Hugging Face Breach Caused by Autonomous AI Agent
Hugging Face reports an autonomous AI agent exploited dataset code-execution paths, accessing internal datasets and service credentials in its production environment.
Hugging Face disclosed a breach in its production infrastructure after an autonomous AI agent exploited dataset processing to run code, gaining access to internal datasets and service credentials.
The company reported the attack began in a data-processing pipeline. A malicious dataset, the company wrote, “abused two code-execution paths in our dataset processing (a remote-code dataset loader and a template-injection in a dataset configuration) to run code on a processing worker.”
Hugging Face reported attackers used an autonomous framework based on an agentic security-research harness to execute tens of thousands of actions across short-lived sandboxes. The intruders relied on public services to stage self-migrating command-and-control capabilities, and the company logged more than 17,000 events related to the activity.
The sequence of events outlined by Hugging Face began with initial access through dataset processing, followed by node-level escalation, harvesting of service credentials and lateral movement inside the environment.
Company investigators were unable to determine which large language model the attacker used to automate the campaign. In its disclosure, Hugging Face wrote, “Autonomous, AI-driven offensive tooling is no longer theoretical. It lowers the cost of running a broad, patient, multi-stage campaign, and it operates at machine speed.”
Hugging Face said it responded mainly with its own AI tooling. The company addressed the exploited dataset code-execution paths, evicted the attackers, rebuilt affected nodes and revoked and rotated impacted credentials. As added precautions, it began broadly revoking secrets, tightened admission controls, added guardrails and improved detection and alerting across the platform.
The company reported the incident to law enforcement and engaged external cybersecurity forensic specialists to investigate. It is reviewing internal datasets and access logs to determine the full scope of exposed information.
Hugging Face stated it found no evidence of tampering with public, user-facing models, datasets or Spaces, and that its software supply chain, including container images and published packages, was verified clean.
The company shared technical details about the exploited dataset processing paths and the defensive measures it implemented while the investigation continues. Hugging Face also urged platforms to reassess how they protect models and data and said defenders must treat data and model surfaces as primary attack surfaces and use AI on defense to address automated threats.








