On 19 July 2024, a global information technology (IT) outage affected a total of five government agencies and nine private companies, according to Digital Minister Gobind Singh Deo.
Bernama reports that the government agencies impacted included the Ministry of Transport, the Ministry of Education, the Ministry of Rural and Regional Development, the National Institute of Health, and the Kedah Zakat Board.
The nine private companies affected were from the aviation, banking, and healthcare sectors.
Gobind assured that all data within the government sector remained secure, with no data leakage or integrity issues observed.
However, he noted that there had been a phishing attempt during the IT outage, which the government successfully thwarted.
Irresponsible parties had created several phishing domains to obtain information and gain access to specific companies’ data.

Besides that, Gobind stated that Microsoft is currently preparing a full report on the incident and has been asked to consider the claims submitted by Malaysian companies that suffered losses and damages due to the disruption.
He has requested a full report on the estimated losses incurred by the affected entities but has not yet received it.
Gobind clarified that the outage was not a cyber attack but was caused by a flaw in CrowdStrike’s update software, which disrupted Microsoft’s operating systems and prevented users from accessing their computer systems.
To prevent similar incidents in the future, Gobind outlined three measures: requiring software providers to improve testing procedures before deployment, ensuring regular reviews and updates of software plans, and having a comprehensive incident response plan and stakeholder communication strategy.
A bug in CrowdStrike’s quality-assurance tool caused the global outage
CrowdStrike revealed that a bug in their quality-assurance tool, used to check updates for errors, allowed flawed data to be distributed to customers, causing last week’s global disruption, according to Bloomberg.
On 19 July, Friday, the company issued an update for Windows machines through a rapid-response mechanism designed to quickly address emerging threats.
Unfortunately, this update contained a critical flaw. The “content validator,” which is intended to test updates for errors before release, malfunctioned and let the bug pass through.

The report mentioned that CrowdStrike is now working to enhance its Rapid Response Content testing. A new check is being developed to fix the faulty content validator.
Additionally, the company plans to give customers more control over how updates are delivered to their systems.
To prevent similar issues in the future, CrowdStrike also intends to stagger updates through “canary deployments,” which involve testing updates in smaller segments before a full rollout, rather than deploying them all at once.
As an apology for the major fiasco, the company offered its partners a USD10 (~RM46.70) Uber Eats gift card. This is a company with more than USD62 billion (~RM289 billion) market capitalisation.