Hugging Face, the AI model hosting platform, has suffered a cyberattack that compromised internal datasets and service credentials. The company disclosed the incident on Friday, noting that investigations are ongoing to determine whether customer or partner data was stolen.
External AI agent exploited a vulnerability to escalate privileges
According to Hugging Face, a dataset uploaded to the platform abused a security flaw to execute malicious code on its servers, allowing attackers to escalate permissions and gain broader access to internal systems. The company identified the attack as the work of an external AI agent, capable of executing thousands of individual actions across a swarm of short-lived sandboxes, with self-migrating command-and-control staged on public services.
Anomaly detection via AI and log analysis
Hugging Face stated that its anomaly detection system spotted the attack, using an AI model to analyze server logs. Initially, the company used a frontier AI model from a commercial provider, but the provider's guardrails blocked the analysis. Thus, Hugging Face switched to its own local large language model, which offered the benefit of not uploading sensitive logs to third-party servers. This incident highlights the limitations of commercial AI models in cybersecurity contexts.
Sponsored Protocol
Credentials revoked and users urged to rotate tokens
Hugging Face has revoked and rotated the stolen credentials, urging all users to do the same with any keys stored on the platform and to review their accounts for suspicious activity. Prompt action is essential to prevent unauthorized access. In a landscape where AI is increasingly used for assistance, such as Apple's test of AI-powered Live Notes for Genius Bar repairs (read the article Apple Tests AI-Powered Live Notes to Transcribe Genius Bar Repairs), cybersecurity must also evolve.
Sponsored Protocol
Law enforcement notified and forensic investigation underway
Hugging Face has reported the breach to law enforcement and enlisted cybersecurity forensic specialists to investigate and review security measures. It is unclear whether the company had performed a security audit prior to launch. The incident underscores the challenges AI platforms face against hackers who exploit the same tools to access sensitive data. For further details on cyberattacks, visit the Wikipedia page on Hugging Face.