DMR News

Advancing Digital Conversations

Hugging Face Breach Exposes Internal Datasets and Service Credentials

ByJolyen

Jul 21, 2026

Hugging Face Breach Exposes Internal Datasets and Service Credentials

AI development platform Hugging Face has disclosed a cyberattack that gave an intruder access to internal datasets and credentials used by several company services. The company is still investigating whether any customer or partner information was affected.

Hugging Face said it found no evidence that public models, datasets or Spaces were altered. It also checked its published software packages and container images and found no signs of supply-chain tampering.

Malicious Dataset Exploited Processing Systems

According to Hugging Face’s official incident disclosure, the attack began when a malicious dataset exploited vulnerabilities in its data-processing pipeline. The flaws allowed unauthorised code to run on a processing worker before the attacker increased its permissions and accessed other internal systems.

Hugging Face said its internal anomaly-detection systems identified the activity. The company then isolated affected systems, fixed the exploited vulnerabilities and began reviewing the attacker’s actions.

The company revoked and rotated the compromised service credentials. It also advised users to replace any access keys stored on the platform and examine their accounts for unfamiliar activity.

Company Attributes Attack to an AI Agent

Hugging Face attributed the intrusion to an external AI agent that carried out thousands of individual actions across short-lived computing environments. It said the attacker moved its command-and-control activity between publicly available services to maintain access.

The company has not publicly identified the person or organisation responsible for operating the system. It also did not initially provide independent evidence confirming that the attack was conducted autonomously by an AI agent.

A TechRepublic report said Hugging Face described the incident as a multistage attack conducted against its production infrastructure. External forensic investigators are reviewing the company’s findings.

Local Model Used to Examine Attack Logs

Hugging Face initially tried to analyse its server logs with a commercial frontier AI model. The company said the provider’s safety controls blocked parts of the cybersecurity investigation because some requests resembled instructions that could be used offensively.

It then used a locally operated large language model to examine the logs. Running the model internally also allowed Hugging Face to avoid transferring sensitive security records to an outside provider.

The company has notified law enforcement and hired cybersecurity specialists to investigate the breach. Its assessment of potential customer and partner exposure remains ongoing, and affected parties will be contacted directly where required.


Featured image credits: Magnific.com

For more stories like it, click the +Follow button at the top of this page to follow us.

Jolyen

As a news editor, I bring stories to life through clear, impactful, and authentic writing. I believe every brand has something worth sharing. My job is to make sure it’s heard. With an eye for detail and a heart for storytelling, I shape messages that truly connect.

Leave a Reply

Your email address will not be published. Required fields are marked *