13-year-old hacks Microsoft Teams, rewrites rules for global security program

13-year-old hacks Microsoft Teams, rewrites rules for global security program

13-year-old hacks Microsoft Teams, rewrites rules for global security program

Bug bounty programs attract some of the most skilled engineers in cybersecurity. These are professionals who find their way through enterprise-level software in search of vulnerabilities for recognition, impact, or high payouts.



But Dylan, a high school junior, entered that world at just 13. His first major find, a critical Microsoft Teams vulnerability, didn’t just earn him accolades. It led Microsoft to rewrite the rules of its bug bounty program to allow teenage researchers.

Now 17, Dylan has become one of Microsoft’s most valuable independent collaborators, with dozens of reported bugs and a growing presence in the global security community.

From Scratch to source code

Given his age, it will be fair to say that Dylan’s interest in computers began early. He started coding with Scratch, a visual programming platform for children, before moving on to HTML and other programming languages. By 5th grade, he was already analyzing the source code behind educational platforms and testing their limitations.

One such test, unlocking games without completing lessons, resulted in disciplinary action at school. But it also marked the beginning of a deeper interest in system vulnerabilities.

During the COVID-19 lockdown, when his school disabled students’ ability to create Microsoft Teams meetings, Dylan found a workaround using Outlook. Microsoft later said, “It wasn’t about bypassing rules—it was about helping classmates stay connected in a time of isolation.”

His deeper foray into cybersecurity came when student-created Teams chats were also blocked. Over the next nine months, he taught himself the basics of security research and ultimately discovered a critical flaw that allowed full control over Teams groups.

He disclosed the vulnerability responsibly to Microsoft.

Bug bounty history rewritten

Dylan’s report was well-received. Microsoft updated its bug bounty program to allow participation from researchers as young as 13, a direct result of his contribution. He continued filing reports and soon built a working relationship with MSRC.

One of his more impactful disclosures involved the Authenticator Broker service. Initially deemed out of scope, the vulnerability was later accepted after Dylan’s detailed technical explanation. “Not only was the issue acknowledged, but the bounty program also expanded its scope… a testament to Dylan’s impact,” Microsoft stated.

His work earned him spots on MSRC’s Most Valuable Researcher list in both 2022 and 2024. In April 2025, Dylan placed third at Microsoft’s Zero Day Quest, a competitive on-site hacking event held in Redmond, Washington.

Challenges accompanied the success. Dylan faced misunderstood reports and disagreements over assessments. He also faced a personal health crisis during the pandemic, temporarily losing his voice and undergoing two surgeries.

Despite these challenges, Dylan remained committed, crediting his parents and extended family for their support. Last summer, he filed 20 vulnerability reports, a sharp increase from his earlier output.

He sees security research as a rewarding hobby and is open to future paths in tech, science, or public service. He also hopes to attend cybersecurity conferences once he’s eligible, eager to connect with the global researcher community.

Source: Interesting Engineering

Scientists build solar cells that charge even in dim office light with 38% efficiency

13-year-old hacks Microsoft Teams, rewrites rules for global security program

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Çok Okunan Yazılar