At 16, most people are trying to survive school.
One teenage security researcher was finding his way into a Microsoft analytics system.
A researcher known online as Faav discovered a serious authentication flaw in Titan, an internal analytics service used by Microsoft.
The problem was surprisingly fundamental.
Titan was checking information contained inside digital authentication tokens without properly verifying the cryptographic signature proving those tokens were legitimate.
In normal human language, it was a little like a security guard carefully reading the name on an ID without checking whether the ID itself was fake.
Faav eventually discovered that changing the username to “admin” could give him administrator level access.
That potentially opened access to a huge analytics environment containing an estimated 17.3 trillion database rows.
That number needs context.
It does not mean 17.3 trillion people had their information leaked. Faav did not download trillions of records, and there is no evidence that customer data was stolen or that malicious hackers exploited the flaw.
Instead, he responsibly reported the vulnerability to Microsoft.
Microsoft closed the affected API days later and eventually awarded the teenager a $5,000 bug bounty.
There is another interesting detail.
Faav used an AI security tool he built himself, called Antares, to automate parts of the investigation. But the AI did not solve everything.
The breakthrough came when the human behind it thought to try one very simple word:
admin.
Sometimes the smartest hacking tool in the room is still human curiosity.