18 days ago
TechCrunch Jul 20, 2026

Hugging Face confirms breach affected internal datasets and credentials, urges users to take action

Hugging Face, a prominent platform known for hosting AI models and datasets, revealed that it suffered a security breach last week compromising its internal datasets and service credentials. The company disclosed the incident on July 17, 2026, explaining that attackers exploited a security flaw in an uploaded dataset to execute malicious code, elevate their access privileges, and infiltrate Hugging Face's internal systems. Although the investigation is ongoing, Hugging Face has revoked the stolen credentials and urged users to rotate any access tokens stored on the platform and scrutinize their account activity for suspicious behavior.

The cyberattack was reportedly carried out by an external AI agent, which executed thousands of operations through numerous short-lived sandboxes, employing self-migrating command-and-control techniques hosted on public services. Hugging Face detected the intrusion using anomaly detection tools and leveraged an AI model to analyze server logs documenting the attack. Initially, they used a commercial frontier AI model to assist with the analysis but switched to a proprietary local large language model after the commercial provider's security constraints hindered their investigation. This local model also ensured sensitive data did not leave the company’s servers.

This incident highlights the evolving cybersecurity challenges facing companies that serve as infrastructure providers for AI development and deployment, as adversaries increasingly use advanced techniques to exploit platform vulnerabilities. Hugging Face has patched the identified security flaw and engaged cybersecurity forensic experts to further investigate the breach, while also reporting it to law enforcement authorities. The company has not yet confirmed if any customer or partner data was accessed or stolen during the attack.

Amid rapid growth in AI tools, companies like Hugging Face are on the frontline of securing complex ecosystems that blend user-generated content and powerful machine learning capabilities. The breach underscores the importance of robust monitoring, swift response measures, and the use of self-hosted tools for sensitive security work, as reliance on external AI services may sometimes impose unanticipated limitations. Users of Hugging Face's platform are strongly recommended to update their security credentials immediately to protect their data and systems.

0
0 Read source
Share this post
Facebook Twitter LinkedIn

Discussion

0 comments

No comments yet

Start the discussion with a take, question, or market read.