About 17 TRILLION Microsoft Records Accessed by 16-Year-Old Researcher 

An estimated 17.3 trillion stored rows across a wide range of Microsoft datasets in Microsoft’s Titan analytics service, were reachable through a single internal analytics service, all because it never checked the signature on a login token. The flaw, which a 16-year-old security researcher known as Faav uncovered, enabled him to claim an administrator’s identity and submit unauthorized SQL queries without any real credentials.

The blog entry with started all of this is here: https://blog.faav.net/how-i-couldve-accessed-17-trillion-microsoft-records

Ensar Seker, CISO at SOCRadar, commented:

“This is a strong example of how one fundamental authentication mistake can undermine multiple layers of otherwise well-designed access controls. Titan was validating information inside the JWT, such as the tenant, audience and application, but according to the researcher it was not verifying the cryptographic signature. If an attacker can control the claims without proving who issued the token, those downstream checks provide very little protection. The 17.3 trillion figure also needs to be understood carefully. It represents an estimated number of database rows technically reachable through the vulnerable environment, not 17.3 trillion individuals or confirmed stolen records. There is currently no evidence presented that malicious actors exploited the vulnerability, and the researcher deliberately limited access during testing.


“What makes this case particularly interesting is the combination of AI automation and human security expertise. The AI system handled repetitive discovery, enumeration and authentication testing over several days, while the decisive breakthrough came from the researcher questioning an assumption about how the application interpreted the user identity field. That is likely a preview of how both offensive security research and defensive testing will evolve: AI can dramatically increase the speed and breadth of investigation, but human intuition and contextual reasoning remain critical.

“For security teams, the lesson is straightforward: authentication controls should fail closed, JWT signatures must always be cryptographically verified, unsigned tokens must be rejected, and externally reachable APIs should be independently assessed even when the associated application is supposedly protected by VPN or internal-access controls.”

Well, this is a sign of things to come. Which is guaranteed to be bad for all of us.

Leave a Reply

Discover more from The IT Nerd

Subscribe now to keep reading and get access to the full archive.

Continue reading