Hugging Face Says Autonomous AI Agents Breached Its Systems


hugging face breach
Image credit: Hugging Face

Hugging Face says an autonomous AI agent system breached its infrastructure, compromised credentials, and accessed a limited number of internet datasets.

The company detected and investigated much of the attack with its own AI-powered security tools. It has not yet confirmed the full extent of any data theft.

Attackers Accessed Datasets and Service Credentials

Hugging Face said the attackers gained unauthorized access to a limited number of internet datasets. They also compromised several credentials used by the company’s services.

The investigation has found no evidence that the attackers modified public-facing models, datasets, or Spaces.

Hugging Face also said its software supply chain remains clean. This includes its published packages, container images, and other software distributed to users.

The company continues to investigate whether the attackers stole customer or partner data. It plans to notify affected parties if investigators confirm any data theft.

Malicious Dataset Triggered the Breach

The attack began when a malicious dataset abused code-execution paths in Hugging Face’s dataset-processing infrastructure.

This allowed malicious code to execute on a processing worker. The attacker then escalated privileges and gained node-level access.

After compromising the worker, the attackers collected cloud and cluster credentials from the affected systems. They used those credentials to move into several internal clusters during the weekend.

The intrusion shows how a malicious dataset can become an entry point into systems that automatically process uploaded content.

Autonomous AI Agents Carried Out Thousands of Actions

Hugging Face said an agentic AI system conducted the attack from beginning to end.

The company has not identified the specific large language models used by the attackers. However, the system reportedly completed thousands of individual actions across temporary sandbox environments.

It also used self-migrating command-and-control infrastructure hosted through public services. This approach allowed the operation to move between environments and maintain access as the attack progressed.

Hugging Face Rotates Credentials and Adds Protections

Hugging Face revoked and rotated compromised credentials and access tokens after detecting the intrusion.

The company also introduced stricter cluster admission controls and additional security guardrails. It improved its detection and alerting systems to support responses to high-severity incidents within minutes.

External cybersecurity forensic specialists have joined the investigation. Hugging Face is also reviewing its security policies and internal procedures.

The company reported the incident to law enforcement.

Users Should Rotate Hugging Face Access Tokens

Hugging Face recommends that users rotate their account access tokens as a precaution.

Users should also review recent account activity for unknown logins, unexpected changes, or suspicious operations. Integrations and services that still rely on older credentials should receive new tokens.

Anyone who believes the incident may have affected their account should contact Hugging Face’s security team.

AI-Driven Cyberattacks Create New Security Risks

The breach highlights the growing threat of automated cyberattacks. Microsoft has also changed its AI defense strategy as these threats grow, urging organizations to patch systems quickly and strengthen defenses against AI-assisted attacks and threats such as ACR Stealer.

The Hugging Face incident shows how autonomous systems can coordinate attacks at scale, making rapid detection, credential protection, and infrastructure isolation increasingly important.

More about the topics: AI, security

Readers help support Windows Report. We may get a commission if you buy through our links. Tooltip Icon

Read our disclosure page to find out how can you help Windows Report sustain the editorial team. Read more

User forum

0 messages