Search TorNews

Find cybersecurity news, guides, and research articles

Popular searches:

Home » News » Cyber Threats » Hugging Face Says AI-Driven Cyberattack Breached Part of Production Infrastructure

Hugging Face Says AI-Driven Cyberattack Breached Part of Production Infrastructure

Last updated:July 21, 2026
Human Written
  • Hugging Face says a stealthy AI agent network compromised part of its infrastructure for production after exploiting a malicious dataset.

  • The attackers stole internal credentials and moved across several systems, but the company found no evidence that public AI models or datasets were altered.

  • The incident shows how AI can now automate complex cyberattacks with very little human involvement.

Hugging Face Says AI-Driven Cyberattack Breached Part of Production Infrastructure

Hugging Face has confirmed that attackers breached part of its production infrastructure during a cyberattack driven by an autonomous AI agent system. The company said the attackers gained access to a limited number of internal datasets and service credentials before security teams stopped the intrusion.

The New York-based AI platform said it quickly detected the attack and removed the attackers from its systems. The investigation is still underway. However, the company said it has not found any sign that public AI models, datasets, Spaces, or its software supply chain were changed during the incident.

The breach stands out because the attackers relied on artificial intelligence to carry out most of the operation. According to Hugging Face, the attack involved thousands of automated actions instead of depending on constant human control.

Attack Started with a Malicious Dataset

Hugging Face said the attack began when a malicious dataset entered its data processing pipeline. The dataset abused two different code execution paths to run malicious code on one of the company’s processing workers.

After breaking into the system, the attackers increased their access level. They then took cloud as well as cluster credentials before moving through several internal clusters over the weekend.

The sophistication of such attacks is evident in the ransomware incident that forced Coca-Cola to halt Fairlife production in the U.S.

According to Hugging Face, the campaign relied on “many thousands of separate actions” completed by a swarm of short-lived AI agent environments. The company also explained that these agents used self-moving command-and-control infrastructure hosted on public online services.

The company has not identified the large language model behind the attack. It remains unclear whether the attackers used a modified commercial model or an unrestricted open-weight model.

Even without knowing the exact AI model, Hugging Face said the incident proves that autonomous AI systems can now perform complicated cyberattacks with very little human involvement. According to the company, these systems are becoming capable of handling several attack stages on their own.

After discovering the breach, Hugging Face removed the attackers’ access and rebuilt the affected systems. The company also replaced compromised credentials and security tokens.

It tightened cluster admission controls and improved its monitoring tools so security teams can receive alerts within minutes whenever suspicious activity appears. As an added safety measure, Hugging Face urged customers to rotate their access tokens and carefully review recent account activity for anything unusual.

AI Safety Rules Slowed the Investigation

The company’s investigation revealed another unexpected challenge. Hugging Face said several well-known Western AI models refused to help analyze the attack. Their built-in safety rules blocked prompts that contained real exploit code, attack commands, and command-and-control artifacts.

Because of those restrictions, the company’s investigators turned to GLM 5.2, an open-weight AI model developed by the Chinese company Z.ai. Unlike the other models, it processed the technical evidence without stopping the investigation because of safety restrictions.

According to Hugging Face, this experience exposed an important challenge for defenders. Attackers running unrestricted or self-hosted AI models often face very few limits. Meanwhile, security teams using commercial AI assistants may struggle because built-in safety rules cannot always tell the difference between a real cyberattack and a legitimate security investigation.

The company explained that these restrictions can slow incident response when investigators need AI to study real attack data. Hugging Face said organizations should maintain capable AI models that can run entirely inside their own secure infrastructure during cyber investigations.

According to the company, this approach helps prevent interruptions caused by safety policies. It also keeps sensitive attack data, credentials, and forensic evidence from leaving protected environments.

Company Says Public AI Models Were Not Affected

Although attackers entered parts of the company’s production infrastructure, Hugging Face said the breach never reached its public-facing AI services. The company stated that it found no evidence showing attackers had altered publicly available AI models, datasets, Spaces, or its software supply chain.

Even so, the incident highlights a growing shift in cyber threats. Instead of using AI only to create software or write code, attackers can now use autonomous systems to search for weaknesses, exploit them, steal credentials, and move through internal networks much faster.

According to Hugging Face, the recent attack demonstrates how quickly autonomous AI systems are advancing. The company said these systems are becoming increasingly capable of carrying out complex operations with minimal human input.

For now, Hugging Face says it has contained the breach and strengthened its security measures. The investigation continues as the company works to understand every part of the attack and determine exactly how the autonomous AI system carried out the operation.

The incident also serves as a reminder that AI platforms themselves have become valuable targets. As autonomous AI technology continues to improve, organizations that build and host AI systems may increasingly face attackers who use artificial intelligence not just as a tool, but as the driving force behind sophisticated cyber operations.

Share this article

About the Author

Memchick E

Memchick E

Digital Privacy Journalist

Memchick is a digital privacy journalist who investigates how technology and policy impact personal freedom. Her work explores surveillance capitalism, encryption laws, and the real-world consequences of data leaks. She is driven by a mission to demystify digital rights and empower readers with the knowledge to protect their anonymity online.

View all posts by Memchick E >
Comments (0)

No comments.