CrowdStrike July Outage (C-00000291) - Update
Incident Report for Rapid Response Status Page
Resolved
This incident has been resolved.
Posted Jul 22, 2024 - 14:35 UTC
Identified
Dear Customers,

Axon is aware that multiple threat actor groups are exploiting the current chaos and panic within organizations caused by the ongoing Crowdstrike outage incident.

Our analysis has identified several ongoing malicious campaigns, including:
* Phishing and adware campaigns aimed at fraud and credential theft.
* Malware campaigns delivered via email targeting employees and IT personnel.
* Fraudulent groups impersonate Crowdstrike in phone calls to IT personnel to install remote tools or steal money.


Over the past day, our team has been continuously monitoring and hunting for IOCs based on our intelligence sources. Affected customers will be notified directly. In addition, the IOCs have been added to the Axon IOCs feed, to allow future tracking with the Hunters platform.

The appendix to the current IOCs can be found on our RR Github page: https://github.com/axon-git/rapid-response/blob/main/CrowdStrike%20July%20Outage%20(C-00000291)/threat_iocs_cs_outage_breach_200724.txt


Please do not hesitate to reach out if you have any questions.

Yours,
Team Axon
Posted Jul 20, 2024 - 11:23 UTC
This incident affected: Rapid Response.