The news
A 16-year-old security researcher known online as Faav says a flaw in Titan, an internal Microsoft (MSFT) analytics service, let him act as its administrator and run queries against databases that he estimates hold 17.3 trillion rows. Microsoft locked down the affected endpoint on September 9.
According to the researcher's account, as reported by The Register, Titan checked the contents of the JSON Web Token (JWT), a signed digital pass that proves who a user is, but never checked the token's signature. That meant a token with no valid signature was still accepted. On September 5, he changed the user name inside an unsigned token to "admin" and gained administrator access.
Titan's web interface was reachable only through Microsoft's VPN, the researcher says, but a separate API endpoint connected through Azure Cloud Services was publicly documented. He says an automated bug-hunting tool he built, called Antares, flagged that API on August 25 and spent about ten days probing its login checks before he took the final step himself.
The Register reported that the access reached 17 connected analytics databases spanning 9,863 table names. The researcher puts their combined size at about 17.3 trillion rows, a storage estimate drawn from database metadata. The researcher also described metadata including about 25,000 account and email records, 17,990 employee emails, 15,001 employee organization records, 355 database configurations and 20,979 SQL definitions.
Help Net Security reported that he saw employee details such as job titles, departments and reporting lines, plus two sample rows of Bing analytics containing search, identifier and location data. The researcher says he never touched customer data or personal information, and that the trillion-row figure likely includes historical, duplicated and derived data. Microsoft asked him to stop testing between September 6 and 8, and he says he received a $5,000 bounty on September 17.
In a statement quoted by Help Net Security, Microsoft thanked the researcher and said his coordinated disclosure helped it harden its services. Help Net Security also reported, citing the researcher, that Microsoft had editorial control over his write-up and cut sections and figures and reworded its impact descriptions before publication.
The numbers
- Rows in reachable databases (researcher estimate)
- 17.3 trillion
- Connected databases
- 17
- Employee email records
- 17,990
- Bug bounty paid
- $5,000
- Endpoint locked down
- September 9
Why CEOs should care
For CISOs, the lesson is narrow and urgent: token validation is not the same as token verification. Ask your engineering leads to confirm that every internal service checking JWTs rejects unsigned tokens and tokens signed with an unexpected algorithm. Internal tools often get less review than customer-facing ones, yet this case shows they can sit behind a public API that nobody treats as public.
For boards and CFOs, the bounty is the striking number. A $5,000 payment closed a hole that, by the researcher's count, reached employee directory data and analytics tables at enormous scale. Bug bounty programs and outside testing are cheap compared with the cost of an attacker finding the same gap first. Ask whether your program covers internal services exposed through cloud gateways, not just your flagship products.
For security buyers, the role of an automated hunting tool matters. A teenager's homemade tool spent ten days working through authentication checks alongside him. Attackers have the same kind of automation, so the time between an API becoming reachable and someone probing it is shrinking. Inventory every documented API endpoint, including ones meant for staff only.
The bigger picture
Cloud providers operate under a shared-responsibility model, in which the provider secures its platform and customers secure what they build on it. The Titan case is a reminder that the provider's own internal systems are also software with ordinary bugs. Microsoft's handling, a fix within days and a paid bounty, is how coordinated disclosure is meant to work, though Microsoft's edits to the public write-up mean outsiders see only part of the impact picture.
What’s next
Microsoft has not published a detailed advisory on Titan in the sources we reviewed, and the full scope of what the forged tokens could reach rests largely on the researcher's account. Security teams should watch for any further statement from Microsoft and use the case to review JWT handling in their own internal APIs.
What “Fact-checked” means
Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.
- What we checked
- Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
- How
- A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
- Who
- The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, Hussein Mukhtar. A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
- If something is wrong
- “Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error
Companies in this story








