Hugging Face Confirms AI Agent Breached Production Systems
Hugging Face said an autonomous AI agent carried out a cyberattack against its production infrastructure, according to TechRepublic. The company confirmed that the attacker exploited weaknesses in its data processing pipeline, leading to unauthorized access to some internal datasets and service credentials. No public models, user data, or published software were affected, and the company has advised users to rotate tokens and review account activity.
The breach began when a malicious dataset triggered code execution paths in Hugging Face’s dataset loader and configuration system, as detailed by Hyper.ai. The attacker, operating through a distributed AI agent framework, executed thousands of automated actions, escalated privileges, and moved laterally across internal clusters.
Hugging Face’s internal AI supported security tools detected the intrusion and analyzed more than 17,000 attacker logs to reconstruct the timeline and verify the scope of compromise. Investigators relied on the GLM 5.2 model hosted privately to avoid safety restrictions in commercial models that interfered with forensic analysis.
The company has since closed exploited paths, rebuilt affected systems, tightened cluster security, and involved external forensic specialists and law enforcement. The investigation remains active.
We hope you enjoyed this article
Consider subscribing to one of our newsletters like Cybersecurity AI Weekly or Daily AI Brief.
Also, consider following us on social media:
More from Cybersecurity
Sep 16 AV-Comparatives Certifies 11 Endpoint Security Products in 2026 Test Sep 16 Cohesity Adds AI Agent Backup and Recovery to Data Cloud Sep 15 Hexnode Introduces Synapse for IT and Security Operations Sep 15 Cisco Expands Splunk AI for Private and Isolated Environments Sep 15 Zip Security Joins CrowdStrike Coalition to Protect Small BusinessesCybersecurity AI Weekly
Weekly newsletter about AI in Cybersecurity.
Industry analysis
2025 Global Business Services Agenda: Gen AI Takes Center Stage
This industry analysis by The Hackett Group explores the transformative impact of generative artificial intelligence (Gen AI) on global business services (GBS) in 2025. The study highlights the shift from exploration to acceleration of Gen AI initiatives, with 89% of executives advancing these projects to improve customer satisfaction, innovate products, and reduce costs. The report also discusses the challenges and strategies for successful Gen AI adoption, emphasizing the need for a technology-enabled operating model and the importance of reskilling the workforce.
Read moreYou may also like
Senate Opens Inquiry Into OpenAI Agents' Hugging Face Hack
OpenAI Executive Warns of Persistent AI Cyber Attacks
Researchers Link OpenAI Agents to May RubyGems Attack
Anthropic's Threat Report Finds AI Moving From Assistant to Orchestrator
US Agencies Accuse Chinese AI Firms of Industrial Scale Model Distillation
Daily AI Brief: the AI news that matters, in your inbox.