16-year-old finds flaw exposing 17T Microsoft records
Original: I Could've Accessed 17T Microsoft Records
Why This Matters
A signature-less JWT in an internal analytics service shows how a single auth gap can threaten enterprise-scale data at rest.
A 16-year-old bug bounty hunter found that a single internal Microsoft analytics service called Titan failed to verify JWT signatures, potentially exposing an estimated 17.3 trillion rows of data. The researcher, known as Faav, reported the flaw responsibly and never accessed customer data. Microsoft acknowledged the finding through its Bug Bounty Program.
On August 25, 2026, Faav — a 16-year-old independent security researcher — and his AI-assisted hunting tool Antares identified an internal Microsoft service called 'Titan.' The frontend required a Microsoft VPN, but a separate API endpoint was publicly discoverable via subdomain enumeration. Its Swagger documentation exposed four routes, one of which — /v2/Query — accepted raw SQL without the Azure AD bearer authentication required by the others.
Over ten days, Antares systematically probed Titan's JWT validation logic, iterating through tenant, audience, and application allowlist errors one at a time. Eventually, Faav discovered the service never actually verified the token's cryptographic signature. That single oversight meant anyone could forge administrator-level credentials and submit arbitrary SQL queries.
To scope the potential damage, Faav used only table metadata and bounded sample rows — no customer data was accessed. He estimates the service could have exposed approximately 17.3 trillion stored records spanning a wide range of Microsoft datasets.
Microsoft confirmed the finding: 'Their submission and coordinated vulnerability disclosure helped us to better protect our customers by hardening our services.' The company had editorial control over the published write-up, redacting certain sections and figures before publication. Faav previously disclosed a Microsoft guest check-in PII leak at age 15.