Hugging Face Confirms Breach Exposed Internal Datasets and Service Credentials

Hugging Face has confirmed a cyberattack exposed internal datasets and service credentials after attackers exploited a platform vulnerability, prompting users to rotate stored keys and review account activity.

Jul 20, 2026 - 13:51
 1
Hugging Face Confirms Breach Exposed Internal Datasets and Service Credentials
Image Credit: Chatgpt

Hugging Face has confirmed that a cyberattack last week compromised its internal datasets and service credentials after attackers exploited a security vulnerability on the AI platform. While the company is still investigating whether customer or partner data was accessed, it has urged users to rotate any stored access keys and review their accounts for suspicious activity.

According to the company, the attack began when a dataset uploaded to its platform exploited a vulnerability that allowed malicious code to run on Hugging Face’s servers. The attackers then escalated their privileges and gained broader access to internal systems. Hugging Face said it has since fixed the vulnerability and revoked the compromised credentials.

AI-assisted investigation reveals sophisticated attack.

Hugging Face attributed the breach to an external AI agent that carried out thousands of actions across short-lived sandbox environments using self-migrating command-and-control infrastructure hosted on public services. The company said its anomaly detection systems identified the unusual activity before using artificial intelligence to analyse server logs and reconstruct the attack.

Initially, Hugging Face relied on a frontier AI model from a commercial provider to analyse the incident. However, the company said theprovider’ss guardrails prevented effective cybersecurity analysis, prompting it to switch to its own locally hosted large language model. Running the investigation internally also avoided uploading sensitive attack logs to an external AI service.

Security concerns extend beyond the breach.

The incident highlights the growing challenges AI companies face as attackers increasingly attempt to exploit their own platforms and development tools. It also adds to the ongoing debate over restrictions placed on frontier AI models, with security researchers arguing that some safeguards limit legitimate cyber defence and forensic investigations.

Hugging Face said it has reported the breach to law enforcement and engaged cybersecurity forensic specialists to investigate the incident and review its security measures. The company has not confirmed whether it conducted a comprehensive security audit before launching the affected systems, and a spokesperson did not respond to requests for further comment.

What's Your Reaction?

Like Like 0
Dislike Dislike 0
Love Love 0
Funny Funny 0
Angry Angry 0
Sad Sad 0
Wow Wow 0
Shivangi Yadav Shivangi Yadav reports on startups, technology policy, and other significant technology-focused developments in India for TechAmerica.Ai. She previously worked as a research intern at ORF.