Hugging Face, a platform that hosts artificial intelligence models and datasets, said its internal datasets and service credentials were compromised in a hack last week. The company disclosed the breach on Friday, but said it was still investigating whether any customer or partner data was stolen during the incident.
In a blog postthe company said a dataset uploaded to its platform abused a security vulnerability to run malicious code on its servers, allowing attackers to escalate their permissions and gain wider access to Hugging Face’s internal systems.
The company said it has recalled and replaced the stolen credentials it accessed. It urged users to do the same with any keys stored on the platform and check for any suspicious activity on their accounts.
Hugging Face said it has patched the vulnerability that was exploited during the cyberattack. While it’s common for hackers to try to break into a company’s network using stolen employee credentials, keys, or a weak point in their security perimeter, this incident highlights the challenges companies like Hugging Face face when hackers try to abuse platforms and tools to access and steal sensitive data from the inside.
Hugging Face blamed the breach on an external AI agent, which executed “many thousands of individual actions in a swarm of short-lived sandboxes, with self-migrating commands and control over public services.”
The company did not immediately provide evidence for that claim when asked by TechCrunch.
Hugging Face said its own anomaly detection detected the attack and used an artificial intelligence model to analyze the server logs that kept a record of the cyberattack.
The company said it initially used a border AI model from a commercial provider, although it did not name a company, but found that the analysis effort was blocked by the provider’s guardrails. Instead, the company used its own local large-language model, which it said provided the added benefit of not having to upload sensitive attack logs to an AI firm’s servers.
Security researchers have complained in the past that some boundary models, such as Anthropic’s Mythos and Fable, are too restrictive and prevent defenders from asking almost anything related to cybersecurity, including defense and investigations.
Makers of Frontier AI models, including Anthropic, have been at odds with the Trump administration over fears and concerns about the potential for these models to be used for aggressive cyberattacks. Anthropic was even forced to withdraw the Fable from public use after the US government imposed export controls on the model.
Hugging Face said it has reported the incident to law enforcement and asked cybercrime experts to investigate the breach and review its security.
It is unclear whether Hugging Face had security audited its systems prior to its launch. A representative for Hugging Face did not respond to a request for comment Monday.
When you purchase through links in our articles, we may earn a small commission. This does not affect our editorial independence.
