· 13 min read

Illustration: a young person at a laptop faces a futuristic armored door opening onto a glowing data center; an unsigned identity credential with a dashed border passes next to a key toward the door.

If you are in a hurry: a 16-year-old researcher who goes by Faav found that Titan, an internal Microsoft analytics service, accepted login tokens without verifying their signature. With a forged token he posed as an administrator and could run SQL queries against 17 databases. Microsoft awarded him 5,000 dollars. Almost every headline said he "hacked Microsoft" and "exposed 17 trillion records." Neither is true: he took no data, it was not a customer product, and the figure is a count of metadata. What actually matters for anyone who runs systems is the flaw itself, an authentication mistake that Microsoft forbids in its own documentation.

The viral headline and the real title

In late September the story went around of "a 16-year-old who hacked Microsoft and got 5,000 dollars." The researcher titled his own account differently: "How I Could've Accessed 17 Trillion Microsoft Records". That "could've" is the whole difference, and it is the first thing the headlines dropped.

The researcher goes by Faav. He says it plainly in his writeup: "The impact I describe is hypothetical. It's what an attacker could have done with this access, but luckily I found the bug instead, reported it, and never touched any customer data or PII." He reported the flaw the same day he confirmed it, Microsoft closed it in four days, and awarded him the bounty. It is a case of responsible disclosure that was told as if it were a break-in.

This article reconstructs what happened with the primary source in front of us, separates the facts from what the headlines added, and turns it into a checklist for anyone who manages Microsoft 365 or Azure tenants. Since Faav is a minor, I use only his alias.

Who Faav is

Faav describes himself as a "Hacker & Developer" and says he is 16: "A little over a year ago, when I was 15, I published [my first Microsoft writeup]. I'm 16 now, and this one is a little bigger." The age is his own claim, nobody has verified it independently, and his real name and country appear nowhere.

This is not his first finding. His blog has a run of Microsoft reports starting in July 2025, and he says he has spent the year "hacking Microsoft off and on around school," along with finding bugs at other large companies. He built an AI tool he calls Antares to automate part of the hunt. We will come back to how credit splits between the tool and the person, because it is one of the more interesting parts.

A teenager earning bounties is nothing new. The best-known case in Latin America is Argentina's Santiago López, who earned his first reward of 50 dollars in 2016 and in 2019, at 19, became the first person to pass one million dollars on HackerOne. What made this case news was not the age, it was the scale of the access.

The flaw, step by step

Titan is an internal Microsoft analytics platform. Its web interface was restricted to employees: anyone coming from outside saw a "VPN REQUIRED" page. But the interface was not the problem.

The API lived somewhere else. Antares, enumerating subdomains, found that Titan's API was not linked from the interface and ran on a separate host, hosted on Azure Cloud Services and reachable from the internet. Its Swagger documentation was public and listed four routes. Three required an Azure AD token. The fourth, /v2/Query, did not require one in the documentation, and it was exactly the one that accepted raw SQL.

The table names came from an old archive. Running a query needed table names, and Swagger gave no examples. Faav pulled 2023 snapshots of Titan's pages from the Wayback Machine, and from an archived Apache Superset configuration recovered 56 table definitions.

The token signature was never checked. A JWT, the token used to log in, has three parts: header, payload, and signature. The signature is what proves the token is genuine and that nobody changed its contents. Over about ten days, Antares kept changing the token's contents and reading the errors: Titan checked the tenant, then the audience, then an application allowlist, then the user, but never the signature. Faav describes it with his own comparison: "like a bouncer checking the name on every ID but never looking at the photo."

The decisive step was human. Antares built an unsigned token (with the header {"alg":"none"} and an empty signature) that passed all four checks, but it got stuck at the user lookup, because the upn field is normally an email address and the tool kept trying addresses. Faav describes what he did late at night: he stopped trying emails and thought about what the server was doing with that field. He changed the upn to the string admin. Titan resolved it to "local user ID 1, which held the Admin role." From there he could run SQL as administrator. In his words: "The funny part is that admin is obvious, but obviously not a valid UPN. That's exactly why Antares never guessed it."

Here it pays to be precise, because this is exactly what the headlines distorted. He did not type "admin" into a login screen. He forged an unsigned token and put admin in an internal field, after ten days of mapping how Titan validated requests. There are two chained mistakes: accepting an unsigned token, and using a field the attacker controls to authorize access.

Diagram: a forged token with alg:none and upn:admin passes the tenant, audience, application and user checks (green), but the token signature is never verified (red). The result is administrator access and SQL queries against 17 databases.

What the "17 trillion" means

The figure that circled the world, 17.3 trillion, is the number of rows Faav estimated by summing metadata from the 17 databases. He qualifies it himself: it is "a storage estimate from metadata that likely includes historical, duplicated, and derived data." These are not 17 trillion people or unique records, and he did not download them.

What he actually had within reach, by his own inventory:

What the headlines publishedWhat the original account says
"17 trillion records exposed"17.3 trillion rows summed from metadata, duplicates and history included
"25,000 employee records"about 25,000 account and email records from an application table; in the record he shows, the password was a Superset placeholder hash, not a real Microsoft credential
"hacked Microsoft," "broke into," "breach"admin access to an internal service, obtained in a test and reported the same day, with no data taken
"typed admin and opened the door"forged an unsigned token with upn set to admin, after ten days of testing
"a critical flaw"Microsoft has not published what severity it assigned

The employee records were something else: 17,990 email and 15,001 organization records, with job titles, departments, and hierarchy, for a subset of employees. There was also a Bing analytics source, from which he took only two one-row samples. His most-repeated line is "I never touched any customer data or PII," and it fits how he measured the scope: instead of downloading data, he counted rows with metadata tables.

You have to be fair in both directions. Saying he only saw "metadata" also undersells it: he had real SQL access as administrator and saw at least one table of accounts with names, emails, and login history. But there is no evidence of bulk extraction, and Faav himself flags something important: Microsoft had editorial control over the text, "cutting sections and figures and reshaping how the impact is described." The figures we read are the version Microsoft approved.

The timeline: twelve days from report to bounty

Date (2026)What happened
August 25Antares identifies Titan's API and recovers the archived configuration
August 25 to September 5About ten days of testing the token validation
September 5, early morningThe admin trick works; Faav reports to Microsoft the same day
September 6 to 8Microsoft asks him to stop testing and to confirm his IP
September 9Microsoft locks down the API
September 17He is awarded 5,000 dollars
September 25He publishes the writeup, after reviewing it with Microsoft
September 28The story goes viral on Hacker News

A point of wording that matters: "awarded" is not the same as "paid." The program rules require submitting a US tax form before payment, so September 17 is the award date. The case number he mentions (144051) comes only from him, and there is no CVE or public Microsoft advisory about Titan.

Microsoft spoke only once

Microsoft's only public position is a statement the company gave Faav for his own blog: "We appreciate the opportunity to investigate the findings reported by Faav. Their submission and coordinated vulnerability disclosure helped us to better protect our customers by hardening our services…" The Register confirms the statement was given "for his blog," not in response to a press inquiry.

That statement confirms the case exists and that it was handled within the program. It confirms no figure: not the 17.3 trillion, not the 25,000 records, not the 5,000 dollars. Nor does it say what severity it assigned, or whether there was third-party access before the lockdown. Per the timeline, Microsoft asked for Faav's IP to separate his activity from any other in the logs, but the result of that review is not public. No outlet I reviewed appears to have asked Microsoft the obvious questions: why 5,000 dollars, what severity, why demand editorial control.

5,000 dollars: a lot or a little?

This is the part where the technical community disagreed with the headlines. Microsoft publishes bounty tables per program. The Azure one, for example, crosses the type of flaw, the severity, and the quality of the report. These are a few rows, in dollars:

Azure flawCriticalImportant
Elevation of Privilege (high-quality report)40,00010,000
Information Disclosure (high-quality report)12,0007,500
Spoofing (high-quality report)8,0004,000

For scale: the Identity program goes up to 100,000 dollars and Azure up to 60,000. In Azure, a critical elevation of privilege pays between 20,000 and 40,000 dollars depending on report quality.

By that yardstick, 5,000 dollars sits in the low band. In the Azure table it matches an Important-severity information disclosure with a medium-quality report. The most reasonable reading is that Microsoft rated it below critical, or treated it as an internal service with no customer impact, or paid a discretionary amount. None of these is confirmed, but the absence of a CVE fits: since June 2024 Microsoft issues CVEs for critical cloud flaws even when the customer has nothing to do, and none has been published that references Titan.

On Hacker News, where the case was discussed at length, most thought the payout was low. One comment summed it up: "$5k is a literal penny for Microsoft. Give the kid $100k." Some defended it too: for a company, 5,000 dollars is "an absolute steal" compared with hiring auditors, and bounty programs do not pay what an attacker would. What nobody did was present it as an exceptional payout, as some headline suggested.

For context, between July 2025 and June 2026 Microsoft paid more than 20 million dollars to 562 researchers across 64 countries, for 2,531 valid reports. The largest single payout in that period was 200,000 dollars.

On minors: the program rules set the minimum age at 14, with a parent's or guardian's permission, and Microsoft may pay the guardian and require them to sign the forms. Faav meets the requirement. Whether his parents authorized or received the payment, nobody says.

For anyone who runs systems: six checks

Titan is an internal Microsoft service and was fixed server-side. There is nothing to patch on the customer side, there is no CVE, and nobody has said customer tenant data was involved. If a client asks, the honest answer is that they have nothing to do and that no exposed tenant data has been reported.

The useful part is the pattern, because this flaw is the latest in a run of token-trust problems in Microsoft's cloud, like Storm-0558 in 2023 or the Actor tokens of 2025. Six concrete checks:

  1. Validate tokens properly in your own APIs. If you have an internal portal, an Azure Function, or an integration that accepts Entra tokens, it must verify the signature, the issuer, the audience (aud), and the tenant (tid), pin the algorithm server-side, and reject none. To decide who the user is, use oid plus tid, never upn or email. This is not my recommendation, it is Microsoft's: its developer guide literally says "don't use the upn claim for authorization."
  2. Inventory what is exposed to the internet, not just the front door. In Titan, the interface asked for a VPN and the API did not. "Requires VPN" is not an authentication control. Look for APIs and Swagger or OpenAPI pages published by accident.
  3. Remove or rename the default local admin accounts in self-hosted dashboards like Superset or Grafana. Titan's administrator was, literally, local user number 1.
  4. Limit user consent to applications. By default, any user can grant low-impact permissions to applications. Restrict that to verified publishers or turn it off, and enable the admin consent workflow.
  5. Keep the logs you need to investigate. In tenants with Entra ID P1 or P2, send the Microsoft Graph activity, sign-in, and audit logs to a SIEM, with longer retention than the default. When the flaw is on the provider's side, sometimes the only useful trace is your own.
  6. Use GDAP and PIM so that no identity, including the MSP's, holds standing Global Admin.

The case is also a good example of how to report a flaw. Faav reported the same day, measured the scope with metadata tables instead of downloading data, stopped testing when Microsoft asked, and published after the lockdown, with the text reviewed by Microsoft itself. The program rules ask for exactly that: keep the report confidential until the flaw is fixed and do not publish details that would make an attack easier ahead of time. And a reminder for anyone working at an MSP: a bounty program authorizes testing that company's services within its terms. It does not cover testing a client's or a third party's system without written authorization.

What's left

The case has less of a movie hack about it than of a basic authentication mistake in a large system. One of the companies that writes the Entra token-validation guide broke it on its two central rules, and the VPN in front of the interface did not protect an API published separately. The lesson for anyone who runs systems is direct: neither the perimeter, nor the size of the provider, nor "it's only internal" replaces verifying the signature and building identity on fields the attacker cannot change.

And there is a background story that may be the most interesting: Microsoft reviewed and cut the public account, was the only source of its own statement, and did not explain why admin access to 17 databases is worth 5,000 dollars. Now that AI makes finding flaws cheaper, the question of what a report is worth, and who decides how it gets told, is going to come up more and more.

Sources

Keep reading on IT Rafa

Deja una respuesta

Tu dirección de correo electrónico no será publicada. Los campos obligatorios están marcados con *