Teen hacker exploits Microsoft Titan flaw, gains admin rights to trillions of records
A 16-year-old researcher discovered an authentication weakness in Microsoft’s Titan analytics service, allowing admin-level SQL queries on databases estimated to hold 17.3 trillion rows.
Sixteen-year-old security researcher Faav, aided by his AI hackbot Antares, identified that Microsoft’s internal Titan analytics platform failed to verify the signature on JWT login tokens. After ten days of testing, he altered an unsigned token’s user principal name to “admin,” which the system accepted as a local user with ID 1, granting full admin privileges. This allowed him to query Titan’s metadata and reach a collection of analytics databases estimated to contain 17.3 trillion rows of data, including employee records and dashboard definitions.
Microsoft promptly locked down the vulnerable API, requested his IP for verification, and later confirmed the fix. In recognition of the finding, the company paid Faav a $5,000 bounty under its bug-bounty program.
Why it matters
The flaw shows how a simple signature check omission can expose massive corporate data, highlighting the need for rigorous authentication safeguards.
In this story
