On September 17, 2026, Microsoft paid a $5,000 bounty through its official Bug Bounty Program to a 16-year-old security researcher named Faav. That modest payout was tied to a critical vulnerability granting direct, unauthenticated access to Titan, Microsoft’s core internal analytics service. Through an unlocked backdoor, an attacker could traverse 17.3 trillion rows of internal backend telemetry without restriction.
More intriguing than the flaw itself was what the bounty purchased: not merely a backend patch, but substantial editorial control over the public vulnerability disclosure. Prior to publication, Microsoft pressured the teenager to rewrite his impact assessment and excise key technical evidence. A high-stakes technical exploit concluded as a masterclass in asymmetrical bargaining power.
AI Does the Grunt Work, Human Intuition Flips the Switch
The intrusion began with an autonomous artificial intelligence agent dubbed Antares. Built by Faav, the custom hacking bot orchestrated LLMs from multiple frontier providers in rotating cycles. Over a ten-day reconnaissance sprint, the program mapped Microsoft’s public-facing attack surface, tirelessly executing automated network scans and endpoint discovery routines.
Eventually, Antares hit the perimeter of Titan, Microsoft’s internal data analytics engine. For corporate employees, navigating to Titan’s frontend displays a conspicuous block screen warning that a corporate VPN connection is required. But Antares approached the target from an API perspective, pinpointing exposed endpoints behind the frontend and bypassing the web interface’s perimeter fencing entirely.
Figure: The VPN REQUIRED page shown to non-employees accessing Titan’s frontend. Source: blog.faav.net
Before interacting directly with production systems, Faav turned to the Internet Archive’s Wayback Machine, unearthing snapshots from two years prior. By analyzing legacy login portals and deprecated privacy notices, he recovered complete schema definitions for 56 core database tables. Stitching those forgotten configurations together with modern routing paths published in API documentation gave him the structural blueprint required to strike at the database core.
A Fake ID That Fooled Four Gatekeepers
Titan’s internal authentication layer harbored an astonishing architectural flaw. Under standard identity federation protocols, an authentication gateway inspects both the user identity claims and the cryptographic signature affixed by the issuing authority. Titan, by contrast, diligently parsed every business attribute in the token claims while failing to verify the digital signature altogether.
When automated tools fired unauthenticated requests at the endpoint, the server consistently returned HTTP 401 Unauthorized errors. Faav proceeded to forge authorization tokens parameter by parameter. Supplying Microsoft’s corporate tenant ID triggered a new error; adjusting the audience claim moved the needle further; injecting an application identifier ran into an internal application whitelist. Like a locksmith picking a tumbler lock, he used each verbose error response to craft an increasingly refined payload.
Once all expected business claims aligned, the fatal misconfiguration emerged. Faav stripped the cryptographic signature block entirely—effectively presenting a token unsigned by any recognized identity provider. The backend server accepted it without objection. Rigorously cross-checking every descriptive field while ignoring the cryptographic seal turned the gateway into an open turnstile for arbitrary external traffic.
Hitting the Brakes in Front of 17 Trillion Records
Holding an access token exempt from signature verification, the final puzzle piece was identifying an acceptable username. Faav’s AI agent had spent hours exhausting permutations of corporate email handles, every single one rejected by backend validation logic. At 1:00 AM on September 5, Faav abandoned the linear trial-and-error approach and substituted the simplest possible identifier: admin.
Figure: Titan accepting an unsigned administrator identity and executing SQL. Source: blog.faav.net
That single parameter triggered an immediate privilege escalation cascade. The system resolved admin as an internal superadministrator, granting root execution rights over the data tier. Through direct backend database queries, Faav pulled the definitive record tally: exactly 17,333,335,124,315 rows. Approximately 17.3 trillion records sat completely exposed to unauthorized external queries, confirmed identically across multiple independent execution paths.
Sampling structural metadata revealed 25,000 corporate accounts, nearly 20,000 employee email addresses, 15,000 organizational hierarchy records, and more than 20,000 analytics dashboards. The data encompassed comprehensive internal organizational charts and analyst telemetry across Microsoft’s corporate footprint. Recognizing the gravity of the breach, the 16-year-old halted his probing. He extracted only schema descriptions, leaving sensitive customer records untouched.
A Five-Thousand-Dollar Bounty Buys Editorial Redaction
On September 5, Faav submitted a comprehensive vulnerability report to the Microsoft Security Response Center (MSRC). The remediation unfolded rapidly: within four days, the exposed endpoints were severed from the public web. On September 17, Microsoft officially disbursed a $5,000 bounty. From that point forward, the engagement pivoted from a technical exchange into a corporate negotiation.
Figure: The archived Titan interface recovered from the Wayback Machine. Source: blog.faav.net
On September 22, Microsoft held a private video briefing with Faav to coordinate the parameters of public disclosure. In the wake of that meeting, Faav extensively revised his original technical write-up under Microsoft’s insistence. Sensitive sections were deleted, and a prominent disclaimer was appended to the opening paragraph emphasizing that real-world harm remained theoretical and explicitly disclosing that Microsoft held editorial oversight over the final text.
Microsoft issued standard public relations boilerplate commending the researcher for assisting in hardening its infrastructure and reaffirming the bounty program’s success. The polished corporate statement obscured both the severity of the architectural failure and the razor-thin margin by which massive commercial datasets avoided catastrophic exposure.
An Asymmetric Bargaining Game
When the curated write-up surfaced across tech communities, it sparked fierce debate. Discussion of the unsigned token vulnerability quickly took a back seat to outrage over the terms of the transaction. The explicit disclosure that Microsoft exercised editorial control became a central lightning rod, with many developers arguing that an exploit exposing 17 trillion records warranted at least a seven-figure bounty.
Yet the equation was never merely about financial compensation. Seasoned industry observers pointed out the underlying reality: the researcher was only 16 years old. Having previously earned bounties from Microsoft, Faav was eyeing a lifelong career in cybersecurity. For an underage researcher, preserving goodwill with an industry titan holds vastly more long-term career value than burning bridges over a one-time payout.
The episode laid bare an entrenched power dynamic. An adolescent armed with automated AI tooling managed to breach one of the world’s most guarded enterprise data vaults. In return, the vault’s owner paid a token $5,000 to acquire both the technical fix and the right to shape the public narrative. The technical defenses collapsed, but the institutional power to define the rules of the game remained firmly in corporate hands.
References:
- Faav’s Blog Post
- Hacker News Discussion