I Could've Accessed 17T Microsoft Records
AIThis post was created with the assistance of artificial intelligence (AI).

TL;DR

Prime Big Deal Days · Oct 6–7Offer from Amazon

Get privacy and security gear delivered free — and shop member deals

  • Fast, free delivery on millions of items
  • Access to Prime Big Deal Days deals on October 6–7
  • Prime Video, Amazon Music and more included
Start your free Prime trial Free trial for eligible customers · Cancel anytime
As an affiliate, we earn on qualifying purchases.

A researcher known as Faav reported that Microsoft’s Titan analytics API accepted login tokens without validating their signatures, potentially allowing unauthorized SQL queries. Faav estimated that 17.3 trillion stored rows across Microsoft datasets were reachable, but said the figure describes potential scope, not records accessed; they reported using metadata and bounded samples and did not view customer data or personal information. Microsoft said it investigated the report and hardened its services.

Security researcher Faav says an internal Microsoft analytics service accepted login tokens without checking their signatures, a flaw that could have enabled unauthorized SQL queries across datasets containing an estimated 17.3 trillion stored rows. The researcher said the figure describes potential access, not records obtained: they used metadata and bounded sample rows to gauge scope and did not access customer data or personal information. Microsoft said it investigated the report and hardened its services.

In a report published September 25, Faav described the service as Titan, an internal analytics platform whose web interface appeared behind a VPN restriction. The researcher said an API endpoint was separately discoverable and that its published Swagger documentation listed four routes. One route, /v2/Query, accepted raw SQL and did not have the Azure Active Directory bearer-authentication requirement specified for the other three routes.

Faav said an unauthenticated test first returned an error. Over the following days, the researcher altered token claims and observed Titan progress through checks for tenant, audience, application and user identity, while the token signature remained unchanged. Faav then tested a token with no signature and said the service continued to process its claims. Changing the user principal name to “admin” reportedly produced a response that allowed further investigation.

The report says the researcher used table descriptions, metadata and bounded sample rows to estimate the potential scope. Faav characterized the 17.3 trillion figure as an estimate of stored rows across a wide range of Microsoft datasets that were reachable through the service, not a count of records downloaded or exposed. Microsoft’s statement thanked Faav for the coordinated disclosure and said the findings helped it harden its services.

At a glance
reportWhen: Disclosure published September 25, 2026…
The developmentFaav disclosed a token-signature validation flaw in an internal Microsoft analytics API and estimated the potential reach at 17.3 trillion stored rows.

A Token Check With Broad Potential Reach

The reported flaw matters because signature verification is a core safeguard for identity tokens: without it, a service may accept claims that have not been authenticated by a trusted issuer. If Faav’s account is accurate, the API’s acceptance of fabricated identity claims could have let an outsider act as an administrator for query purposes, despite lacking valid credentials.

The possible scale is substantial, but the distinction between potential reach and confirmed exposure is central. The reported 17.3 trillion rows are an estimate of data represented in accessible datasets, not evidence that an attacker retrieved that volume, or that every row contained sensitive information. Faav says no customer data or personal information was accessed during the research. The disclosure therefore points to a serious access-control weakness while not establishing a customer-data breach.

Amazon

Microsoft Azure security monitoring tools

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

How Faav Traced the Titan API

Faav said an automated lead-finding tool called Antares identified Titan on August 25, 2026. The researcher then located the API through Microsoft subdomains and consulted an archived version of Titan’s interface and configuration from 2023, which reportedly contained 56 table definitions. Those definitions helped identify a value to test against the query endpoint.

The report describes roughly ten days of testing before Faav recognized that the service appeared to inspect token claims without validating the signature. Faav said they reported the issue to Microsoft and disclosed it under coordinated vulnerability disclosure. The post also says Microsoft had editorial control over its publication and edited sections and figures, a disclosure relevant to how the published account and impact estimate were presented.

Faav, who says they were 16 when the report was published, described this as a bug-bounty investigation conducted alongside schoolwork. Their age and use of automated tools are details from the researcher’s account; they do not independently establish the technical impact. Microsoft’s public comment confirms that it investigated a submission from Faav and hardened services, but does not provide technical findings in the supplied statement.

“We appreciate the opportunity to investigate the findings reported by Faav. Their submission and coordinated vulnerability disclosure helped us to better protect our customers by hardening our services.”

— Microsoft, in a statement included in Faav’s report

Amazon

SQL query security testing software

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Scope and Fix Details Still Undisclosed

The available material does not include Microsoft’s technical assessment, a detailed remediation timeline, or independent verification of the 17.3 trillion-row estimate. It is also unclear how many datasets were exposed to the query route, what kinds of information those datasets held, or whether any other party used the flaw before it was reported.

Faav says Microsoft edited the report before publication, including changes to sections and figures. The account does not specify which impact figures were changed or provide the original and revised versions, limiting readers’ ability to compare the published estimate with the researcher’s initial assessment. Microsoft’s statement does not address those editorial changes or confirm whether customer data was at risk beyond the general hardening it described.

No evidence in the supplied report establishes that records were stolen or that a breach occurred. Faav says they did not access customer data or personal information, but the available sources do not include a separate Microsoft statement about whether it found misuse or whether its investigation ruled out other access.

Amazon

API security testing tools

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Microsoft’s Remediation Needs Detail

Microsoft says it investigated the report and hardened its services. The supplied statement does not say when the fix was deployed, which components were changed, or whether the Titan API itself was taken offline or modified. Those details would help establish how the flaw was contained and whether related services received additional review.

The next useful public information would include Microsoft’s account of the affected endpoint, the controls added to validate tokens, and whether its review found any unauthorized queries. Faav’s post presents the finding as a coordinated disclosure, but the provided material does not set out a date for further updates or identify an independent audit. Until more detail is released, the confirmed development is that Microsoft investigated Faav’s report and says it hardened services—not that 17.3 trillion records were accessed.

Amazon

identity token validation tools

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Key Questions

Were 17.3 trillion Microsoft records accessed?

No such access is established by the report. Faav described 17.3 trillion stored rows as an estimate of the potential reach of the flaw and said they used metadata and bounded sample rows, not customer data or personal information.

What was the reported flaw?

Faav said Microsoft’s Titan analytics API accepted login-token claims without verifying the token’s cryptographic signature. The researcher said this could allow unauthorized SQL queries by letting a user present fabricated identity claims.

What has Microsoft confirmed?

Microsoft said it investigated Faav’s findings and that the coordinated disclosure helped it harden its services. Its quoted statement does not provide a technical description of the fix or say whether an investigation found misuse.

Did Faav access personal information?

Faav said they did not access customer data or personal information, and used table descriptions, metadata and bounded sample rows to understand potential scope. The supplied material does not include a separate Microsoft account of data access.

When was the flaw found and reported?

Faav said Antares identified the Titan service on August 25, 2026, and described testing over about ten days. The report was published September 25, 2026; the provided material does not give a specific date when Microsoft received the report or deployed its changes.

Source: hn

EVERGREEN BESTSE

Evergreen bestsellers Picks

As an affiliate, we earn on qualifying purchases.

You May Also Like

Third-party data breach may affect some former Mayo Clinic patients

A data breach at healthcare management firm Xsolis may have exposed information of some former Mayo Clinic patients, though Mayo denies direct involvement.

Kimi K3 Exploited The Latest Redis Server

Cybersecurity researcher Kimi K3 has successfully exploited a recent vulnerability in the latest Redis server version, raising security concerns.

The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

AI voice scams now can mimic voices and execute fraud in just three seconds, challenging current security measures and raising urgent concerns.

CVE-2026-15410: SonicWall SMA1000 Appliances Code Injection Vulnerability Actively Exploited (CISA KEV)

SonicWall SMA1000 appliances are actively targeted due to a code injection vulnerability, enabling remote attackers to execute arbitrary commands. Details are evolving.