A flaw in Titan, an internal Microsoft analytics service, meant it did not verify the signature on login tokens. The researcher, who publishes as Faav, found Titan's web interface was reachable only over a Microsoft VPN, but a separate, publicly documented API endpoint accepted raw SQL. Iterating on a token from his own external Entra test tenant, he walked past tenant, audience and application-allowlist errors to a user lookup; because the token's payload could change while its signature stayed identical, he inferred signature verification was absent and sent a token with the algorithm set to "none" and an empty signature. Setting the upn claim to "admin" matched it to user ID 1, which held the Admin role, granting administrator access and the ability to run SQL against 17 connected databases. Its platform metadata database held roughly 25,000 account and email entries, 17,990 employee email records and 15,001 employee organisation records including job titles, departments and hierarchy; he also pulled two single-row samples from Bing analytics containing search, identifier and location fields. Faav reported the flaw to the Microsoft Security Response Center on 5 September, the endpoint was locked down on 9 September and he received a $5,000 bounty on 17 September. He described the 17.3 trillion figure as a storage estimate from database metadata that likely includes historical, duplicated and derived data, and said he did not touch customer data or PII.
| Attribute | Detail |
|---|---|
| Sector | Global (Macro) |
| Date | 2026-09-29 |
| Source | Help Net Security |
| Reliability | Tier 2 |