On July 19, 2024, a faulty software update pushed through by a security vendor brought down 8.5 million Windows devices across hospitals, airlines, and financial institutions within hours. Most affected organizations had current, valid assessments of CrowdStrike as a direct vendor. Their Third-Party Risk Management (TPRM) programs recorded it as reviewed and approved.