Data centres, military records and Palantir: the week in data infrastructure
A 16-year-old researcher found an authentication flaw in Microsoft's Titan analytics service and reached databases holding an estimated 17.3 trillion rows, The Register reported on 30 September.

Faav, the handle the researcher uses, spent ten days probing Titan's JSON Web Token checks with an AI agent he built called Antares, according to The Register. The service never verified the token signature, only its contents. Just after 1 AM on 5 September he ran SQL as a Titan administrator, then sat staring at the number 17,333,335,124,315 while his parents slept. Microsoft has since locked the endpoint and paid him a $5,000 bug bounty.
That is a clean bug. It is also the sort of thing that sits underneath almost every story about data analytics this week.
Millions of military records, unencrypted
Separately, the US Defense Manpower Data Center began notifying current and former service members that their personal information was stolen over a months-long breach, TechCrunch reported on 30 September. The notification, shared on Reddit, says several unauthorised users exploited a vulnerability in an unspecified file-sharing system between October 2025 and mid-July 2026. Exposed data included Social Security numbers, names, dates of birth, sex, race and service details. The records were not encrypted.
A Pentagon official told CNN and Federal News Network that the breach affects about 2.8 million living people and close to 300,000 deceased people, according to TechCrunch. Susan Gough, a Department of Defense spokesperson, confirmed the figure by email but did not answer questions about whether officials had heard from the hackers, whose identities are unknown. The DoD says it has no indication the data was misused, and did not say how it reached that conclusion.
The DMDC holds more than 60 million records and acts as the military's identity management provider, linking personnel to smart cards and passwords used to enter Pentagon systems and bases. Its own website states that "security of identity information is paramount." The breach follows a September incident at the FBI attributed to ShinyHunters, and echoes the 2015 Office of Personnel Management hack, broadly attributed to China, in which records of more than 22 million government employees were taken.
Palantir faces 44,000 objections over NHS data
In the UK, more than 44,000 people have filed formal legal objections to NHS England's Federated Data Platform handling their health data, The Guardian reported on 30 September. The platform is operated with Palantir's technology under a seven-year deal worth £330m. The objections cite article 21 of the UK General Data Protection Regulation and state that "the involvement of Palantir undermines my personal trust in NHS data confidentiality." Under the campaign, which was coordinated by the not-for-profit 38 Degrees, the NHS must stop using the data unless it can give a compelling reason to continue.
Campaigners point to Palantir's work for the Israeli military and for US immigration enforcement. On the same day, Amnesty International and the patient group Just Treatment parked a van styled as a damaged Palestinian ambulance outside Palantir's London office. David Murray, a retired IBM systems engineer who filed an objection, told The Guardian: "I want it to be something you can really trust to be used for the right purposes. I am not happy about Palantir's involvement with the IDF in Gaza and ICE in America."
Palantir disputes the criticism. Louis Mosley, its executive vice-president for UK and Europe, has said people who disagree with the company's assessment suffer from "Palantir derangement syndrome." A spokesperson said trusts using the software recorded 117,000 additional operations, a 14.3% reduction in discharge delays for long-stay patients and a 5.6% improvement in cancer diagnosis within 28 days. NHS England said organisations remain in control of their data within the FDP and that suppliers cannot access it for their own purposes. Two Commons select committees have called for Labour to use a break clause that comes into force in February 2027.
Data centres, power and a blocked Senate bill
On 30 September, Senate Democrats blocked the Ratepayer Protection Act by 57 votes to 43, short of the 60 needed to advance, The Guardian reported. The bill would have required electric utilities to consider standards so that data centres cover the cost of grid upgrades, rather than passing them to households. Four Democrats joined Republicans: Maggie Hassan, Amy Klobuchar, Jon Ossoff and Raphael Warnock. The House had passed it almost unanimously earlier in the month.
"Republicans' toothless datacenter bill completely misses the mark," Senate Democratic leader Chuck Schumer said on the floor, adding that relying on self-regulation "is how we got into this mess." Ohio Republican Jon Husted, who championed the bill, said big tech should pay its own way. The vote was among the last before the 3 November midterms.
Meanwhile, most European data centres still will not say how much electricity and water they consume, NL Times reported on 30 September, citing a year-long study by Lighthouse Report with Trouw and other outlets. The European Energy Efficiency Directive requires sites with at least 500 kW of installed capacity to report energy and water use, but few do so three years after it took effect. In the Netherlands, the Dutch Datacenter Association counted 186 commercial sites at that size at the end of last year; the RVO holds data on 104 of them, with public figures for the electricity use of 44 and the water use of 47.
Statistics Netherlands says Dutch data centres used 5.1 billion kWh in 2024, 4.6% of national electricity consumption and close to double the level five years earlier. Grid operator TenneT projects 10% to 15% by 2030. The RVO disclosed this summer that Microsoft's largest Dutch data centre alone accounts for 1% of national electricity consumption; Google does not disclose the figure for its two large sites.
Where the compute is going, and who pays
Meta saved $3.9 billion in 2025 through a federal research tax credit by classifying AI data centres as "pilot models" and Nvidia chips as experimental materials, according to the New York Times, as summarised by The Decoder on 30 September. The figure rose from $2 billion the previous year and $700 million in 2023, making Meta the largest beneficiary of the credit among publicly traded companies. Meta warns in SEC filings that the savings could be challenged, and its reserves for uncertain tax positions rose 45% to $18.74 billion. Its auditor, EY, approved the strategy and helped set it up.
The compute itself is moving offshore and underwater. Panthalassa, an Oregon start-up, is building 85-metre steel nodes that sit below the ocean surface and use wave motion to drive a turbine that powers AI chips in a seawater-cooled container, according to Sustainability Magazine. The company raised $140m in a round led by Peter Thiel, with participation from Marc Benioff, Max Levchin and John Doerr, pushing its valuation to nearly $1bn. All queries travel over SpaceX's Starlink network. "One of the key insights that we had was that it's very important to use the electricity in place," co-founder and CEO Garth Sheldon-Coulson told the Financial Times.
Back on land, the plumbing is getting attention too. AWS said on 30 September that Aurora PostgreSQL can now query Apache Iceberg and Parquet data in S3, S3 Tables or the Glue Data Catalog through foreign tables, using DuckDB's query engine embedded in PostgreSQL. The capability is generally available from Aurora PostgreSQL 17.11 and 18.6 in all commercial and GovCloud regions at no additional charge. Tigris, writing on its own blog the same day, described moving asynchronous tasks such as garbage collection off a FoundationDB-backed queue and onto Kafka, while keeping the original queues in place.
Two other items are worth noting. Robert F. Kennedy Jr., the US health secretary, told a Maha Institute event on Monday that medical and lifestyle data should be connected and shared with government and independent researchers, and searched by AI, The Guardian reported. He said federal officials are already using AI to process data and that "studies that used to take years, you can do them literally in seconds." And 404 Media reported on 30 September that the White House's Office of National Drug Control Policy is using the HIDTA grant programme to pull local licence plate reader data from Flock, Axon and other cameras onto federal servers, where it is accessible to agencies that may hold no contract with the vendors.
The through-line is not the technology. It is who gets to look at the data once it is collected, and who is told about it afterwards.
Sources
11- 0116-year-old researcher found a Microsoft bug, got admin access to databases with 17.3 trillion rowsEN
- 02Hackers stole millions of US military personnel records during months-long data breachEN
- 03More than 44,000 file legal objections to Palantir NHS platform handling their dataEN
- 04Senate Democrats block datacenter energy bill, saying 'toothless' legislation 'misses the mark'EN
- 05Most data centers refusing to say how much water, electricity they useEN
- 06Meta dodges billions in US taxes by calling its AI data centers experimentsEN
- 07Panthalassa's Floating, Wave-Powered Data Centre TechnologyEN
- 08Aurora PostgreSQL now supports querying of Apache Iceberg and Parquet dataEN
- 09We used a database as a message queue. Now we use KafkaEN
- 10RFK Jr outlines expansive vision for collecting US health data at Maha eventEN
- 11How Cities Are Forced to Funnel License Plate Data to a Massive Federal Surveillance ProgramEN
All figures and quotations in this text come from the sources listed below.
Content prepared by the editorial team with AI assistance.
Comments
0- No comments yet — be the first.