Hugging Face reported an intrusion into part of its production infrastructure.

Analytics2026-07-20, 12:02
Hugging Face reported an intrusion into part of its production infrastructure. According to the company, the defining feature of the incident was that the attack was driven end to end by an autonomous AI agent system.
The initial entry point was a malicious dataset that exploited two code-execution paths: a remote-code dataset loader and a template-injection in a dataset configuration. After gaining code execution on a processing worker, the attacker escalated to node-level access, harvested cloud and cluster credentials, and moved laterally across several internal clusters. Hugging Face recorded more than 17,000 events associated with the intrusion.
After detecting the intrusion, Hugging Face closed the code-execution paths used for initial access, removed the attacker's foothold, rebuilt compromised nodes, and revoked and rotated affected credentials and tokens. The company also deployed additional guardrails, strengthened cluster admission controls, and improved its detection and alerting mechanisms.
Vendors
Hugging Face