Hugging Face Infiltrated by AI: Unprecedented Cyberattack Thwarted

Le brief IA que les pros lisent chaque soir
Les 7 actus IA du jour, décryptées en 5 min. Gratuit.
Inclus dès l'inscription : notre sélection des meilleurs guides & comparatifs IA.
Choisis ton rythme
Gratuit · Pas de spam · Désabonnement en 1 clic
An AI Agent Infiltrated Hugging Face Before an AI Defender Caught It
Hugging Face recently reported a concerning security incident involving an unidentified AI agent. This agent managed to infiltrate the platform, potentially exposing credentials and sensitive data. The extent of the impact on partners and clients remains to be determined, as the investigation is still ongoing.
What is Hugging Face?
Hugging Face presents itself as an open-source repository and community platform where the machine learning community collaborates on models, datasets, and applications. The platform is a valuable resource for those interested in AI and large language models (LLMs). It offers datasets, applications, models, as well as trending AI creations and collaboration opportunities.
A Data Set Catastrophe
In a security notice published on July 16, Hugging Face indicated that it had detected unauthorized access to a limited set of internal datasets and several credentials used by the platform's services. The attack began with Hugging Face's data processing pipeline. A dataset deployed by the attacker included the ability to exploit two code execution paths: a remote code data loader and a model injection in a dataset configuration, allowing for the execution of malicious code on a processing worker.
This enabled the attacker to escalate privileges to node-level access, infiltrate the production pipeline, move through the network, and steal cloud and cluster credentials. However, Hugging Face claims that it was actually an unknown AI agent that executed "thousands of individual actions across a swarm of ephemeral sandboxes, with self-migrating command and control over public utilities." More than 17,000 events related to this automated attack were recorded. "This aligns with the scenario of the agentic attacker that the industry anticipated," added Hugging Face.
The organization found no evidence of manipulation of public and user-oriented models, Spaces, or its software supply chain — at least, at this stage.
Hugging Face's Defense and Response
Data breaches, information leaks, and security incidents are, unfortunately, now very common — but it is the combination of AI against AI that makes the Hugging Face incident remarkable. While an AI agent was blamed for launching the attack, it was also an AI that "largely detected" the incident, according to Hugging Face.
Hugging Face's own LLM tools reported the security event and also analyzed the attack log, allowing for a reconstruction of the timeline, indicators of compromise, and mapping of exposed and stolen credentials, a task that took a few hours when it "would normally have taken days," according to the team.
"Hugging Face noted that autonomous, AI-driven offensive tooling is no longer theoretical. This reduces the cost of implementing a broad, patient, multi-step campaign, and it operates at machine speed. Defending an online platform now means treating data and model surfaces as a primary attack surface and using AI in defense to keep pace."
We will likely see the evolution of AI-based attacks and defenses in the months and years to come. In the meantime, Hugging Face has patched the initial vulnerability that allowed access; eliminated all traces of the attacker in the impacted clusters, rebuilt the compromised nodes, revoked and rotated secrets, and deployed additional safeguards as well as stricter admission controls across the clusters.
What Should Hugging Face Users Do Next?
Hugging Face is assessing whether partner or client data has been affected by the breach and will contact the relevant parties. Until Hugging Face determines exactly which datasets, partners, and users are affected — if any — it recommends precautionary measures to protect user accounts and information.
Users should:
- Rotate their access tokens and closely monitor their accounts for any signs of unusual, unknown, or suspicious activity.
- If Hugging Face users believe they have been impacted by this breach, they should contact the organization directly at security@huggingface.co.
Brief IA — L'actualité IA en français
L'essentiel de l'actualité de l'intelligence artificielle, décrypté et expliqué chaque jour.