Hugging Face was invaded by an AI agent, leaked internal data sets and documents

The artificial intelligence platform Hugging Face disclosed a production environment safety incident on 16 July 2026, and the attackers successfully breached the internal system by using malicious data sets to trigger two codes in the data-processing stream line. The attack was driven by the entire autonomous AI agent, which completed horizontal movement and document theft at machine speed, exposing some of the internal data sets and service vouchers but without affecting open models, data sets or Spaces. The incident originated from the malicious data set in the data-processing stream, which abused two code execution paths and enabled the attackers to obtain code execution privileges at the processing nodes. Subsequently, the attackers raised their authority to the nodal level and used stolen clouds and cluster vouchers to move horizontally during weekends. Hugging Face confirmed that the entire invasion was driven from the “autonomous AI agent system” which performed thousands of operations in short-term sandboxes, in line with industry's earlier prediction of the “agent attacker”. The coverage includes internal data sets and multiple service vouchers, but the impact on partner and client data is still under review. Hugging Face has closed the access code implementation path, rebuilt infected nodes, rotated affected keys and strengthened cluster control and alarm mechanisms. It is noteworthy that, as a result of the protective measures on the hosting model, which prevented forensic inquiries, the security team shifted to an internal open source weight model for analysis。

Search