Teen researcher found unsigned-token flaw in Microsoft's internal Titan service, with 17 trillion rows reachable
Faav says a missing JWT signature check exposed an analytics environment estimated at 17.3 trillion rows; Microsoft shut the API after his September 5th report.
By Ryan Merket · Published
Primary source: Faav
Why it matters
Titan’s other identity checks relied on claims that could be rewritten because the service never validated the token signature. The incident also shows the practical division of labor in Faav’s hunt: Antares automated the repetitive probing, while his interpretation of an error message led to the administrator identity.

A missing signature check let a 16-year-old security researcher impersonate an administrator on Microsoft’s internal Titan analytics service and run SQL queries, according to a disclosure Faav published on September 25th. Faav estimated that 17 connected analytics databases held 17.3 trillion rows reachable through the flaw. That is a metadata-based estimate of stored rows, not a count of unique people or confirmed customer records taken.
Microsoft shut down the affected API on September 9th, four days after Faav says he reported the vulnerability to the Microsoft Security Response Center. The company paid him a $5,000 bug bounty on September 17th, according to his account. Faav says he used table descriptions, metadata and limited samples to assess the exposure, and did not bulk-download customer data or access personally identifiable customer information.
Faav’s route to administrator access began with Antares, a personal AI-assisted security tool he built. On August 25th, Antares found Titan’s API behind a publicly reachable Azure host, despite the service’s web interface displaying a VPN-required page. The API documentation listed four routes. Three specified Azure Active Directory bearer authentication; the fourth, /v2/Query, accepted raw SQL and did not specify the same requirement.
An archived 2023 configuration helped Faav recover 56 table-routing values to test. Over the next ten days, Antares worked through errors from Titan’s token checks. Changing claims in a test JSON Web Token produced new responses as the service checked tenant, audience, application ID and then user identity, Faav wrote. The token’s signature stayed unchanged. That pattern led him to test a token with no signature.
The decisive step came from Faav, not the automated search. Titan treated the token’s upn field as a local application username. After email-formatted identities failed, Faav changed the value to admin. Titan mapped that username to local user ID 1, which had the administrator role, and executed his query. Antares had reached the user lookup but had not tried the non-email username. Faav says he recognized that possibility after returning to the lead himself after 1 a.m. on September 5th.
The number in the headline-grabbing estimate describes the potential scope, not what Faav retrieved. He says 30 of the 56 archived routing values were active and led through 24 configurations to 17 databases and 9,863 unique table names. He summed row counts from database metadata, checking the result through two metadata paths. The total, 17,333,335,124,315, could include historical, duplicated and derived data, he cautioned. Faav also says he sampled two individual rows from a Bing analytics partition to confirm that data from the separate source was reachable; he did not attempt a bulk query or correlate records across datasets.
Titan’s own metadata presented a more concrete risk. Faav reported finding approximately 25,000 application account and email records, 17,990 employee email records and 15,001 employee-organization records, as well as database configurations and dashboard and dataset definitions. He said some employee information included job titles, departments and management hierarchy for staff associated with Titan, a subset of Microsoft’s workforce. He did not test whether that material could be used for social engineering.
This was Faav’s second public Microsoft disclosure. In July 2025, at age 15, he published a report about exposure in Microsoft Guest Check-In, describing access to building and visitor information. In the Titan account, he says he has since hunted bugs at Microsoft and other technology companies while working around school, and built Antares to automate parts of that work.
Microsoft said Faav’s submission and coordinated disclosure helped it harden its services. Faav also disclosed that Microsoft had editorial control over the Titan post, asking for sections and figures to be cut or reshaped before publication. That qualification is relevant to how the company’s internal system and the potential impact are described; the 17.3 trillion figure remains Faav’s estimate based on the metadata he says he examined.
The technical failure was direct: Titan evaluated identity claims without first verifying that the token’s cryptographic signature came from a trusted issuer. The tenant, application and user checks could not establish identity when the claims being checked were editable. Faav’s account also shows where his AI tool helped and where it stalled: Antares persisted through the API and token checks, while a human inference about the meaning of upn supplied the username that unlocked the administrator account.