By Rahim Amir
Publication Date: 2026-10-05 21:10:00
- 16-year-old bug hunter gained admin access to Microsoft’s internal Titan analytics service through an unsigned login token that the service never checked
- From there, an estimated 17.3 trillion stored rows and a metadata table of about 25,000 accounts were reachable, though Faav says he only sampled data, avoiding dumping records or touching customer data
- Microsoft has hardened the service’s security since and paid a $5,000 bounty, downplaying the trillion-row figure as a theoretical storage estimate rather than actual exposed customer information
A 16-year-old bug hunter who goes by ‘Faav’ logged into Microsoft‘s internal Titan analytics platform using a token that no real credentials should have produced, and from an administrator’s seat, he could see an estimated 17.3 trillion stored rows and a metadata table listing roughly 25,000 accounts.
Microsoft paid him $5,000 and has since closed the hole, prompting him to detail his findings online even as he describes the impact as…



