Teenager hacks open Microsoft database with 17 trillion total rows and 25,000 user accounts
- ID
- 29260
- Status
- summarized
- Published
- 28 Sep 2026, 7:00 PM
- Fetched
- 28 Sep 2026, 8:32 PM
- Provider
- Tom's Hardware
- Category
- technology
- Original URL
- https://www.tomshardware.com/tech-industry/cyber-security/teenager-hacks-open-microsoft-database-with-17-trillion-total-rows-and-25-000-user-accounts-custom-ai-bot-and-lack-of-jwt-token-validation-yields-a-fruitful-trove-earns-usd5-000-bug-bounty
- Source URL
- https://www.tomshardware.com/feeds/all
Summary
- Score
- 6.5
- Created
- 28 Sep 2026, 8:32 PM
- Tags
- Audience
- developersvibe_codersai_agent_users
What happened
Tom's Hardware reports that a teenager accessed an open Microsoft database containing 17 trillion total rows and 25,000 user accounts, reportedly by pairing a custom AI bot with a failure to validate JWT tokens, and earned a $5,000 bug bounty. The article body available here is almost entirely paywall and newsletter boilerplate, so the mechanics of the attack, the affected service, and Microsoft's response are not described in the text provided.
Why it matters
The one concrete technical claim is 'lack of JWT token validation' — if your app accepts a JWT without verifying its signature and claims, an attacker can mint their own token and read whatever the database returns, which is exactly the class of mistake that ships when auth is generated quickly and never tested. Before your next deploy, confirm your backend actually verifies the signing key and issuer rather than decoding the token payload, and check that any AI-generated auth code isn't doing `jwt.decode` where it should be doing `jwt.verify`.
Discussion angle
JWT verification is the single most common thing AI coding assistants get subtly wrong — walk through what `decode` vs `verify` looks like in the libraries your stack uses, and whether your own project would survive a hand-crafted token.