# Researcher reports access to Microsoft analytics data through flawed token check

_Published Monday, September 28, 2026 at 8:07 AM EDT · Security, Infrastructure · Latest · Tier 1 — Major_

![asdf — Primary](https://cdn.mos.cms.futurecdn.net/Jz3s87CzobimC9szxWZth-2309-80.jpg)

A researcher accessed Microsoft's internal Titan analytics platform by presenting an administrator token whose digital signature the server did not check, Tom's Hardware reported. The researcher, known as Faav, said the access exposed 25,000 employee records and tables containing a total of 17 trillion records; those totals describe accessible data, not data taken.

An unauthenticated query route accepted raw SQL, while an archived configuration file supplied database table definitions. Faav used an AI agent to investigate the route but identified the token flaw through a human inference. Microsoft awarded the researcher a $5,000 bug bounty after the report.

## Sources

- [Tom's Hardware](https://www.tomshardware.com/tech-industry/cyber-security/teenager-hacks-open-microsoft-database-with-17-trillion-total-rows-and-25-000-user-accounts-custom-ai-bot-and-lack-of-jwt-token-validation-yields-a-fruitful-trove-earns-usd5-000-bug-bounty)

---
Canonical: https://techandbusiness.org/newswire/Y4WUsk5WPaDDi0IW3Xx9-Y
Published: 2026-09-28T12:07:30.726Z
Story chronology: 2026-09-28T11:00:00.000Z
Retrieved: 2026-09-28T13:24:44.678Z
Publisher: Tech & Business (techandbusiness.org)
