
16-year-old researcher found a Microsoft bug and reached admin access on databases with 17.3 trillion rows
A 16-year-old researcher who blogs as Faav found an authentication flaw in Microsoft's internal Titan analytics service. Because Titan never verified a login token's signature, he ran admin SQL and reached databases with an estimated 17.3 trillion rows.
A 16-year-old researcher named Faav found an authentication flaw in Microsoft's internal Titan analytics service. It let him take admin access and run SQL without valid credentials, reaching databases with an estimated 17.3 trillion stored rows.
Titan is an internal analytics platform, and Microsoft restricts web-interface access to employees. Working with Antares, an AI "hackbot" he built, Faav found he could reach Titan's API through an Azure Cloud Services host because the service never checked the signature on a login token.
Ten days of authentication errors
The research began on August 25, when Antares found Titan's public API. Over the next 10 days the human and the bot tested the service's JSON Web Token (JWT) authentication checks and email-formatted user principal names (UPNs).
Early on September 5, Faav changed the token's UPN from an email-formatted identity to admin. Titan treated it as a local username, resolved it to local user ID 1, which held an admin role, and allowed him to run SQL. Titan validated the contents of the JWT but never verified the signature. Faav compared the setup to a hotel where every door has a working keycard reader but any keycard opens any room.
He wrote: "It was 2 AM. I wanted to yell, but my parents were asleep. So I just sat there staring at 17,333,335,124,315 and checked the math again."
What the access exposed
The flaw gave him access to Titan's platform metadata database, from which he could query application tables directly. It covered about 25,000 account and email records, 17,990 employee email records, 355 database configurations, 20,979 virtual-dataset SQL definitions, 24,569 dashboards and 425,891 charts.
Titan's user directory exposed employee job titles, departments and management hierarchy, which the researcher noted could help social-engineering attacks, though he never tested that. He also found a Bing analytics sample and checked two rows containing search information and country- or state-level location data.
He then tested 56 routing values from an archived configuration and found 30 still active. Those resolved through 24 configurations to 17 connected analytics databases, for an estimated total of about 17.3 trillion rows, a storage estimate that likely includes historical and duplicated data.
Microsoft's response
Between September 6 and 8, Microsoft asked the teenager to stop testing and requested his IP address to confirm no activity beyond bug-bounty research. A day later the company locked down the endpoint, saying the report "prompted immediate investigation and remediation." Microsoft awarded him $5,000 on September 17.
Microsoft said the coordinated disclosure helped harden its services and protect customers. Faav noted he rewrote his blog post at Microsoft's request, cutting sections and numbers.
SiTech — AI-powered web development
We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.