Teen Researcher’s AI Tool Gains Admin on Microsoft Titan

A 16-year-old researcher used a self-built AI tool to gain admin access to Microsoft's internal Titan analytics platform, exposing 17.3 trillion rows.
Table of Contents
    Add a header to begin generating the table of contents

    A 16-year-old security researcher using a self-built AI hacking tool gained full administrative access to Titan, an internal Microsoft analytics platform, exposing an estimated 17.3 trillion data rows across 17 connected databases before Microsoft locked down the vulnerable endpoint and paid a $5,000 bug bounty.

    A JWT Signature Gap Let an Unsigned Token Claim Admin Rights

    The researcher, known as “Faav,” used a self-built AI hacking tool called Antares to discover that Titan’s API failed to verify JWT signatures during authentication, meaning the system would accept unsigned tokens with modified user-principal names as valid. JSON Web Tokens are designed to carry an identity claim alongside a cryptographic signature that proves the claim has not been tampered with; when a system skips verifying that signature, anything written into the token is effectively taken on faith. After roughly ten days of testing, Faav changed an unsigned token’s user-principal name to “admin,” which Titan resolved to user ID 1 with full administrative privileges and SQL query execution rights across the platform.

    The Access Exposed 17.3 Trillion Rows Across 17 Analytics Databases

    The scope of what Faav’s admin access could reach was extensive: an estimated 17.3 trillion data rows spread across 17 connected analytics databases. Within that exposure were roughly 25,000 account and email records, about 18,000 employee email records, organizational hierarchy data, 355 database configurations, and samples of Bing analytics data containing country- and state-level location information.

    Microsoft Locked the Endpoint Within Days of Notification

    Once notified, Microsoft asked Faav to stop testing and, within days, locked down the vulnerable endpoint entirely. The company paid the $5,000 bug bounty roughly a week after the lockdown, and required edits to Faav’s public write-up before it was allowed to be published, a step Microsoft commonly takes to control exactly how much technical detail about an internal system reaches a public audience.

    Microsoft Required Edits Before the Technical Write-Up Went Public

    The requirement for pre-publication edits reflects the sensitivity of the platform involved: Titan is not a customer-facing product but an internal tool Microsoft employees use to query vast volumes of organizational and customer-adjacent data, and a detailed public account of exactly how its authentication failed carries different risk considerations than a bug report about a consumer application. The write-up was ultimately published on September 30, after those requested changes were made.

    A Basic Authentication Gap With an Outsized Blast Radius

    The underlying flaw — an API that accepted unsigned tokens without verifying their signatures — is a well-understood class of authentication mistake, not a novel attack technique, which makes the scale of what it exposed all the more notable. JWT signature verification exists specifically to prevent exactly the kind of tampering Faav performed: altering a token’s claimed identity and having the system trust it anyway. That such a fundamental check could be missing from an internal platform handling tens of trillions of rows of data illustrates how admin-facing internal tools, built for employee convenience rather than public exposure, can sometimes receive less rigorous security scrutiny than customer-facing products despite holding comparably sensitive data.

    The case also reflects a broader trend in vulnerability research: AI-assisted tooling appears to be lowering the barrier to finding high-impact authentication flaws in major-vendor infrastructure, allowing a teenage independent researcher working alone to uncover and responsibly disclose a bug with a blast radius spanning employee records, organizational structure data, and customer-adjacent analytics. Microsoft’s response — asking the researcher to stop, locking down the endpoint within days, and paying a bounty — followed a fairly conventional responsible-disclosure path once the report reached the company, but the episode leaves open the question of how long an authentication gap of this severity sat undiscovered on an internal platform of Titan’s scale before Faav and Antares found it.

    The size of the exposed dataset also raises questions that extend beyond Microsoft’s own walls. The Bing analytics samples containing country- and state-level location data, along with the organizational hierarchy information accessible through Titan, point to a platform that aggregates data from multiple product lines into a single queryable surface for internal analysts. That kind of centralized aggregation is operationally useful precisely because it lets employees query across datasets that would otherwise sit in separate systems, but it also means a single authentication failure at the aggregation layer can expose the combined sensitivity of everything feeding into it, rather than the more contained blast radius a flaw in any one source system would carry on its own.

    Related Posts