Skip to main content

HKCERT urges the public to beware of phishing attempts by hackers exploiting the recent CrowdStrike software update failure incident

HKCERT urges the public to beware of phishing attempts by hackers exploiting the recent CrowdStrike software update failure incident

(Hong Kong, July 22, 2024) Regarding the CrowdStrike software update failure incident on July 19, 2024, the Hong Kong Computer Emergency Response Team Coordination Centre (HKCERT) found reports that criminals are using this incident to launch further cyber attacks, and reminds the public to aware of hackers using phishing attacks to commit fraud.

According to related news, HKCERT has observed the following phishing attempts and other malicious activities that taking advantage of this incident:

  • Sending phishing emails posing as CrowdStrike support to customers
  • Impersonating CrowdStrike staff in phone calls
  • Posing as independent cyber security researchers, claiming to have evidence the technical issue is linked to a cyber attack and offering remediation insights
  • Misleading and selling scripts purporting to automate recovery from the content update issue
  • Distributing trojans malware pretending as recovery tools


HKCERT urges the public to be vigilant against the phishing attacks and recommends that users should:

  • Apply remediation methods provided by official websites (Such as remediation methods provided by CrowdStrike)
  • Obtain software patch update from trusted source (Such as recovery tool provided by Microsoft)
  • Not click any links from untrusted sources, such as emails from unknown senders and advertisements from search engines etc.
  • Adopt anti-phishing features in web browsers to help block phishing attacks
  • Use the free search engine “Scameter” of Cyberdefender.hk to identify frauds and online pitfalls through email, URL or IP address, etc.


For information on malicious domain names related to the phishing campaign, please visit the security bulletin on the HKCERT website:
https://www.hkcert.org/security-bulletin/phishing-alert-phishing-campaigns-and-other-malicious-activities-in-the-theme-of-crowdstrike-outage-event_20240207

To learn more about the security advisory of CrowdStrike denial of service alert, please visit the HKCERT website for the latest news:
https://www.hkcert.org/security-bulletin/crowdstrike-denial-of-service-vulnerability_20240719

Businesses or members of the public who wish to report to HKCERT on cyber security related incidents such as malware, phishing, denial of service attacks, etc. can do so by completing the online form at: https://www.hkcert.org/incident-reporting, or call the 24-hour hotline at 8105 6060. For further enquiries, please contact HKCERT at hkcert@hkcert.org.

- Ends -