Hugging Face confirms breach exposing internal datasets and credentials
> cd .. / HUB_EDITORIALE
News

Hugging Face confirms breach exposing internal datasets and credentials

[2026-07-20] Author: Meteora Web Redazione
> share
Zenithby Meteora Web The operating system for your business. Social, clients, bookings and invoices in one platform. Gyms, barbers, professionals. Discover Zenith Free demo · no card

Hugging Face, the AI model hosting platform, has suffered a cyberattack that compromised internal datasets and service credentials. The company disclosed the incident on Friday, noting that investigations are ongoing to determine whether customer or partner data was stolen.

External AI agent exploited a vulnerability to escalate privileges

According to Hugging Face, a dataset uploaded to the platform abused a security flaw to execute malicious code on its servers, allowing attackers to escalate permissions and gain broader access to internal systems. The company identified the attack as the work of an external AI agent, capable of executing thousands of individual actions across a swarm of short-lived sandboxes, with self-migrating command-and-control staged on public services.

Anomaly detection via AI and log analysis

Hugging Face stated that its anomaly detection system spotted the attack, using an AI model to analyze server logs. Initially, the company used a frontier AI model from a commercial provider, but the provider's guardrails blocked the analysis. Thus, Hugging Face switched to its own local large language model, which offered the benefit of not uploading sensitive logs to third-party servers. This incident highlights the limitations of commercial AI models in cybersecurity contexts.

Sponsored Protocol

Credentials revoked and users urged to rotate tokens

Hugging Face has revoked and rotated the stolen credentials, urging all users to do the same with any keys stored on the platform and to review their accounts for suspicious activity. Prompt action is essential to prevent unauthorized access. In a landscape where AI is increasingly used for assistance, such as Apple's test of AI-powered Live Notes for Genius Bar repairs (read the article Apple Tests AI-Powered Live Notes to Transcribe Genius Bar Repairs), cybersecurity must also evolve.

Sponsored Protocol

Law enforcement notified and forensic investigation underway

Hugging Face has reported the breach to law enforcement and enlisted cybersecurity forensic specialists to investigate and review security measures. It is unclear whether the company had performed a security audit prior to launch. The incident underscores the challenges AI platforms face against hackers who exploit the same tools to access sensitive data. For further details on cyberattacks, visit the Wikipedia page on Hugging Face.

Source: https://techcrunch.com/2026/07/20/hugging-face-confirms-breach-affected-internal-datasets-and-credentials-urges-users-to-take-action

> share
Meteora Web Redazione

> AUTHOR_EXTRACTED

Meteora Web Redazione

La redazione di Meteora Web Agency: ingegneri informatici e professionisti del digitale che pubblicano ogni giorno news e approfondimenti su tecnologia, software, marketing e innovazione.
[ Read Full Dossier ]

> METEORA_WEB // DIGITAL AGENCY

We build the digital presence your business deserves.

Websites, social media, online advertising, e-commerce and high-performance hosting, engineered with method by computer engineers in Sciacca, for all of Italy.

> MW_JOURNAL

> READ_ALL()