Open Microsoft database with 17 trillion total rows and 25,000 user accounts hacked by a bored teenager — but he's been well-paid for his actions
A 16-year-old set one login field to "admin," and an estimated 17.3 trillion Microsoft rows became accessible.
A 16-year-old hacker known as Faav gained administrative access to Microsoft's internal Titan analytics service through a flaw in how the system handled login tokens. He discovered that the service never checked the cryptographic signature of unsigned tokens, allowing him to bypass security measures. The Titan service contained an estimated 17.3 trillion stored rows and a metadata table listing around 25,000 accounts.
Faav, who used an orchestration bot called Antares to automate the process, detailed his findings on September 5, 2026, and Microsoft paid him $5,000 to resolve the issue. Microsoft later admitted that the bug could have been catastrophic if exploited by malicious actors. The teenager's discovery highlights the potential vulnerabilities in modern web services and the importance of robust security measures, such as verifying cryptographic signatures in login tokens.
Written by urgent.news from TechRadar's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.