was prolonged partly because the airline allegedly failed to comply with a TSA cybersecurity emergency requirement adopted in March 2023.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →CrowdStrike said the requirement concerned policies and controls intended to allow an airline’s operational-technology systems to continue operating safely if its information-technology systems were compromised. The company argued that Delta’s systems lacked sufficient resilience and separation between IT and operational environments.
CrowdStrike also claimed that its work with Delta exposed outdated systems, weaknesses in Delta’s Active Directory environment and thousands of compromised passwords. It used those assertions to argue that Delta’s infrastructure and recovery practices—not the faulty update alone—helped explain the unusually long disruption.
Rank #2
- PREMIUM-QUALITY RECORD BOOK FOR DEALERS & COLLECTORS: Clever Fox Firearms Record Book is designed to help professional firearm dealers keep detailed and legally compliant acquisition and disposition information.
- 129 PAGES WITH 1,342 NUMBERED ENTRIES TOTAL: There are 129 pages in this firearm log book with 1,342 numbered entries total. Each pre-printed entry allows you to record the firearm’s description, as well as receipt and disposition info.
- LARGE FORMAT & PLENTY OF SPACE FOR EVERY DETAIL: This firearm record book comes in large format and measures 10 by 7 inches, so you have lots of space to make detailed records and add all the information you need.
- STORAGE POCKET, DURABLE HARDCOVER & THICK NO-BLEED PAPER: This gun record book features a pocket for loose papers, a pen loop, an elastic band, and a bookmark. The hardcover is made of durable vegan leather. The pages are thick 120gsm paper.
- 60-DAY MONEY-BACK GUARANTEE: We will exchange or refund your book of firearms if you aren’t satisfied with your personal firearms record book for any reason. Reach out to us via message to refund your personal gun log book.
These were allegations made in litigation. The available public record cited in the October 2024 reporting did not independently establish that Delta had outdated systems, compromised passwords or an inadequate IT/operational-technology architecture.
The central distinction is important: the TSA issue was reportedly about continuity, segmentation and recovery controls. It was not necessarily a claim that Delta failed to install a particular CrowdStrike patch or “security update.” Calling it a skipped update can incorrectly suggest a single missed software installation.
What the TSA requirement reportedly covered
Public reporting described the March 2023 TSA emergency amendment as requiring airlines to develop policies and controls that would:
- Allow operational-technology systems to continue operating safely if an information-technology system was compromised.
- Support timely responses to the exploitation of cybersecurity or operating systems.
- Improve resilience between systems used for corporate IT and systems supporting airline operations.
In an airline, operational technology may include systems supporting airport processes, aircraft operations, baggage, dispatch, maintenance or other activities. The exact scope depends on the regulatory text and the airline’s approved security plans.
The available account did not establish the amendment’s precise applicability date, enforcement mechanism, audit process or the specific controls Delta was alleged to have missed. Nor did it publicly identify a TSA determination that Delta was noncompliant.
Rank #3
Compliance with a resilience requirement would not guarantee that an airline could avoid every major outage. Conversely, a long outage would not automatically prove noncompliance. To establish a violation, evidence would be needed about the specific obligation, Delta’s approved controls and how those controls performed or failed.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Scan for outdated or missing drivers - takes under a minute3Clear out junk files and repair common Windows errorsWhat TSA said—and did not say
TSA declined Ars Technica’s request to comment on whether it had checks to ensure compliance with the emergency amendment. The agency did not publicly confirm that Delta was compliant, and it did not publicly confirm that Delta was noncompliant.
It also did not announce, in the cited reporting, a specific investigation into CrowdStrike’s allegation.
Those statements must not be treated as interchangeable:
- No comment means the agency declined to provide a public response.
- No investigation announced means no specific investigation was publicly identified in the cited account.
- No violation found would mean an agency had reached and disclosed a conclusion.
The third conclusion does not follow from the first two. TSA’s silence neither validated CrowdStrike’s claim nor disproved it.
Free tools Windows power users keep installed
One-click scans. No signup required.
DOT’s investigation was different
The Department of Transportation opened an investigation into Delta’s widespread cancellations and customer-service response. Transportation Secretary Pete Buttigieg said the agency would enforce passenger-protection obligations.
That inquiry was publicly described as addressing passenger treatment and disruption-related obligations. It was not publicly described as a determination that Delta had violated TSA cybersecurity requirements. TSA is a separate agency and is not part of DOT.
This agency distinction matters because a DOT investigation into refunds, assistance and customer service cannot by itself answer whether Delta maintained the cybersecurity controls described in CrowdStrike’s filing.
Delta’s response
Delta blamed CrowdStrike for the outage and said it intended to pursue claims against CrowdStrike and Microsoft. Delta alleged that CrowdStrike inadequately tested the update, failed to stage its deployment properly, lacked effective rollback capabilities and made misleading representations about how its software operated.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
CrowdStrike disputed Delta’s account. It said Delta’s claims were based on misinformation, argued that Delta had failed to modernize its infrastructure, and said the airline repeatedly refused or failed to accept assistance from CrowdStrike and Microsoft. CrowdStrike also raised contractual limits on damages and denied gross negligence and willful misconduct.
Microsoft separately disputed Delta’s public account. In a letter from Microsoft’s lawyer, the company said Delta had declined or failed to use Microsoft’s assistance and argued that some systems involved in the disruption, including crew-tracking and scheduling systems, relied on other providers and technologies.
Delta’s allegations, CrowdStrike’s defenses and Microsoft’s statements are positions in a business and legal dispute. They should not be confused with neutral technical findings.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What is documented and what remains unproven?
| Issue | What the public record supports |
|---|---|
| Initial outage | A faulty CrowdStrike update affected certain Windows systems on July 19, 2024. Government research described it as a software-update failure rather than a cyberattack or data breach. |
| Delta’s impact | Delta reported about 7,000 cancellations, 1.4 million affected customers and significant financial costs. |
| TSA requirement | Reporting described a March 2023 emergency requirement involving safe continuity of operational technology when IT systems are compromised. |
| Delta’s compliance | The cited public record did not establish that Delta violated the requirement. |
| CrowdStrike’s technical claims | CrowdStrike alleged weaknesses involving outdated systems, Active Directory and passwords. Those claims were not independently established in the cited record. |
| TSA’s position | TSA declined to comment on compliance checks and did not publicly confirm or deny the allegation. |
| DOT’s inquiry | DOT investigated Delta’s cancellations and passenger-service response, not a publicly confirmed TSA cybersecurity violation. |
Why the legal dispute matters
The dispute is not simply about who caused the first system failure. It also concerns whether Delta’s architecture and recovery practices amplified the consequences of that failure.
Delta’s case focuses on CrowdStrike’s software, testing, deployment process and rollback capabilities. CrowdStrike’s defense focuses on Delta’s infrastructure, recovery readiness, use of assistance and alleged failure to meet resilience obligations. Microsoft has contested parts of Delta’s account as well.
Damages are another unresolved issue. Delta’s request for at least $500 million is a claimed recovery amount, not an adjudicated loss. CrowdStrike’s argument that contractual terms limit damages could depend on the relevant agreements, applicable law and whether a court finds gross negligence or willful misconduct. The legal treatment of direct operating losses, consequential damages, reputational harm and future revenue would likewise depend on the litigation.
A later CrowdStrike SEC filing from 2026 shows that Delta’s claims remained part of CrowdStrike’s material litigation disclosures. That confirms the dispute remained significant to the company’s reporting; it does not resolve the underlying factual allegations.
The questions still unanswered
- Did TSA determine whether Delta complied with the March 2023 emergency amendment?
- Did TSA audit Delta before or after the outage?
- What specific technical and organizational controls did the amendment require?
- Were Delta’s operational-technology systems sufficiently separated from its IT environment?
- Did Delta’s recovery fail because of regulatory noncompliance, technical debt, vendor dependencies, weak recovery procedures, or a combination of factors?
- Did Delta reject assistance from CrowdStrike or Microsoft, and what assistance was offered?
- Were the alleged compromised passwords caused by the outage, present beforehand or related to a separate security issue?
- Will later court proceedings or government records establish any of these disputed claims?
Bottom line
CrowdStrike alleged that Delta failed to meet TSA-related cybersecurity resilience requirements and that this contributed to its slow recovery after the faulty July 2024 update. TSA declined to comment. The available public record therefore supports a dispute over Delta’s resilience and compliance—not a confirmed finding that Delta skipped a required security update or violated TSA rules.
Recommended Free Tools
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

