Microsoft: 17.3 Trillion Microsoft Records Exposed

Microsoft: 17.3 Trillion Microsoft Records Exposed

Microsoft Data Exposure Highlights Critical JWT Authentication Flaw

A critical security vulnerability in Microsoft’s internal analytics service exposed an estimated 17.3 trillion database rows to potential unauthorized access due to a missing cryptographic signature check in login tokens. The flaw, discovered by 16-year-old security researcher Faav, allowed attackers to impersonate administrators and execute unauthorized SQL queries without valid credentials.

The issue stemmed from Microsoft’s Titan authentication system, which validated claims within JSON Web Tokens (JWTs) such as tenant, audience, and application details but failed to verify the token’s cryptographic signature. This oversight meant attackers could manipulate token claims without proving their legitimacy, bypassing downstream access controls. While the 17.3 trillion rows represent the total reachable data through the vulnerable environment, there is no evidence that malicious actors exploited the flaw.

Ensar Şeker, CISO at SOCRadar, emphasized the broader implications, noting that the incident underscores how a single authentication failure can undermine otherwise robust security measures. The discovery also highlighted the growing role of AI in cybersecurity research, with automated systems handling repetitive tasks like discovery and testing, while human intuition such as questioning assumptions about user identity fields provided the critical breakthrough.

Microsoft has since addressed the vulnerability, reinforcing the need for strict JWT signature verification and the principle that authentication controls should "fail closed" rejecting unsigned tokens outright. The case also serves as a reminder that externally accessible APIs require independent security assessments, even when protected by VPNs or internal-access controls.

Source: https://www.securitymagazine.com/articles/102609-173-trillion-microsoft-records-exposed

Microsoft TPRM report: https://www.rankiteo.com/company/microsoft-security-response-center

"id": "mic1790699153",
"linkid": "microsoft-security-response-center",
"type": "Vulnerability",
"date": "9/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'industry': 'Technology',
                        'name': 'Microsoft',
                        'type': 'Corporation'}],
 'attack_vector': 'Authentication Bypass (JWT Signature Verification Flaw)',
 'data_breach': {'data_exfiltration': 'No evidence of malicious exploitation',
                 'number_of_records_exposed': '17.3 trillion (potential '
                                              'exposure)',
                 'type_of_data_compromised': 'Database rows (unspecified data '
                                             'types)'},
 'description': 'A critical security vulnerability in Microsoft’s internal '
                'analytics service exposed an estimated 17.3 trillion database '
                'rows to potential unauthorized access due to a missing '
                'cryptographic signature check in login tokens. The flaw '
                'allowed attackers to impersonate administrators and execute '
                'unauthorized SQL queries without valid credentials.',
 'impact': {'brand_reputation_impact': 'Undermined trust in Microsoft’s '
                                       'security measures',
            'data_compromised': '17.3 trillion database rows exposed to '
                                'potential unauthorized access',
            'systems_affected': 'Microsoft’s internal analytics service (Titan '
                                'authentication system)'},
 'investigation_status': 'Resolved',
 'lessons_learned': 'Single authentication failure can undermine robust '
                    'security measures; strict JWT signature verification is '
                    'critical; externally accessible APIs require independent '
                    'security assessments even when protected by VPNs or '
                    'internal-access controls.',
 'post_incident_analysis': {'corrective_actions': 'JWT signature verification '
                                                  'enforced; authentication '
                                                  "controls updated to 'fail "
                                                  "closed'",
                            'root_causes': 'Missing cryptographic signature '
                                           'check in JWTs; over-reliance on '
                                           'token claims without signature '
                                           'validation'},
 'recommendations': ['Enforce strict JWT signature verification',
                     "Implement 'fail closed' authentication controls",
                     'Conduct independent security assessments for externally '
                     'accessible APIs'],
 'references': [{'source': 'Security Research by Faav'},
                {'source': 'SOCRadar CISO Ensar Şeker'}],
 'response': {'containment_measures': 'Vulnerability addressed; JWT signature '
                                      'verification enforced',
              'remediation_measures': 'Reinforced JWT signature verification; '
                                      "implemented 'fail closed' "
                                      'authentication controls'},
 'title': 'Microsoft Data Exposure Highlights Critical JWT Authentication Flaw',
 'type': 'Data Exposure',
 'vulnerability_exploited': 'Missing cryptographic signature check in JSON Web '
                            'Tokens (JWTs)'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.