Hugging Face Discloses Security Breach Compromising Internal Datasets and Credentials
Key Takeaways
- ▸Hugging Face suffered a breach of internal datasets and service credentials after attackers exploited a vulnerability using an external AI agent to escalate permissions
- ▸Frontier AI model guardrails blocked security analysis, forcing the company to use its own LLM for forensic investigation instead of outsourcing to commercial providers
- ▸Law enforcement has been notified; the company is still determining whether customer or partner data was compromised during the attack
Summary
Hugging Face, the popular platform for hosting AI models and datasets, disclosed a security breach that compromised internal datasets and service credentials. An external AI agent exploited a vulnerability in a user-uploaded dataset to run malicious code on Hugging Face servers, allowing attackers to escalate permissions and access internal systems. The breach was detected by Hugging Face's anomaly detection systems, and the company has since revoked and rotated stolen credentials while fixing the vulnerability.
Hugging Face stated it is still investigating whether customer or partner data was stolen during the incident. Notably, the company initially attempted to use a frontier AI model from a commercial provider to analyze attack logs and server records, but found the analysis blocked by the provider's security guardrails. Hugging Face instead relied on its own local language model to conduct forensic analysis, avoiding the need to share sensitive attack logs with external AI providers.
Hugging Face has reported the incident to law enforcement and engaged cybersecurity forensic specialists to investigate. The company urges users to review API keys and credentials stored on the platform, check for suspicious account activity, and rotate access tokens. The incident underscores the security challenges platforms face when hosting user-generated code and datasets, particularly as threat actors increasingly leverage AI agents for coordinated attacks.
- The breach highlights rising risks of AI-powered attacks and tensions between safety guardrails and legitimate cybersecurity defense capabilities


