Analysis10k / Blog
The Story · CRWD

CrowdStrike's Last Two Years: From 'This Will Never Leave My Mind' to 'The Agentic AI Era' — Except in the Fine Print

The short answer

In July 2024, a CrowdStrike software update took down Windows systems worldwide, and the CEO opened the next earnings call with an apology: "the weight of this incident will never leave my mind." One year later, the company was declaring a full growth recovery and discussing the agentic AI era — but its FY2026 10-K still lists the incident as the #1 risk factor, unchanged for the third year running.

The story

June 2024: peak momentum

On the Q1 FY2025 call, CEO George Kurtz opened: "we started the year from a position of momentum and overwhelming strength." Net new ARR grew 22% to $212M, and free cash flow hit $322M — 35% of revenue — both records. The company was already talking about the next milestone beyond "the $1B club": $10B in ARR.

July 19, 2024: the outage

A content update the company shipped took down Windows systems worldwide (the "Channel File 291 Incident"). Six weeks later, at the next earnings call, Kurtz's opening words weren't numbers — they were an apology: "I want to first apologize to everyone impacted by the July 19th incident... the weight of this incident will never leave my mind, and it is my responsibility to ensure this never happens again." Net new ARR growth that quarter was cut in half, from 22% to 11%.

Buying back trust with action

CrowdStrike overhauled the verification process that let the flawed update through and hired two independent outside security firms to audit its code. It rolled out a "customer commitment package" bundling discounts, extra modules, and extended subscription terms. That package stopped customer churn but had a quantified cost — on the Q3 call, the CFO said directly that "the customer commitment package reduced Q3 net new ARR by approximately $25 million." That call's dominant keyword was "trust," alongside repeated references to "the first normal quarter since the incident."

A recovery that wasn't a clean line

As late as June 2025 (Q1 FY2026), net new ARR was $194M — still below the year-earlier, pre-incident figure of $212M. The real inflection came the following quarter: on the August 2025 call, the company explicitly declared it had "returned to year-over-year net new ARR growth a quarter earlier than expected." Net new ARR then hit records for three straight quarters ($221M → $265M → $331M). By the most recent call reviewed (June 2026), the incident wasn't mentioned even once — a word that had appeared 51 times two years earlier had vanished completely.

What the filings still won't drop

Management's story now is a different one entirely — the most recent quarter's call discusses "the agentic AI era" and a 500-basis-point guidance raise, not the outage. But the FY2026 10-K, filed the same period (March 2026), still lists "the July 19 Incident" at the very top of its own summarized risk-factor list — for the third year running, with language essentially unchanged.

What changed in the filings — and what didn't The July 19 Incident risk language first appeared at the top of the FY2025 10-K's risk summary (it wasn't there in FY2024), displacing what had been the #1 risk ("failure to manage rapid growth"). In the FY2026 10-K, 20 months after the incident, it's still the #1 item, word-for-word nearly identical — a company that normally softens or reorders old risks as they fade chose not to here, likely because the related litigation and investigations remain open.
Our take, in one line The gap between the earnings-call story and the 10-K risk-factor story isn't a contradiction — earnings calls sell the future, while 10-K risk factors legally defend against still-open litigation. "Growth is back" and "our biggest risk is still that incident" are simultaneously true.

Guidance scorecard

6 tracked promises, in order made
TargetGuidanceActualResult
Q2 FY2025Revenue $958.3-961.2M$964MBeat
Q3 FY2025Revenue $979.2-984.7M$1.01BBeat
Q4 FY2025Revenue $1,028.7-1,035.4M$1.06BBeat
Q1 FY2026Revenue $1,100.6-1,106.4M$1.1BMet within range
Q4 FY2026 (set a year ahead)"Return to GAAP profitability"GAAP net income $38.7MAchieved
Q1 FY2027Net new ARR guidance$256M, above the top endBeat

5 of 6 beaten, 1 met within range — no misses. But the guided revenue growth rate itself kept sliding (31% → 25% → 22% → 20%) even as each successively lower bar was cleared: "beating guidance" and "growth rate structurally slowing" were both simultaneously true.

Source: each quarter's earnings call transcript, checked against the following quarter's actual results.

Timeline

  • Jun 4, 2024Q1 FY2025 earnings: records across the board; "$10B ARR" mentioned as the next milestone.
  • Jul 19, 2024Channel File 291 Incident — a content-update error causes widespread Windows outages worldwide.
  • Aug 28, 2024Q2 FY2025 earnings: CEO opens with an apology; net new ARR growth cut in half.
  • Nov 26, 2024Q3 FY2025 earnings: "trust" becomes the dominant keyword; customer commitment package's $25M ARR cost disclosed.
  • Mar 4, 2025Q4 FY2025 earnings: guidance beaten; GAAP profitability promised for a year later.
  • Mar 10, 2025FY2025 10-K filed: the July 19 Incident debuts at #1 in the risk-factor summary.
  • Jun 4, 2025Q1 FY2026 earnings: net new ARR ($194M) still below the pre-incident year-ago figure ($212M).
  • Aug 27, 2025Q2 FY2026 earnings — the inflection: "returned to year-over-year net new ARR growth a quarter earlier than expected."
  • Dec 2025–Jun 2026Three consecutive quarters of record net new ARR ($265M → $331M → $256M); incident mentions drop to zero.
  • Mar 5, 2026FY2026 10-K filed: the July 19 Incident remains the #1 risk factor, for the third year running.

Our read

The clearest lesson from these two years is that a company's earnings-call narrative and its legal risk disclosure can diverge completely without either one being dishonest — they're written for different audiences with different purposes. CrowdStrike's business has genuinely recovered, and the legal aftermath genuinely hasn't concluded. Both are true at once.

What we still don't know

  • The final cost of July 19-related securities/class-action lawsuits and DOJ/SEC investigations isn't knowable from the materials reviewed here — both are described as "ongoing" as of the FY2026 10-K and Q1 FY2027 call.
  • Whether the net-new-ARR reacceleration reflects the Falcon Flex bundled-subscription model or simply the natural fading of incident-related drag over time can't be cleanly separated from this data, since both factors overlap in timing.
  • How much incident-period customer churn competitors (Microsoft Defender, Palo Alto Networks) actually absorbed isn't disclosed in CrowdStrike's own filings.
Built from 10-K filings for FY2024 through FY2026 and 9 quarters of earnings call transcripts from Q1 FY2025 (Jun 4, 2024) through Q1 FY2027 (Jun 3, 2026). Tone assessments are qualitative. This is a research summary, not investment advice.

Frequently asked questions

What was the July 2024 CrowdStrike outage?

A flawed CrowdStrike software update took down Windows systems worldwide in July 2024 — the CEO opened the next earnings call with an apology, saying "the weight of this incident will never leave my mind."

Has CrowdStrike fully recovered from the 2024 outage?

By results and management tone, largely yes — one year later the company was declaring a full growth recovery. But its FY2026 10-K still lists the incident as the #1 risk factor, unchanged for the third year running, showing the legal and reputational tail is longer than the business recovery.

What sources does this analysis draw from?

This piece is built from CrowdStrike's 10-K filings for FY2024 through FY2026 and 9 quarters of earnings call transcripts from June 2024 to June 2026.