LiMP VPN
← All news

Teen Hacker Accessed 17.3 Trillion Rows of Microsoft Data

Teen Hacker Accessed 17.3 Trillion Rows of Microsoft Data

In short: A 16-year-old security researcher known as Faav discovered that Microsoft's Titan analytics service never verified the cryptographic signature of its login tokens. By forging a JWT token with algorithm "none" and an admin field, he gained administrator access and potential reach into 17 connected databases holding an estimated 17.3 trillion rows, including metadata on nearly 18,000 Microsoft employee accounts. Microsoft fixed the flaw within four days and paid the researcher a $5,000 bug bounty.

What the teenager actually found

Titan is an internal Microsoft analytics service used to work with large volumes of corporate data. Faav says he has spent over a year testing systems at major companies using Antares, an automated bug-hunting agent he built himself that scans services for common configuration mistakes. In Titan's case, the flaw turned out to be one of the oldest in web security: the service accepted login tokens without ever checking their signature. That meant the token's contents — including the field describing the user's role — could be changed freely without needing a cryptographic key.

Faav created an unsigned token using algorithm "none" with the username field set to admin, and the service accepted the request as coming from an administrator. That gave access to 17 connected databases with an estimated 17.3 trillion rows combined, plus a directory of roughly 25,000 application accounts, including nearly 18,000 records with Microsoft employee email addresses. The researcher said he also confirmed that data linked to Bing search could theoretically be reached through the system, but limited his testing to single demonstration queries rather than bulk extraction.

Why this isn't an isolated case

Unverified token signature checks are a well-documented class of vulnerability that shows up for years across systems of every size, from small startups to the largest tech companies' infrastructure. What makes the case notable isn't so much the headline number (17 trillion rows sounds alarming, but most of it is metadata and internal tables rather than end-user personal data) as how much automated vulnerability hunting — including with AI agents — is lowering the bar for finding flaws like this. We've covered a related trend before: the rising share of exploited vulnerabilities that were originally discovered with AI assistance.

Microsoft responded quickly: after being notified on September 5, 2026, the service was locked down and fixed within four days, and the researcher received a bug bounty payout — standard practice for responsible disclosure, where a finding is reported to the vendor before publication rather than sold or released immediately.

What it means for everyday users

The incident didn't directly expose Microsoft customers' personal data — the access was primarily to internal infrastructure and employee-related records. But it's a reminder that even the largest tech companies have basic authentication-checking mistakes slip through, so it's unwise to assume your data in any cloud service is protected by default. The more services and apps that hold your data, the higher the cumulative odds that at least one of them turns out vulnerable, through no fault of your own.

We've covered similar cases before on the LiMP VPN blog — including how modern attacks on cloud infrastructure and third-party service leaks typically unfold.

How to reduce your own exposure

At the user level, you can't fully prevent incidents like this — they happen on the company's infrastructure side, not on your device. But you can limit the fallout: use unique passwords per service with a password manager, enable two-factor authentication wherever it's offered, and stay wary of emails or notifications that reference a "data breach" and urge you to click a link immediately — that's exactly the kind of follow-up phishing campaign that tends to ride on the back of high-profile breach news.

A separate, service-independent layer of protection is controlling your own network traffic. The LiMP VPN app encrypts the connection between your device and the internet and hides from your ISP or a public Wi-Fi owner which sites and services you use. It won't fix a vulnerability on a cloud provider's side, but it does cover the network half of your privacy when dealing with sensitive services.

Plans from 69 ₽/month, a verified no-logs policy: LiMP VPN pricing.

Sources