Subscribe
Hugging Face AttackJul 16, 20261 source

Hugging Face discloses an intrusion run end to end by an autonomous AI agent system

Hugging Face said it detected and contained an intrusion into part of its production systems that was driven by an autonomous AI agent framework. It found no tampering with public models, datasets or Spaces.

Hugging Face CEO Clément Delangue, with the Hugging Face logo

Photo: SiliconANGLE theCUBE / Wikimedia Commons, CC BY 3.0. Logo via Wikimedia Commons (Public domain).

Hugging Face disclosed on July 16 that earlier that week it had detected and responded to an intrusion into part of its production infrastructure. The company said the incident differed from anything it had handled before because it was driven end to end by an autonomous AI agent system.

According to the disclosure, a malicious dataset abused two code-execution paths in Hugging Face's dataset processing to run code on a processing worker. From there the actor escalated to node-level access, collected cloud and cluster credentials, and moved into several internal clusters over a weekend. At the time, Hugging Face said the model behind the agents was not known.

The company said it found unauthorized access to a limited set of internal datasets and several service credentials, but no evidence of tampering with public models, datasets or Spaces, and that its software supply chain was verified clean. It closed the vulnerable code paths, rebuilt affected nodes, rotated credentials, reported the incident to law enforcement and advised users to rotate their access tokens.

Hugging Face also said commercial AI models it first tried for forensic analysis blocked its requests because of safety guardrails, so it ran the analysis on the open-weight GLM-5.2 model on its own infrastructure.

Sources (1)

  1. Hugging Face — Security incident disclosure, July 2026
← Back to AI World News