Skip to main content
Emerging Threats

Microsoft Exposes 17.3 Trillion Records in Authentication Flaw

Rows of computer servers and storage systems in a brightly-lit data center, with a server rack in focus and a blurred login…

"This is a strong example of how one fundamental authentication mistake can undermine multiple layers of otherwise well-designed access controls," said Ensar Seker, CISO at SOCRadar.

Approximately 17.3 trillion stored rows across several Microsoft datasets were found to be accessible through an internal analytics service because the service failed to verify the cryptographic signature on a login token. The flaw, discovered by 16‑year‑old security researcher Faav, could let an attacker claim an administrator’s identity and submit SQL queries without possessing real credentials. According to the reporting, there is currently no evidence that malicious actors exploited the vulnerability and the researcher deliberately limited access while testing.

The vulnerability: Titan accepted unsigned JWTs

The weakness centers on how an internal analytics component — identified in reporting as Titan — handled JSON Web Tokens (JWTs). Titan reportedly validated token fields such as tenant, audience and application, but, according to the researcher, it did not verify the token's cryptographic signature. That gap lets an actor control the token's claims without proving who issued it; when signature verification is absent, downstream checks on tenant or audience provide little actual protection. The practical attack scenario described is simple in concept: present a token whose claims assert an administrative identity, and the service will accept those claims without demanding proof of issuance.

Discovery by Faav and the interplay of AI and human insight

The finding is credited to Faav, a 16‑year‑old security researcher. The report emphasizes a hybrid process: an AI system performed repetitive discovery, enumeration and authentication testing over several days, while the decisive step came when the researcher questioned an assumption about how the application interpreted the user identity field. That sequence — broad, automated coverage followed by human intuition about a single unchecked assumption — is highlighted in the source as a likely preview of future offensive and defensive security work.

Scope explained: what "17.3 trillion" actually means

The 17.3 trillion figure requires careful interpretation. It represents an estimated number of database rows technically reachable through the vulnerable environment — not 17.3 trillion individuals, and not a confirmed count of stolen or exposed personal records. The report explicitly states there is no presented evidence that third parties exploited the vulnerability and notes the researcher intentionally limited how far testing went. In short, the number describes a potential technical reach within datasets, not a verified data breach of that scale.

What this means for technologists and security teams, affected enterprises, and end users

  • Technologists and security teams: The source sets out concrete controls to prioritize — ensure authentication controls fail closed; always cryptographically verify JWT signatures; reject unsigned tokens; and independently assess externally reachable APIs even when an application is said to be protected by VPN or internal access controls.
  • Affected enterprises and procurement leaders: The case underscores the need to include token validation and independent API assessment in vendor reviews and security testing, because internal analytics services and third‑party components can expose large datasets if fundamental authentication checks are missing.
  • End users and the general public: The reporting clarifies that the headline number is an upper‑bound technical reach, not proof of mass identity theft. There is, per the source, no publicly presented evidence of exploitation and the researcher limited testing to avoid wider exposure.

SOCRadar's prescription and practical security steps

Ensar Seker summarized the operational remedy in pointed terms: "authentication controls should fail closed, JWT signatures must always be cryptographically verified, unsigned tokens must be rejected, and externally reachable APIs should be independently assessed even when the associated application is supposedly protected by VPN or internal-access controls." That list encapsulates the explicit corrective actions the reporting attributes to SOCRadar's CISO — all aimed at preventing a single authentication oversight from negating more elaborate access controls.

The public facts here are narrow but sharp: a token‑validation gap in an internal analytics service left a vast number of rows technically reachable; a teenage researcher using AI‑assisted methods found the path; and experts caution that signature verification is a non‑negotiable part of authentication. Whether that technical exposure translates into real-world harm remains, according to the source, an open question without evidence of active exploitation.

Original reporting: https://www.securitymagazine.com/articles/102609-173-trillion-microsoft-records-exposed