A 16-year-old security researcher found an open door to 17 trillion Microsoft records

A 16-year-old security researcher found an open door to 17 trillion Microsoft records

A 16-year-old security researcher found a missing check in a Microsoft API that guarded 17.3 trillion data records.

Security researcher Faav discovered an internal Microsoft analytics service called Titan with an API that never verified login token — or JWT — signatures. By passing a synthetic, unsigned token with the user identity set to "admin", Faav gained administrator access to run raw SQL queries. Microsoft patched the flaw after Faav reported it through their bug bounty program, and no customer data was accessed.

Why it matters: A single skipped signature check can leave massive internal datasets exposed. It is a reminder that backend endpoints remain vulnerable if they blindly trust incoming claims without verifying who signed them.

Know this: Faav used a self-built AI tool called Antares to find the unlinked API host, though breaking the final user check took a late-night manual hunch. Microsoft also exercised editorial control over Faav's write-up before publication, trimming sections and figures.

Always check the signature on the ID before letting anyone into the building.

Sources