Brief IA

Hugging Face Responds to a Cyberattack Orchestrated by an AI

💻 Code & Dev·Tom Levy·

Hugging Face Responds to a Cyberattack Orchestrated by an AI

Hugging Face Responds to a Cyberattack Orchestrated by an AI
Key Takeaways
1Hugging Face suffered a cyberattack carried out by an autonomous AI agent, targeting its production infrastructure.
2The attack involved thousands of coordinated actions by an agent framework, making defense complex.
3Commercial AI models hindered the response by failing to distinguish operational data from actual attacks.
💡Why it mattersThis attack highlights the challenges posed by autonomous AIs in cybersecurity, even for advanced tech companies.
Le brief IA que lisent les pros

Le brief IA que les pros lisent chaque soir

Les 7 actus IA du jour, décryptées en 5 min. Gratuit.

Inclus dès l'inscription : notre sélection des meilleurs guides & comparatifs IA.

Choisis ton rythme

Gratuit · Pas de spam · Désabonnement en 1 clic

📄
Full Analysis

Hugging Face Responds to a Cyberattack Orchestrated by an AI

Hugging Face, the popular AI platform, has fallen victim to a cyberattack that was reportedly carried out entirely by an autonomous AI agent system. The attackers used a malicious dataset as an entry point, allowing them to compromise internal data and steal login credentials from the platform.

To analyze the more than 17,000 actions recorded by the attacker, Hugging Face deployed its own AI tools, completing the forensic analysis in just a few hours instead of several days.

Details of the Attack

Hugging Face revealed a breach of certain parts of its production infrastructure, allegedly executed by an autonomous AI agent system. According to the company, the attackers gained unauthorized access to a limited set of internal datasets and several credentials used by Hugging Face services. The company claims that public models, datasets, and Spaces were not altered, and the software supply chain was not affected. The investigation is still ongoing to determine if partner or customer data was compromised.

An Open Door Through a Malicious Dataset

According to Hugging Face, the attack began at one of the weakest points of any AI platform: the data processing pipeline. A malicious dataset exploited two code execution paths in the processing of datasets, particularly a remote dataset loader and a model injection in a dataset configuration.

From there, the attacker escalated to the node level, harvested cloud and cluster credentials, and moved laterally across several internal clusters over a weekend. A framework of autonomous agents built on a security agent research harness orchestrated the entire campaign, according to the company.

Hugging Face does not know which language model powered the attack. The system executed thousands of individual actions across a swarm of ephemeral sandboxes and used a self-migrating command and control infrastructure operating on public services. The company classifies the incident as the scenario of the agentic attacker that the industry has been predicting for some time.

AI-Powered Analysis Reduced Investigation Time

Hugging Face detected the attack through an AI-powered anomaly detection pipeline that executes LLM-based triage (large language model triage) on security telemetry. To understand the more than 17,000 actions recorded from the attacker, the company deployed LLM-driven analysis agents.

These agents reconstructed the timeline, extracted indicators of compromise, mapped affected credentials, and separated actual damage from deceptive activities. A task that would normally take days was completed in just a few hours, according to the company.

Commercial Security Filters Blocked the Company’s Defense

According to Hugging Face, when the security team initially attempted to analyze the attack logs using cutting-edge models behind commercial APIs, they encountered a roadblock. The security safeguards of the vendors blocked requests because they could not distinguish between an incident responder and an attacker. The analysis required the submission of large volumes of actual attack commands, exploit payloads, and C2 artifacts, which triggered the filters.

The company then turned to the open-weight model GLM 5.2, operating on its own infrastructure. According to the company, this had two advantages: no attacker data and none of the referenced credentials ever left its environment.

Hugging Face stated, "We do not know which model powered the attacker’s agents, whether it was a jailbroken hosted model or an unrestricted open-weight model; in any case, the attacker was not bound by any usage policy, while our own forensic work was blocked by the safeguards of the hosted models we initially tried."

Hugging Face's Response and Open Questions

Hugging Face stated that it has closed the exploited code execution paths, revoked the attacker’s access, rebuilt the compromised nodes, and rotated the affected credentials. The company has also strengthened access controls and improved its detection systems, according to the blog post. Hugging Face is collaborating with external cybersecurity experts and has reported the incident to law enforcement. As a precaution, the company recommends that all users rotate their access tokens and review recent activity on their accounts.

The incident confirms that autonomous, AI-driven attack tools are no longer theoretical. According to Hugging Face, they reduce the cost of broad, multi-step campaigns and operate at machine speed. The company argues that data and model surfaces must be considered first-class attack surfaces and that defenders need their own AI to keep pace.

Hugging Face emphasizes that the fact that commercial security filters blocked its own forensic work is a gap that the industry must anticipate. However, the company is also one of the largest platforms for open-source AI models and has a clear commercial interest in presenting open models as essential for security work, so its conclusion that defenders absolutely need their own open-weight models at hand is not entirely selfless.

Brief IA — L'actualité IA en français

L'essentiel de l'actualité de l'intelligence artificielle, décrypté et expliqué chaque jour.