Data Breaches Hugging Face Hacked in Autonomous AI Attack Targeting production infrastructure, the attack compromised internal datasets and service credentials. By Ionut Arghire | July 20, 2026 (5:36 AM ET) Flipboard Reddit Whatsapp Whatsapp Email Machine learning collaboration platform Hugging Face has disclosed a data breach resulting from a cyberattack conducted by an autonomous AI agent. The attack targeted the company’s production infrastructure and resulted in unauthorized access to internal datasets and to service credentials. According to Hugging Face, a data-processing pipeline was used as the entry point, followed by node-level escalation, credential harvesting, and lateral movement. “A malicious dataset abused two code-execution paths in our dataset processing (a remote-code dataset loader and a template-injection in a dataset configuration) to run code on a processing worker,” Hugging Face explains . The attackers used an autonomous framework built on an agentic security-research harness to execute tens of thousands of actions across short-lived sandboxes, and relied on public services to stage self-migrating command-and-control (C&C) capabilities. Hugging Face says it responded to the attack largely with its own AI, addressed the dataset code-execution paths exploited for initial access, evicted the attackers from its infrastructure, rebuilt the affected nodes, and revoked and rotated all affected credentials. Advertisement. Scroll to continue reading. As a precaution, it also started broadly revoking secrets, deployed stricter admission controls and additional guardrails, and improved detection and alerting. The company reported the incident to law enforcement and is investigating it in collaboration with outside cybersecurity forensic specialists. “We have found no evidence of tampering with public, user-facing models, datasets, or Spaces, and our software supply chain (container images and published packages) was verified clean,” Hugging Face says. The company says its systems logged over 17,000 events associated with the intrusion and ran agentic analysis to reconstruct the incident timeline and determine its scope. However, it could not determine the LLM that the threat actor used to automate the attack. “Autonomous, AI-driven offensive tooling is no longer theoretical. It lowers the cost of running a broad, patient, multi-stage campaign, and it operates at machine speed. Defending an online platform now means treating the data and model surface as a first-class attack surface, and using AI on defense to keep pace,” the company notes. Related: AI Data Centers Are Being Built Faster Than They Can Be Secured Related: Unpatched Cursor Vulnerability Exposes Users to Code Execution Related: White House Launches AI-Driven ‘Gold Eagle’ Vulnerability Coordination Initiative Related: Unpatched Claude for Chrome Flaw Lets Extensions Read Gmail, Calendar Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire Fresh SharePoint Vulnerability Exploited Soon After Disclosure Coca-Cola Suspends US Fairlife Production Due to Ransomware Attack Oak Emerges From Stealth Mode With $60 Million in Funding Splunk, Zoom Patch Critical Vulnerabilities F5 Patches Multiple NGINX, BIG-IP Vulnerabilities Old UEFI Shims Expose Systems to Secure Boot Bypass Nightmare Eclipse Drops ‘LegacyHive’ Windows Zero-Day Unpatched Cursor Vulnerability Exposes Users to Code Execution Latest News Chrome 150 Update Patches Severe Memory Safety Bugs WP2Shell WordPress Vulnerabilities Exploited in the Wild In Other News: Iran Tracks US Military Phones, CrashStealer macOS Malware, CVD Blueprint Podcast: Broken Governance, Agentic AI, and the MindStone Agent Exclusive Beacon Security Raises $13 Million for Security Data Platform Industry Reactions to Pentagon Suspending CMMC Phase 2: Feedback Friday Cyberattack Disrupts Operations of Japanese Frozen Food Giant Nichirei Risk Ledger Raises $32 Million in Series B Funding Trending Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Why Email Security Keeps Failing (And What Has to Change) July 8, 2026 Join this live webinar as we break down why email-layer defenses alone can't keep pace with the modern phishing ecosystem, how agentic AI is changing the capacity equation for security teams, and more. Register Virtual Event: 2026 Cloud Security Summit July 15, 2026 This year's summit will help organizations learn how to utilize tools, controls, and design models needed to properly secure cloud environments. Interact with leading solution providers and other end users facing similar challenges in securing a variety of cloud deployments. Register People on the Move Jazz has named Sean Robinson, Rickie Goyal, Danielle Guetta, Shani Nago, and Lior Magram as VPs and Michael Calev as COO. AJ Shipley has been appointed Chief Product Officer at CrowdStrike. Brinqa has named Ron Dovich as Chief AI and Automation Officer, David Allen as CTO, Steve Biagioni as CFO, and James Walta as VP of Product. More People On The Move Expert Insights Legacy Systems, Real-World Impacts: The Reality of OT Security Legacy systems, safety concerns, and critical infrastructure risks make OT vulnerability disclosure one of cybersecurity's most challenging balancing acts. (Tod Beardsley) The Shift Toward Business-Aligned Risk Management Moving from isolated, technical data to a continuous risk lifecycle can help organizations align security controls with actual business consequences. (Steve Durbin) How to Conduct a Successful Audit of AI-Driven Software Development As AI-generated code becomes commonplace, CISOs need new audit strategies to measure developer practices, govern AI tool usage, and identify software risks before they reach production. (Matias Madou) Frontier AI: Six Questions Every Enterprise Should Ask Security Vendors From model selection and automation to validation and measurable results, the right questions can help enterprises separate genuine AI capabilities from marketing hype. (Joshua Goldfarb) The AI Token Costs That Can Break Cybersecurity As cybersecurity platforms embrace agentic AI, organizations must balance detection performance against the escalating costs of token consumption, deployment architecture, and AI credits. (Danelle Au) Flipboard Reddit Whatsapp Whatsapp Email
The attack exploited two code-execution paths in Hugging Face's dataset processing pipeline—a remote-code dataset loader and a template-injection vulnerability in dataset configuration—to gain initial access, followed by node-level escalation, credential harvesting, and lateral movement using an autonomous AI agent framework. Hugging Face responded by patching the exploited code-execution paths, rebuilding affected nodes, and broadly rotating credentials, while also deploying stricter admission controls and improved detection. The incident demonstrates that autonomous AI-driven offensive tooling is now operational, requiring defenders to treat data and model surfaces as primary attack vectors and leverage AI for defense.