Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

A 16-year-old security researcher who goes by Faav reportedly gained administrator-level access to Microsoft’s internal Titan analytics service after finding that it accepted JSON Web Tokens without verifying their cryptographic signatures. The Register reported an estimate of 17.3 trillion stored rows and about 25,000 account and email records, but those figures do not establish that 17.3 trillion unique personal records were exposed or stolen. The reporting does not confirm data exfiltration or downstream harm.

What happened in the Microsoft Titan incident?

According to The Register’s September 30, 2026 report, Faav found an authentication flaw in Titan, an internal Microsoft analytics service. Titan’s API accepted a request to its /v2/Query route without the expected Azure Active Directory authentication. The service checked several fields in a JSON Web Token (JWT), such as tenant, audience, application ID and user, but did not check the token’s cryptographic signature.

A JWT signature lets a receiving service verify that the token was issued by a trusted party and that its claims have not been altered. Without that verification, fields such as the claimed user identity cannot be trusted. The Register says Faav eventually set the token’s user identity to admin; Titan mapped that identity to a local administrator account, enabling administrator-level queries.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Faav described the weakness with a hotel analogy: “The authentication checks felt like a hotel where every door had a working keycard reader, but any keycard unlocked any room,” as quoted by The Register. The issue was not that every Microsoft database was shown to be open; the reported access concerned Titan and the analytics data available through its API.

#1 Best Overall

How did the researcher find and reach the service?

The Register reported that Titan’s web interface appeared to require a VPN, while an API endpoint hosted in Azure could be reached separately. Faav used archived configuration material to identify table definitions and routes. His automation bot, Antares, helped with reconnaissance and repetitive attempts, but the report identifies a human inference—trying the local username admin—as pivotal.

This distinction matters: automation assisted the investigation, but the reported path to administrator access depended on the service’s trust in token claims without a verified signature. Faav’s advice to developers and coding agents, quoted by The Register, was to “make sure you verify signatures above all else when building auth.”

What does the 17.3 trillion-row estimate mean?

The Register attributed the 17.3 trillion figure to Faav, who estimated the number of stored rows from metadata across connected analytics databases. The figure is a count of estimated rows, not a verified count of people or unique personal records. It may include historical, duplicated or derived data, and the retrieved reporting does not establish that those rows were downloaded.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Reported figure or material What the reporting supports What it does not establish
17.3 trillion rows Faav’s metadata-based estimate of rows stored across connected analytics databases, as reported by The Register. A count of unique people, unique sensitive records, or records confirmed stolen.
About 25,000 account and email records A figure reported by The Register for employee email and organization records. An independently audited total or proof that every listed record was accessed or taken.
Configurations and analytics materials The report also describes database configurations, dashboards, charts and dataset definitions. Evidence, by itself, of confirmed exfiltration or downstream misuse.

TechRadar Pro and Tom’s Hardware also reported the large row estimate and account figure, but their headlines should not be read as independent confirmation that the estimated rows were stolen: TechRadar Pro and Tom’s Hardware. The available coverage does not provide an independently verified count of unique affected people or confirmed data taken.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What did Microsoft do after disclosure?

The Register reported that Faav disclosed the flaw to Microsoft on September 5, 2026. Microsoft asked him to stop testing and requested his IP address between September 6 and 8. The endpoint was locked down on September 9, and the report says Microsoft paid a $5,000 bug bounty on September 17.

Microsoft’s statement, quoted by The Register, said: “Their submission and coordinated vulnerability disclosure helped us to better protect our customers by hardening our services.” That is the company’s characterization of its response; the incident reporting does not name an individual spokesperson.

Faav also reportedly said Microsoft requested cuts and changes to portions of his write-up, figures and impact language before publication. That account is attributed to Faav in The Register’s reporting and is not independently documented in the material available here.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What should readers take away?

  • The reported flaw was a failure to verify JWT signatures, leaving token claims that should have been authenticated untrusted.
  • The reported access was to Microsoft’s internal Titan analytics service and its API—not evidence of a compromise of every Microsoft database.
  • The 17.3 trillion number is a metadata-derived estimate of stored rows. It is not a verified count of unique records or confirmed theft.
  • The reported categories included employee email and organization records, as well as analytics-platform configurations and materials; the counts and categories come from incident reporting, not an independent audit.
  • The Register says Microsoft locked down the endpoint after disclosure and later paid Faav a bounty.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.