CrowdStrike confirmed on July 12 2026 that attackers breached its systems on July 8. The intrusion affected 890,000 enterprise endpoints and exposed telemetry logs plus partial Falcon 7.4 sensor source code. No customer credentials or detection rules were stolen.
The company isolated the affected cluster within four hours and forced API key rotation for all customers by July 10. Forensic analysis traced the entry point to a compromised contractor account with excessive privileges. CrowdStrike notified the FBI and CISA the same day.
This marks the second major security vendor incident in 2026 after the Microsoft Azure breach in July. CrowdStrike revenue reached 4.8 billion dollars in fiscal 2026. Its stock fell 19 percent on July 13 following the disclosure.
The company released a patched Falcon sensor version 7.4.2 on July 11. All customers must redeploy the update before July 18 to restore full protection. CrowdStrike offered 12 months of free identity monitoring to affected organizations.
Why this matters
The breach highlights persistent supply-chain risks in security tooling itself. Enterprises must now diversify endpoint vendors and implement stricter contractor access controls. Regulators are expected to propose mandatory breach disclosure timelines within 24 hours by September 2026.
CrowdStrike plans to publish a full incident report by July 25. It will also open its detection logic to third-party audits starting in August.