Skip to content
Breaking:

Teen Security Researcher Exposed Microsoft Analytics System Storing 17 Trillion Rows

A 16-year-old bug hunter used an unverified authentication token and custom AI tooling to gain administrative access to Microsoft's internal Titan analytics platform.

By The Company Wire3 min read
Share
Microsoft — Teen Security Researcher Exposed Microsoft Analytics System Storing 17 Trillion Rows
Microsoft — Teen Security Researcher Exposed Microsoft Analytics System Storing 17 Trillion Rows. Photo: TechRadar Pro.

Microsoft has resolved an authentication vulnerability in its internal Titan analytics platform after a 16-year-old security researcher discovered a route to administrative access overseeing an estimated 17.3 trillion data rows and 25,000 user accounts.

The researcher, known online as 'Faav,' received a $5,000 bounty under Microsoft's vulnerability disclosure program, as reported by TechRadar Pro (https://www.techradar.com/pro/security/open-microsoft-database-with-17-trillion-total-rows-and-25-000-user-accounts-hacked-by-a-bored-teenager-but-hes-been-well-paid-for-his-actions). While the researcher characterized the exposure as a potential operational risk rather than an active malicious data breach, the access path reached core administrative controls and internal database metadata.

Titan's primary web portal required internal Microsoft virtual private network access, but its underlying application programming interface remained reachable through an Azure Cloud Services host. A public Swagger documentation file outlined four routes into the system. Three endpoints required Azure Active Directory authentication, but an unauthenticated endpoint designated '/v2/Query' accepted raw SQL commands.

To map the database architecture, Faav analyzed 2023 archived snapshots of Titan via the Wayback Machine, identifying an Apache Superset configuration that exposed 56 backend table definitions. The central flaw involved how Titan validated JSON Web Tokens: the system checked payload parameters such as tenant, application ID, and user identity, but failed to verify the cryptographic signature proving token authenticity.

Submitting an unsigned token permitted arbitrary identity assignment. After initial login attempts using standard email structures failed over a 10-day period, Faav assigned the user principal name parameter to the plain string 'admin'. Titan mapped that identity to local user ID 1, granting full administrative privileges. The resulting access exposed metadata covering roughly 25,000 account and email records, 18,000 employee addresses, 15,000 organization records, and thousands of internal dashboard configurations.

The discovery workflow used Antares, a custom reconnaissance bot built by Faav that orchestrated models from OpenAI (Codex) and Anthropic (Claude) to map subdomains and automate validation testing. The automation stalled when attempting conventional email formatting, requiring manual intervention to input the string that unlocked administrator access.

Faav reported the issue to Microsoft on Sept. 5, 2026, under case 144051. Microsoft requested a halt to testing, collected the researcher's originating IP addresses between Sept. 6 and Sept. 8, locked the vulnerable endpoint on Sept. 9, and issued the bounty on Sept. 17. Faav disclosed that Microsoft exercised editorial review over the public write-up prior to publication.

Sources

  1. TechRadar Pro

Company: Microsoft

Written by

The Company Wire

Newsroom · San Francisco

Inside the companies building what’s next. Reporting on startups, technology, funding and the people shaping them.