{"id":346,"date":"2026-10-05T20:28:27","date_gmt":"2026-10-05T20:28:27","guid":{"rendered":"https:\/\/managedt.com\/blog\/teenager-breaks-into-microsoft-titan-analytics-service\/"},"modified":"2026-10-05T20:28:28","modified_gmt":"2026-10-05T20:28:28","slug":"teenager-breaks-into-microsoft-titan-analytics-service","status":"publish","type":"post","link":"https:\/\/managedt.com\/blog\/teenager-breaks-into-microsoft-titan-analytics-service\/","title":{"rendered":"16-year-old researcher breaks into Microsoft analytics service with access to 17 trillion rows of data"},"content":{"rendered":"<h2>What happened<\/h2>\n<p>A flaw in Titan, an internal Microsoft analytics service, let an outside researcher reach employee records and Bing search analytics by posing as the service&#8217;s administrator. The researcher, a 16-year-old who goes by Faav, found that Titan did not verify the signature on its login tokens, which opened the door to running SQL queries across 17 connected databases holding an estimated 17.3 trillion rows.<\/p>\n<p>Faav did not work alone. He built Antares, an automated bug-hunting tool that flagged Titan and kept working through its login checks for ten days before he stepped in to take the final step himself. Reporting through the Microsoft Security Response Center led to a patch within days and a $5,000 bug bounty.<\/p>\n<h2>How the token check was bypassed<\/h2>\n<p>Titan&#8217;s web interface was only reachable over a Microsoft VPN, but Antares found a separate API endpoint with public documentation. One of its routes, <code>\/v2\/Query<\/code>, accepted raw SQL and refused requests without an authorization header.<\/p>\n<p>Antares kept returning to Titan while Faav chased other leads. The breakthrough came from a token originally created months earlier for testing against an external Entra tenant.<\/p>\n<ul>\n<li>Switching the token&#8217;s tenant value to Microsoft&#8217;s returned an audience error.<\/li>\n<li>Changing the audience produced an application allowlist error.<\/li>\n<li>Changing the application ID finally reached a user lookup.<\/li>\n<\/ul>\n<p>The token&#8217;s payload kept changing while the signature stayed exactly the same, and Titan kept accepting the new claims. The next test sent a token with the algorithm set to <code>none<\/code> and an empty signature section. It passed every check and reached a user lookup that returned a user not found error.<\/p>\n<h2>Reaching the admin account<\/h2>\n<p>Antares spent days trying email-style addresses in the token&#8217;s UPN field. On September 5, Faav changed the value to <code>admin<\/code>. Titan treated the field as a local username and matched it to user ID 1, which held the Admin role. That single change handed him administrator access and let him run SQL queries against the service.<\/p>\n<h2>What was inside the databases<\/h2>\n<p>Titan&#8217;s platform metadata database held roughly 25,000 account and email entries, 17,990 employee email records and 15,001 employee organization records, according to the write-up. The employee information included job titles, departments and management hierarchy for staff associated with Titan, and covered a subset of Microsoft&#8217;s workforce. In the wrong hands, that data could have supported targeted social engineering, though Faav did not test that angle.<\/p>\n<p>The researcher also reached a Bing analytics source and pulled two one-row samples from its latest partition. The samples contained search, identifier and location fields, with country- or state-level information derived from reverse IP lookups. Because MUIDs (the identifiers Microsoft stores in users&#8217; browsers) appeared in more than one dataset, user activity could plausibly have been correlated across services.<\/p>\n<p>Faav called the 17.3 trillion row figure a storage estimate from database metadata that likely includes historical, duplicated and derived data.<\/p>\n<h2>Disclosure and Microsoft&#8217;s response<\/h2>\n<p>Faav reported the vulnerability to the Microsoft Security Response Center on September 5. MSRC asked him to stop testing and requested his IP address to confirm there was no activity beyond his research. The endpoint was locked down on September 9, and the $5,000 bounty was paid on September 17.<\/p>\n<p>Faav stressed that he never touched customer data or personal information, and did not use the two Bing samples to identify anyone, link records between datasets, or build profiles. He also revealed that Microsoft had editorial control over his write-up, with sections, figures and impact descriptions cut or reworded before publication.<\/p>\n<h2>What the case shows about token validation<\/h2>\n<p>The whole chain hinged on a single missing check: Titan accepted tokens whose signatures were absent or had never been verified. A token&#8217;s payload, including the user identity, tenant, audience and application ID, is meant to be sealed by a signature issued by the identity provider. If a service only inspects the contents of the token and never confirms that the signature is valid and trusted, any user can rewrite the contents and claim to be anyone, including the administrator.<\/p>\n<p>Allowing the algorithm to be set to <code>none<\/code> compounds the problem, since the service then has no signature to check at all. Hardening here means rejecting any token that does not carry a valid, currently trusted signature from the right issuer, regardless of what the payload says.<\/p>\n<h2>FAQ<\/h2>\n<h3>What is the Titan vulnerability at Microsoft?<\/h3>\n<p>A 16-year-old researcher found that Titan, Microsoft&#8217;s internal analytics service, did not verify the signature on its login tokens. By rewriting token contents and setting the algorithm to none, he gained administrator access and could run SQL queries across databases holding an estimated 17.3 trillion rows.<\/p>\n<h3>What data was exposed in the Titan flaw?<\/h3>\n<p>The exposed data included around 25,000 account and email entries, 17,990 employee email records and 15,001 employee organization records, plus Bing analytics samples containing search, identifier and location fields. The researcher did not touch customer data or personal information.<\/p>\n<h3>How did Microsoft respond to the Titan bug report?<\/h3>\n<p>The Microsoft Security Response Center received the report on September 5, asked the researcher to stop testing, locked down the endpoint on September 9, and paid a $5,000 bug bounty on September 17.<\/p>\n<p><script type=\"application\/ld+json\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"FAQPage\",\"mainEntity\":[{\"@type\":\"Question\",\"name\":\"What is the Titan vulnerability at Microsoft?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"A 16-year-old researcher found that Titan, Microsoft's internal analytics service, did not verify the signature on its login tokens. By rewriting token contents and setting the algorithm to none, he gained administrator access and could run SQL queries across databases holding an estimated 17.3 trillion rows.\"}},{\"@type\":\"Question\",\"name\":\"What data was exposed in the Titan flaw?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"The exposed data included around 25,000 account and email entries, 17,990 employee email records and 15,001 employee organization records, plus Bing analytics samples containing search, identifier and location fields. The researcher did not touch customer data or personal information.\"}},{\"@type\":\"Question\",\"name\":\"How did Microsoft respond to the Titan bug report?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"The Microsoft Security Response Center received the report on September 5, asked the researcher to stop testing, locked down the endpoint on September 9, and paid a $5,000 bug bounty on September 17.\"}}]}]}<\/script><\/p>\n<hr style=\"margin:2.5em 0 1em;opacity:.35\" \/>\n<p style=\"font-size:.85em;opacity:.7\">This article summarizes reporting from <a href=\"https:\/\/www.helpnetsecurity.com\/2026\/09\/28\/microsoft-titan-jwt-signature-flaw\/\" target=\"_blank\" rel=\"nofollow noopener\">helpnetsecurity.com<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A missing signature check on Microsoft&#8217;s internal Titan analytics service let a 16-year-old researcher pose as admin and query 17 trillion rows.<\/p>\n","protected":false},"author":3,"featured_media":345,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-346","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/posts\/346","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/comments?post=346"}],"version-history":[{"count":1,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/posts\/346\/revisions"}],"predecessor-version":[{"id":347,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/posts\/346\/revisions\/347"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/media\/345"}],"wp:attachment":[{"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/media?parent=346"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/categories?post=346"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/tags?post=346"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}