Open Microsoft database with 17 trillion total rows and 25,000 user accounts hacked by a bored teenager — but he’s been well-paid for his actions
- 16-year-old bug hunter gained admin access to Microsoft’s internal Titan analytics service through an unsigned login token that the service never checked
- From there, an estimated 17.3 trillion stored rows and a metadata table of about 25,000 accounts were reachable, though Faav says he only sampled data, avoiding dumping records or touching customer data
- Microsoft has hardened the service’s security since and paid a $5,000 bounty, downplaying the trillion-row figure as a theoretical storage estimate rather than actual exposed customer information
A 16-year-old bug hunter who goes by ‘Faav’ logged into Microsoft‘s internal Titan analytics platform using a token that no real credentials should have produced, and from an administrator’s seat, he could see an estimated 17.3 trillion stored rows and a metadata table listing roughly 25,000 accounts.
Microsoft paid him $5,000 and has since closed the hole, prompting him to detail his findings online even as he describes the impact as hypothetical rather than a consequential breach.
He said the way in was a single missed check, which let him access a system that should otherwise have been locked to Microsoft staff behind a VPN.
Latest Videos FromTechRadar
A simple mistake that could have catastrophic in the wrong hands
Microsoft’s Titan sits behind a “VPN required” page meant to keep its web interface to Microsoft staff, but its API was still reachable through an Azure Cloud Services host, and the Swagger file describing that API listed four access routes.
Three demanded Azure AD authentication. One, “/v2/Query”, did not, and it accepted raw SQL, giving Faav a way in. He wasn’t moving blind either; to learn what tables to ask for, Faav pulled 2023 snapshots of Titan’s pages from the Wayback Machine and recovered an archived Apache Superset configuration listing 56 table definitions.
The deeper flaw was in how the service read login tokens. As Faav explained, Titan validated the contents of a JSON Web Token- the tenant, audience, application ID, and user- but never verified the cryptographic signature that is supposed to prove the token is genuine, offering the analogy of a hotel where every door has a working keycard reader but any keycard opens any room, making it essentially an ineffective check at best.
He submitted an unsigned token, and then, after ten days of failed logins, stopped treating the “upn” field as a real email identity and set it to the plain string admin. Titan resolved that to local user ID 1, which carried the admin role, and ran his query.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
The saga has an interesting AI subplot: Faav hunts with an orchestration bot he built called Antares, which he says was running OpenAI’s Codex and Anthropic’s Claude. Antares did the grunt work, enumerating subdomains, mapping the attack surface, and pushing the forged token through four layers of validation, one error message at a time.
It did get stumped, however, when it tried to find a UPN; it got stuck attempting only email addresses. That is not a problem per se for what was essentially a brute-force-style approach using the most probable email addresses, but it took manual intervention from the hacker to try ‘admin’ instead as an alternative to finally get access.
Admin access opened Titan’s platform metadata database, which, according to his tally, held about 25,000 account and email records, roughly 18,000 employee email records, 15,000 organization records, and tens of thousands of dashboards, charts, and dataset definitions.
The disclosure moved quickly once he reported it on September 5 2026 as case 144051. Microsoft asked him to stop testing and hand over his IP address between September 6 and 8, locked the endpoint on September 9, and paid out on September 17.
There is an interesting caveat, however: Faav discloses that Microsoft had editorial control over his write-up, cutting sections and figures and reshaping how it described the impact before he published, so the most authoritative account of this bug has already been shaped by the company it embarrasses. None of this makes the bug small, however: one unverified signature that made every other access control in Titan pointless is a potential security nightmare, nipped in the bud by a teenager who has had success with similar bugs at Amazon, Google, and Adobe, in addition to a prior disclosure at Microsoft.

Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.
Source
16-year-old bug hunter gained admin access to Microsoft’s internal Titan analytics service through an unsigned login token that the service never checked From there, an estimated 17.3 trillion stored rows and a metadata table of about 25,000 accounts were reachable, though Faav says he only sampled data, avoiding dumping records…
Recent Posts
- ‘The keyword is speed to power’: Dell, Apollo, and Jera launch a $140 billion plan to build up to 4GW of AI data centers across Japan and Asia
- Reverse-engineered games: All the news on video game decomps, recomps, VR and web and 3D ports
- Open Microsoft database with 17 trillion total rows and 25,000 user accounts hacked by a bored teenager — but he’s been well-paid for his actions
- This startup is issuing AI-generated acne prescriptions
- Instagram is toying with a read-only mode for Plus subscribers
Archives
- October 2026
- September 2026
- August 2026
- July 2026
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023