‘This one was different from anything we’d dealt with before’: Hugging Face confirms it was hit by cyber attack powered by an AI agent


  • Hugging Face reveals a cyberattack in which malicious code stored in a dataset exploited flaws in its systems, enabling privilege escalation and credential theft
  • The incident was unique in being orchestrated end-to-end by an autonomous AI agent, which launched thousands of short-lived sandboxes and migrated C2 infrastructure across public services
  • No customer data or public models were tampered with, but the attack highlights the new “agentic attacker” scenario that the industry has long predicted

Hugging Face, one of the largest artificial intelligence (AI) and machine learning (ML) platforms, recently revealed that it was the victim of a cyber attack carried out by an AI agent.

“This one was different from anything we’d handled before in one important way: it was run end-to-end by an autonomous AI agent system — and we discovered and dissected it largely with our own AI,” Hugging Face explained in its announcement, noting that the attackers hid malicious code inside a dataset that they then uploaded to the platform.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top