Hugging Face disclosed a breach of its production infrastructure that it said was conducted from beginning to end by an autonomous AI agent system.
The intrusion gave the attacker unauthorized access to a limited number of internal datasets and several credentials used by Hugging Face services. The company is still investigating whether any customer or partner data was affected.
Hugging Face said it found no evidence that the attacker modified its public models, datasets or Spaces. The company also verified that its container images and published software packages were not compromised.
The breach began with a malicious dataset that exploited two code execution paths in Hugging Face’s data processing pipeline. One involved a remote code dataset loader, while the other used template injection in a dataset configuration.
After gaining access to a processing worker, the attacker escalated to the underlying node, collected cloud and cluster credentials and moved laterally into several internal clusters over a weekend.
Hugging Face said the campaign used an autonomous agent framework that carried out thousands of actions through a swarm of temporary sandboxes. The system also moved its command and control infrastructure between public services. The company has not identified which language model powered the attack.
The intrusion was initially detected by Hugging Face’s own AI assisted security system, which uses language models to examine security telemetry and identify related signals.
Hugging Face then deployed analysis agents to examine more than 17,000 recorded attacker events. The agents reconstructed the intrusion timeline, identified affected credentials and distinguished genuine attacker activity from decoys, reducing an investigation that would normally take days to several hours.
The company initially attempted to perform the analysis using frontier models accessed through commercial APIs. Those models blocked requests containing real attack commands, exploit payloads and command and control artifacts because their safety systems could not distinguish defensive investigation from malicious activity.
Hugging Face instead used GLM-5.2, an open weight model running on its own infrastructure. The local deployment allowed investigators to analyze the attack without safety restrictions blocking the work and prevented sensitive credentials and attacker data from leaving the company’s systems.
The incident highlighted what Hugging Face described as an asymmetry between attackers and defenders. Attackers can use unrestricted or modified models, while security teams relying on hosted commercial systems may be prevented from processing the malicious material required for an investigation.
Hugging Face said security teams should prepare a capable model that can run locally before an incident occurs, allowing them to continue forensic work if commercial systems reject their requests.
The company closed the dataset processing vulnerabilities used for initial access, removed the attacker from affected clusters and rebuilt compromised nodes. It also revoked affected credentials, began a wider rotation of secrets and introduced stricter controls across its infrastructure.
Hugging Face has hired external forensic specialists and reported the incident to law enforcement. As a precaution, it advised users to rotate their access tokens and review recent account activity for anything suspicious.
The company said the breach demonstrated that autonomous offensive AI systems are no longer a theoretical cybersecurity risk and that platforms will increasingly need AI based defenses capable of responding at machine speed.
#Hugging #Face #autonomous #agents #breached #production #systems





