10-Q: CrowdStrike Q3 2025: Revenue Growth Amidst Rising Losses

Sentiment:

Quarterly Report


CrowdStrike reported a 22% increase in total revenue for Q3 2025, reaching $1.23 billion, but net losses more than doubled to $34 million, impacted by a strategic restructuring and ongoing legal costs from the July 19 Incident.

Delay expectedThe July 19 Incident has resulted in delays in creating sales opportunities and longer sales cycles, including delays in customer purchasing decisions.Sales cycles may be elongated in future periods due to the July 19 Incident.The EU's Network and Information Security Directive II requires EU member states to issue implementing legislation by October 2024, which could impact operations.
Worse than expectedNet loss for the three months ended October 31, 2025, more than doubled to $34.0 million compared to $16.8 million in the prior year.For the nine months ended October 31, 2025, the company swung to a significant net loss of $222.6 million from a net income of $76.1 million in the prior year.Operating expenses, particularly general and administrative, increased substantially due to costs associated with the July 19 Incident and the strategic plan, outpacing revenue growth.The July 19 Incident has led to delays in sales opportunities, longer sales cycles, increased contraction, and decreased upsell dollar values, indicating a negative impact on core business operations.

Summary

  • Total revenue for the three months ended October 31, 2025, increased by 22% year-over-year to $1.23 billion.
  • Subscription revenue grew 21% to $1.17 billion, while professional services revenue increased 38% to $65.5 million.
  • Net loss for the quarter more than doubled to $34.0 million, compared to a net loss of $16.8 million in the prior year.
  • For the nine months ended October 31, 2025, total revenue increased 21% to $3.51 billion, but the company swung to a net loss of $222.6 million from a net income of $76.1 million in the prior year.
  • Annual Recurring Revenue (ARR) grew 23% year-over-year to $4.92 billion as of October 31, 2025.
  • Net new ARR added for the three months ended October 31, 2025, was $265.3 million, up from $153.0 million in the prior year.
  • Operating expenses increased significantly, with sales and marketing up 18%, research and development up 26%, and general and administrative up 32% for the quarter.
  • The company incurred $101.6 million in expenses related to the July 19 Incident and $45.5 million in charges for a strategic plan involving a 5% workforce reduction during the nine-month period.
  • Cash and cash equivalents stood at $4.80 billion as of October 31, 2025.
  • Remaining performance obligations totaled $7.9 billion as of October 31, 2025, with 51% expected to be recognized in the next 12 months.

Sentiment

Score: 4

Explanation: While revenue and ARR growth remain strong, the significant increase in net losses, primarily driven by the July 19 Incident and strategic restructuring costs, indicates substantial operational and financial headwinds. The ongoing legal and reputational risks from the incident, coupled with elongated sales cycles, present a challenging outlook despite underlying business expansion and strategic acquisitions.

Positives

  • Strong revenue growth of 22% year-over-year for the quarter and 21% for the nine months.
  • Annual Recurring Revenue (ARR) increased by 23% year-over-year to $4.92 billion.
  • Net new ARR for the quarter was $265.3 million, a significant increase from $153.0 million in the prior year.
  • Professional services revenue showed robust growth of 38% for the quarter and 30% for the nine months.
  • Net cash provided by operating activities increased to $1.11 billion for the nine months, up from $1.04 billion.
  • Cash and cash equivalents increased to $4.80 billion, indicating strong liquidity.
  • Successful integration of four acquisitions (Pangea, Onum, Adaptive Shield, Flow Security) expanding AI detection, telemetry management, SaaS security posture, and data security solutions.
  • Dollar-based net retention rate increased in the quarter ended October 31, 2025, over the prior quarter.

Negatives

  • Net loss more than doubled for the three months ended October 31, 2025, to $34.0 million.
  • Swung to a significant net loss of $222.6 million for the nine months ended October 31, 2025, compared to a net income of $76.1 million in the prior year.
  • Operating expenses increased substantially across all categories, outpacing revenue growth.
  • Subscription gross margin slightly decreased by one percentage point for the nine months ended October 31, 2025, to 77%.
  • Professional services gross margin decreased by four percentage points for the nine months ended October 31, 2025, to 17%.
  • The July 19 Incident continues to result in significant legal and professional services expenses, delays in sales opportunities, longer sales cycles, increased contraction, and decreased upsell dollar values due to customer commitment packages.
  • The strategic plan resulted in a reduction of approximately 500 positions (5% of global workforce) and incurred $45.5 million in charges.
  • Interest income decreased for both the three and nine months ended October 31, 2025, driven by lower market rates despite a higher cash balance.

Risks

  • The July 19 Incident has had, and is expected to continue to have, an adverse effect on business, sales, customer and partner relations, reputation, results of operations, and financial condition, including ongoing lawsuits and inquiries from the DOJ and SEC.
  • Inability to manage rapid future growth effectively could adversely affect business and results of operations.
  • History of losses and potential inability to achieve or sustain profitability in the future.
  • Risk that organizations do not adopt cloud-based SaaS-delivered endpoint security solutions.
  • Failure to successfully enhance existing products and introduce new ones in response to rapid technological changes and evolving security threats.
  • Inability to attract new customers or retain existing customers and expand their subscriptions.
  • Long and unpredictable sales cycles requiring considerable time and expense.
  • Intense competition in the cybersecurity market, potentially leading to loss of market share or competitive pricing pressure.
  • Solutions failing or being perceived to fail to detect or prevent incidents, or having defects, errors, or vulnerabilities, harming brand and reputation.
  • As a cybersecurity provider, the company is a target of cyberattacks, and compromise of internal networks or systems could damage reputation and financial results.
  • Reliance on third-party data centers (e.g., Amazon Web Services) and own colocation data centers, with any disruption negatively affecting performance and reliability.
  • Reliance on key technical, sales, and management personnel, with loss of key employees harming the business.
  • Inability to attract and retain qualified personnel.
  • Significant fluctuations in results of operations, making future results difficult to predict.
  • Inability to maintain and enhance CrowdStrike and Falcon brands and reputation.
  • Claims by others of intellectual property infringement.
  • Compliance with stringent, complex, and evolving data privacy and security laws (e.g., GDPR, CCPA, U.K. Data Use and Access Act 2025, EU AI Act).
  • Failure to comply with laws and regulations applicable to the business, including anti-corruption and export controls.
  • Involvement in other litigation.
  • Warranty claims, product returns, and product liability claims from real or perceived defects or misuse.
  • Difficulties in identifying and integrating future acquisitions, potentially diverting management attention, disrupting business, and diluting stockholder value.
  • Risks associated with international operations and expansion.
  • Dependence on sales to government organizations, with changes in contracting or fiscal policies posing risks.
  • Inability to timely and cost-effectively scale and adapt existing technology.
  • Reliance on a limited number of suppliers for equipment components.
  • Exposure to credit risks of customers and end-users.
  • Inability to protect and enforce intellectual property rights.
  • Liability or adverse effects from the use of AI technologies.
  • Failure to meet service level commitments.
  • Volatility in the market price of common stock.
  • Share repurchase program may not result in benefits to stockholder value.
  • Sales of substantial amounts of common stock could reduce price and dilute ownership.
  • Lack of dividends in the foreseeable future.
  • Provisions in charter documents and Delaware law could make acquisition difficult.
  • Indebtedness could adversely affect financial condition, with risks of not generating sufficient cash to service debt or breaching covenants.
  • Failure to maintain an effective system of internal controls.
  • Risks associated with equity investments.
  • Costs and risks related to environmental, social, and governance factors.
  • Risks of catastrophic events.

Future Outlook

CrowdStrike expects to continue investing significantly in sales and marketing and research and development to support future growth. The company anticipates general and administrative expenses to increase due to public company costs and expenses related to the July 19 Incident. The July 19 Incident is expected to continue to adversely affect key metrics and results of operations in future periods, including elongated sales cycles and potential customer churn. The company also expects to incur significant legal and professional services expenses related to the incident. The strategic plan is aimed at yielding greater efficiencies as the company scales.

Management Comments

  • "We reinvented cybersecurity for the cloud era and transformed the way cybersecurity is delivered and experienced by customers."
  • "Our approach has defined a new category called the Security Cloud, which has transformed the cybersecurity industry."
  • "The more data that is fed into our Falcon platform, the more intelligent our Security Cloud becomes, and the more our customers benefit, creating a powerful network effect that increases the overall value we provide."
  • "We believe our future success depends in large part on the growth in the market for cloud-based SaaS-delivered endpoint security solutions."
  • "Our future growth depends in large part on our ability to acquire new customers."
  • "Our ability to increase revenue depends in large part on our ability to retain our existing customers and increase the size of their subscriptions."
  • "We believe that our market opportunity is large and requires us to continue to invest significantly in sales and marketing efforts to further grow our customer base, both domestically and internationally."
  • "We expect our general and administrative expenses to increase in dollar amount for the foreseeable future given the additional expenses for accounting, compliance, and investor relations as we grow."
  • "It is not reasonably possible to quantify the precise impact of the July 19 Incident, but the incident has adversely affected our results of operations, and we currently expect a number of factors relating to the incident to adversely affect our key metrics and results of operations in future periods."
  • "While we have maintained high dollar-based gross retention rates following the incident, we have experienced delays in creating sales opportunities and longer sales cycles, including delays in customer purchasing decisions."
  • "The Plan resulted in a reduction of roles representing approximately 500 positions, or 5%, of the Company's global workforce."

Industry Context

CrowdStrike operates in the rapidly evolving and intensely competitive cybersecurity market, which is transitioning towards cloud-based SaaS-delivered endpoint security solutions. The company positions its AI-native Falcon platform as a leader in the 'Security Cloud' category, aiming to leverage cloud-scale AI and a unified platform for XDR (Extended Detection and Response). The industry is characterized by rapid technological changes, evolving security threats, and increasing demand for comprehensive security solutions across endpoints, cloud workloads, identity, and data. The company's strategy of 'land-and-expand' by offering modular cloud solutions aligns with broader industry trends of platform consolidation and integrated security offerings. However, the market also faces challenges such as customer hesitancy to abandon legacy on-premise products, intense competition from both traditional antivirus providers and emerging cloud security vendors, and the need to continuously innovate against sophisticated cyber attackers. The increasing focus on AI in cybersecurity, as highlighted by CrowdStrike's acquisitions in AI detection and telemetry management, reflects a key industry trend. Regulatory scrutiny around data privacy (GDPR, CCPA) and AI governance (EU AI Act) is also a significant factor shaping the industry landscape.

Comparison to Industry Standards

  • CrowdStrike's 23% year-over-year ARR growth is strong, often exceeding the growth rates of more mature cybersecurity companies but potentially in line with or slightly below some hyper-growth SaaS peers depending on the specific quarter.
  • The gross margin of 75% is competitive within the SaaS cybersecurity sector, though the slight decline in subscription and professional services gross margins for the nine-month period suggests cost pressures that bear watching, especially compared to peers known for high-efficiency cloud operations.
  • The substantial increase in operating expenses, particularly R&D (35% increase for 9 months) and G&A (51% increase for 9 months), reflects aggressive investment in innovation and the significant costs associated with the July 19 Incident. This level of expense growth, especially the G&A spike, is likely higher than many industry peers not facing similar legal and reputational challenges.
  • The July 19 Incident and its ongoing impacts (lengthened sales cycles, increased contraction) represent a unique operational and reputational challenge that differentiates CrowdStrike from direct competitors like Zscaler, SentinelOne, or Palo Alto Networks, who have not reported similar widespread service disruptions.
  • The strategy of acquiring companies like Pangea (AI detection), Onum (telemetry pipeline), Adaptive Shield (SaaS security posture), and Flow Security (data security) aligns with broader industry trends of platform consolidation and expanding XDR capabilities, a common strategy seen in companies like Palo Alto Networks (acquiring numerous startups) or Microsoft (integrating security features).
  • The 5% workforce reduction indicates a focus on efficiency, a trend observed across the tech sector as companies optimize operations in a tighter economic environment, similar to actions taken by other large tech firms.
  • The company's strong cash position ($4.8 billion) and positive operating cash flow ($1.11 billion for nine months) are positive indicators of financial health, often exceeding the liquidity profiles of smaller, less established cybersecurity firms.

Corporate Governance

Change TypeDescriptionEffective DateImpact Assessment
Plan AdoptionThe board of directors adopted the 2019 Equity Incentive Plan and 2019 Employee Stock Purchase Plan (ESPP).May 2019Aimed at attracting and retaining talent through equity compensation.
Plan AmendmentThe ESPP was amended and restated by the compensation committee and approved by stockholders.May 2021 / June 2021Clarified annual share increase limits for the ESPP, impacting employee stock purchases.
Stock Class ConversionAll outstanding Class B common stock was automatically converted into Class A common stock.December 11, 2024Simplified capital structure, eliminating dual-class share voting rights.
Controls EvaluationManagement, with CEO and CFO participation, evaluated the effectiveness of disclosure controls and procedures and internal control over financial reporting, concluding they were effective at the reasonable assurance level.October 31, 2025Indicates adherence to regulatory compliance for financial reporting, though inherent limitations exist.
Bylaw AmendmentAmended and restated bylaws designate the Court of Chancery of the State of Delaware as the exclusive forum for certain disputes and federal district courts for Securities Act claims.Not specified, but in effect as of filingAims to centralize litigation and potentially limit stockholders' ability to choose a favorable judicial forum.

Legal Proceedings

  • A putative class action lawsuit was filed on July 30, 2024, alleging federal securities law violations related to the July 19 Incident. An amended complaint was filed on January 21, 2025, and a motion to dismiss was filed by defendants on April 7, 2025.
  • Two putative class action lawsuits related to passenger airline flight disruptions allegedly caused by the July 19 Incident were filed in August 2024, consolidated on November 6, 2024. A consolidated complaint was filed on December 6, 2024, asserting negligence and public nuisance. The district court granted a motion to dismiss on June 18, 2025, but plaintiffs filed a notice of appeal on June 25, 2025.
  • Multiple derivative lawsuits were filed against officers and directors in September 2024 and April/July 2025, alleging breach of fiduciary duty, unjust enrichment, and federal securities law violations related to the July 19 Incident. These have been consolidated and stayed pending resolution of the putative securities class action.
  • Delta Airlines, Inc. filed a complaint on October 25, 2024, alleging computer trespass, breach of contract, intentional misrepresentation/fraud by omission, strict-liability product defect, gross negligence, and deceptive and unfair business practices related to the July 19 Incident. A motion to dismiss was granted in part and denied in part on May 16, 2025, with discovery ongoing.
  • The company has received requests for information from the U.S. Department of Justice and the U.S. Securities and Exchange Commission relating to revenue recognition, ARR reporting for certain transactions, and the July 19 Incident. The company is cooperating and providing information.
  • Some customers and third parties have asserted claims against the company related to the July 19 Incident.

Related Party Transactions

  • The company manages CrowdStrike Falcon Fund LLC and CrowdStrike Falcon Fund II LLC (Falcon Funds), which invest in privately-held companies. Entities associated with Accel also commit up to $10.0 million and $50.0 million, respectively, to these funds and collectively own 50% of the sharing percentage. The company consolidates these funds.

Stakeholder Impact

  • Shareholders face potential dilution from future equity financings, volatility in stock price due to market factors and the July 19 Incident, and reliance on stock appreciation for returns as no dividends are paid. The share repurchase program aims to return value but its effectiveness is not guaranteed.
  • Employees experienced a workforce reduction of 5% (500 positions) due to a strategic plan. There is intense competition for skilled personnel, and potential impacts on retention and recruitment due to stock price volatility and the strategic plan.
  • Customers were impacted by the July 19 Incident, leading to system crashes, potential deferral of purchasing decisions, longer sales cycles, and customer commitment packages (discounts, extensions). There is a risk of losing trust due to product defects or security incidents.
  • Partners' ability or willingness to promote products was negatively impacted by the July 19 Incident. The company relies on channel partners for sales and support.
  • Creditors are exposed to the company's indebtedness of $750.0 million in Senior Notes and a $750.0 million revolving credit facility. Covenants in debt instruments restrict operations.
  • Regulatory Authorities are actively scrutinizing the company through ongoing inquiries from the DOJ and SEC regarding revenue recognition, ARR, and the July 19 Incident. The company must also comply with evolving data privacy, security, and AI regulations.

Next Steps

  • Continue to invest significantly in sales and marketing efforts to grow the customer base domestically and internationally.
  • Continue investing in research and development to enhance the technology platform and product functionality.
  • Potentially pursue acquisitions of businesses, technologies, and assets that complement and expand the Falcon platform.
  • Manage and mitigate ongoing legal proceedings and inquiries related to the July 19 Incident.
  • Monitor and adapt to new accounting pronouncements (ASU 2025-06, ASU 2025-05, ASU 2024-03, ASU 2023-09).
  • Address the appeal in the consolidated class action lawsuit related to airline disruptions.
  • Respond to the litigation demand from one of the plaintiffs in the derivative lawsuits.
  • Continue to cooperate with requests for information from the U.S. Department of Justice and the U.S. Securities and Exchange Commission.
  • Evaluate the impact of the U.K.'s Data Use and Access Act 2025 and the EU's AI Act on operations and compliance.
  • Potentially repurchase shares under the $1.0 billion Share Repurchase Program.

Key Dates

DateDescription
November 7, 2011Company formed.
April 2019Entered into Credit Agreement for revolving line of credit.
May 20192019 Equity Incentive Plan and 2019 Employee Stock Purchase Plan (ESPP) adopted by board.
June 10, 20192011 Plan terminated; ESPP became effective.
January 4, 2021Amended and restated credit agreement (A&R Credit Agreement) for $750M revolving line of credit.
January 20, 2021Issued $750.0 million in 3.00% Senior Notes maturing February 2029.
May 2021ESPP amended and restated by compensation committee.
June 2021Amended and restated ESPP approved by stockholders.
January 6, 2022Modified A&R Credit Agreement (Amended A&R Credit Agreement).
February 1, 2022Vesting commencement date for first tranche of Special PSU Awards.
February 1, 2023Vesting commencement date for second tranche of Special PSU Awards.
February 1, 2024Vesting commencement date for third tranche of Special PSU Awards.
March 26, 2024Acquired 100% of Flow Security Ltd.
July 19, 2024Released a content configuration update for Falcon sensor that resulted in system crashes for certain Windows systems (July 19 Incident).
July 30, 2024Putative class action lawsuit filed against the company and officers in federal court related to July 19 Incident.
August 5, 2024Putative class action filed against CrowdStrike, Inc. related to passenger airline flight disruptions from July 19 Incident.
August 19, 2024Second putative class action filed against the company and CrowdStrike, Inc. related to passenger airline flight disruptions from July 19 Incident.
September 4, 2024First derivative lawsuit filed against officers and directors related to July 19 Incident.
September 11, 2024Second derivative lawsuit filed against officers and directors related to July 19 Incident.
September 20, 2024Third derivative lawsuit filed against officers and directors related to July 19 Incident.
October 25, 2024Delta Airlines, Inc. filed a complaint against CrowdStrike, Inc. related to July 19 Incident.
November 6, 2024Two airline disruption lawsuits consolidated.
November 20, 2024Acquired 100% of A.S. Adaptive Shield Ltd.
November 21, 2024Three derivative lawsuits consolidated and stayed.
December 6, 2024Consolidated class action complaint filed for airline disruptions.
December 11, 2024All outstanding Class B common stock automatically converted to Class A common stock.
December 16, 2024CrowdStrike, Inc. filed a motion to dismiss Delta's complaint.
January 2025ASU 2025-01 issued, clarifying effective date of ASU 2024-03.
January 21, 2025Amended complaint filed in federal securities class action lawsuit.
February 2025Released security fix and advisory for transport layer security issue impacting Falcon Linux sensors.
February 1, 2025Vesting commencement date for fourth tranche of Special PSU Awards.
February 4, 2025Company and CrowdStrike, Inc. filed motion to dismiss consolidated airline disruption complaint.
April 7, 2025Defendants filed a motion to dismiss the federal securities class action lawsuit.
April 9, 2025Another derivative lawsuit filed in District of Delaware.
April 10, 2025Two additional derivative lawsuits filed in Western District of Texas.
May 6, 2025Announced a strategic plan (the Plan) to evolve operations and reduce workforce by 5%.
May 16, 2025CrowdStrike, Inc.'s motion to dismiss Delta's complaint granted in part and denied in part.
May 22, 2025Derivative lawsuit in District of Delaware voluntarily dismissed without prejudice.
May 23, 2025Two additional derivative lawsuits consolidated and stayed.
June 2025Board authorized a share repurchase program of up to $1.0 billion.
June 18, 2025District court granted motion to dismiss consolidated airline disruption complaint and entered a final judgment.
June 19, 2025U.K.'s Data Use and Access Act 2025 became law.
June 25, 2025Plaintiffs filed notice of appeal to Fifth Circuit for airline disruption lawsuit.
June 28, 2025United States and G7 countries announced agreement on Pillar Two global tax reform.
July 3, 2025Additional derivative lawsuit filed in Delaware Court of Chancery.
July 4, 2025One Big Beautiful Bill Act (OBBBA) tax reform legislation enacted in the United States.
July 17, 2025Additional derivative lawsuit filed in Delaware Court of Chancery.
July 18, 2025Consolidated derivative lawsuits stayed pending resolution of securities class action.
August 18, 2025Two Delaware derivative lawsuits consolidated and stayed.
September 12, 2025Acquired 100% of Onum Technology Inc.
September 2025FASB issued ASU 2025-06, Intangibles Goodwill and Other Internal-Use Software.
September 26, 2025Acquired 100% of Pangea Cyber Corporation.
October 31, 2025End of current reporting period.
November 25, 2025Number of shares of common stock outstanding was 252,098,440.
December 2, 2025Filing date of this 10-Q.
December 15, 2025Effective date for ASU 2025-05 for annual periods.
January 2, 2026Maturity date of Revolving Facility.
February 15, 2029Maturity date of Senior Notes.
December 15, 2026Effective date for ASU 2024-03 for annual periods.
December 15, 2027Effective date for ASU 2025-06 for annual periods.

Recommendation

hold

CrowdStrike demonstrates strong underlying business momentum with robust revenue and ARR growth, indicating continued market demand for its cybersecurity solutions. The company's strategic acquisitions further strengthen its platform capabilities. However, the significant increase in net losses, primarily driven by the July 19 Incident and associated legal/remediation costs, along with the strategic workforce reduction, introduces considerable financial and operational uncertainty. While the long-term growth trajectory remains appealing, the immediate future is clouded by these substantial headwinds and ongoing legal and reputational risks. Investors should hold to monitor the company's ability to navigate these challenges, manage costs, and demonstrate a clear path back to sustained profitability, while capitalizing on its market leadership and innovation.

Keywords

Cybersecurity, Cloud Security, Endpoint Security, SaaS, AI-native platform, XDR, CrowdStrike Falcon, ARR, Net Loss, SEC Filing, 10-Q, Risk Management, Corporate Governance, Acquisitions, July 19 Incident, Data Privacy, Financial Performance

Disclaimer:The information provided here is for general informational purposes only and does not constitute financial advice, recommendation, or endorsement of any kind. It may contain errors or omissions. You should not rely on this information to make financial decisions. Always seek the advice of a qualified financial professional before making any investment or financial decisions. Use of this information is at your own risk.