Hugging Face disclosed that in July 2026 their production infrastructure was compromised by an autonomous AI-driven attacker exploiting code-execution vulnerabilities in their dataset processing pipeline, leading to unauthorized access to internal datasets and credentials. They contained the intrusion by closing the vulnerabilities, rotating credentials, rebuilding affected nodes, enhancing cluster controls, and used their own open-weight AI models for rapid forensic analysis, highlighting the emerging challenge of AI-powered attacks and the need for AI-assisted defense capabilities. The investigation continues with external cybersecurity experts, and affected users are advised to rotate tokens and monitor accounts.
Hugging Face

