Hugging Face confirms cyber breach compromised internal datasets and credentials
Security vulnerability allowed malicious code execution, leading to permission escalation and access to internal systems.

Hugging Face has confirmed that a cyberattack last week compromised its internal datasets and service credentials, prompting the platform to urge users to immediately rotate any access tokens stored on the service. The company disclosed the incident on Friday, stating that a malicious dataset uploaded to its platform exploited a security vulnerability to execute code on its servers. This exploitation allowed attackers to escalate permissions and gain broader access to the company’s internal systems.
The breach was attributed by Hugging Face to an external AI agent that executed thousands of individual actions across a swarm of short-lived sandboxes. The company noted that the agent utilised self-migrating command-and-control infrastructure staged on public services. While it is common for hackers to attempt network intrusions using stolen credentials or security perimeter weaknesses, this incident highlights the specific challenges associated with platforms hosting AI models and datasets.
Hugging Face stated that its anomaly detection systems identified the attack. In an effort to analyse server logs, the company initially attempted to use a commercial frontier AI model from an unnamed provider. However, the analysis was blocked by the provider’s guardrails. Consequently, Hugging Face utilised its own local large language model to conduct the investigation, noting that this approach avoided the need to upload sensitive attack logs to an external AI company’s servers.
The company has since revoked and rotated the stolen credentials and patched the exploited vulnerability. Hugging Face is urging users to review their account activity for suspicious behaviour and has reported the incident to law enforcement. Cybersecurity forensic specialists have also been engaged to assist with the investigation.
As the investigation continues, it remains unclear whether any customer or partner data was stolen. A Hugging Face spokesperson did not respond to a request for comment on Monday. The company did not immediately provide evidence for its claim regarding the external AI agent when asked by TechCrunch.
