Teenage Researcher Finds Access to a Microsoft Database With 17 Trillion Rows

A teenage security researcher known as Faav says he discovered a flaw in Microsoft’s internal Titan analytics platform that potentially gave him access to a database with 17 trillion rows and information tied to roughly 25,000 user accounts. According to the account published by the researcher himself, the issue was related to insufficient validation of users and JWT tokens, and it ended with a $5,000 reward under Microsoft’s bug bounty program.

The Microsoft Titan flaw in 30 seconds

  • Faav, a teenage researcher, says he found a flaw in Microsoft’s internal Titan platform.
  • The system potentially gave access to a database with about 17 trillion rows and data on 25,000 users.
  • The issue described would be related to insufficient validation of identity and JWT tokens.
  • The researcher used his own AI bot, called Antares, to automate part of the security analysis work.
  • Microsoft reportedly acknowledged the finding with a $5,000 reward.

The case once again highlights a recurring problem in enterprise systems: correct authentication doesn’t end once a user presents a valid token. It’s also necessary to verify that the token corresponds to the user, service, and permissions it’s meant to use.

The account comes from the researcher himself, who explains in a technical write-up how he analyzed Titan and how he ended up finding a path to access, by his description, a far greater amount of information than should be available to a regular user.

A year of hunting for bugs while still studying

Faav says he has spent about a year researching products from large companies while juggling these activities with his studies. The companies he mentions include Microsoft, Amazon, Google, and Adobe.

His work focuses on vulnerability reward programs, known as bug bounties. In these programs, companies offer financial rewards to researchers who find and responsibly disclose security issues in their products or infrastructure.

In Microsoft’s case, the researcher ended up analyzing Titan, an analytics platform that, according to his description, wasn’t meant for public access.

The size of the system was one of the most striking elements of the discovery. The associated database contained, according to Faav, about 17 trillion rows.

That figure doesn’t mean the researcher downloaded all 17 trillion records. The available account describes potential access to the infrastructure and exposure of information, not a complete extraction of that volume of data.

Also mentioned are about 25,000 user accounts, which according to the account were tied to employee information.

That distinction matters, because the total volume of a database and the data an attacker can actually query aren’t necessarily the same thing.

The problem was in how users were validated

The researcher attributes the access to a combination of authentication and authorization issues.

One of the elements flagged is the validation of JWT tokens, short for JSON Web Token. These tokens are commonly used to prove the identity and permissions of a session or application when different services need to communicate with each other.

A properly validated JWT must check, among other things, that it comes from a trusted source, that it hasn’t been tampered with, that it matches the right context, and that it contains the conditions needed to access the requested resource.

According to Faav’s account, Titan wasn’t correctly performing some of these checks. That would have allowed authentication information to be used in a way the system didn’t expect.

The original write-up describes the problem as “sub-optimal” user validation, though the full technical details should be interpreted within the research published by the researcher himself.

The potential consequence was especially significant because the system was connected to a large-scale data infrastructure.

Instead of limiting access to the set of information tied to a specific identity, the flaw, according to the researcher, allowed the scope of queries to be considerably expanded.

Antares, the AI bot that automated part of the research

Another aspect of the case is the tool used during the research.

Faav developed Antares, an AI-based bot he uses as an orchestrator to automate part of the security analysis work.

The goal wasn’t to fully replace the researcher, but to automate repetitive tasks related to vulnerability hunting. In a security research process, this kind of tool can help review endpoints, analyze responses, test different scenarios, and organize results.

The researcher himself describes Antares as a kind of tool for handling the most repetitive security work.

Using AI doesn’t mean the discovery was made automatically. The account credits Faav with the research and with building the tools used throughout the process.

The combination is representative of a broader shift that’s already visible across the industry: as detailed in our report on how AI is fueling a surge in bug hunting across Linux, Windows, Android, and other systems, individual researchers can now build specialized agents capable of running certain checks continuously and at a scale that would previously have required far more manual work.

ElementRole in the case
TitanInternal analytics platform investigated
JWTToken technology used in authentication
AntaresAI bot built to automate security tasks
17 trillion rowsVolume of data that, according to Faav, was available on the infrastructure
25,000 accountsUser accounts the researcher says he found
$5,000Reward tied to the discovery

A $5,000 reward

The discovery ended up inside Microsoft’s bug bounty program, with a $5,000 payout, according to the information provided about the case.

Bug bounty programs work as a channel for outside researchers to disclose vulnerabilities to companies before they can be exploited publicly.

In situations like this, the value of a finding doesn’t depend solely on the number of potentially exposed records. The type of access achieved, how easy it is to reproduce, the permissions reached, and the potential impact on the infrastructure also play a role.

In this case, the most striking figure is the volume of data the flaw could lead to, but the available material doesn’t support concluding that all 17 trillion records were downloaded, or that the 25,000 accounts were misused.

The information provided also doesn’t detail what specific changes Microsoft made after receiving the report, or how long the issue remained exposed.

That’s why the case should be understood as a security finding disclosed through a bug bounty program, not as a claim that the entire database was stolen.

The story also shows how the profile of some security research is changing. A student with technical skills, access to bounty programs, and AI-based automation tools can analyze complex enterprise systems without being part of a large security team.

The most important part, however, remains the same: correctly limiting what each identity can do once it has cleared the first authentication barrier.

A valid token shouldn’t automatically turn into access to everything behind it. When identity, permission, and scope checks aren’t properly separated, a relatively specific flaw can end up having far greater consequences than the original design intended.

Frequently Asked Questions

What did Faav discover at Microsoft?

According to his own account, he found a problem in Microsoft’s internal Titan analytics platform that allowed access to far more information than intended, including an infrastructure with about 17 trillion rows.

How was the flaw related to JWT tokens?

The researcher points to problems in the validation of tokens and identity. According to his description, those insufficient checks allowed access within the system to be expanded.

What is Antares?

Antares is an artificial intelligence bot built by Faav to automate some of the repetitive tasks related to vulnerability research and security.

How much did Microsoft pay for the finding?

According to the information provided, Microsoft awarded a $5,000 reward for the discovery under its security bug bounty program.

Sources:

  • Faav, research on the potential access to Microsoft’s 17 trillion records.
Scroll to Top