Hugging Face confirms breach affected internal datasets and credentials, urges users to take action
Hugging Face, the AI model and dataset hosting platform, has confirmed that a hack last week compromised its internal datasets and service credentials, and is still investigating whether customer or partner data was also stolen. The breach matters because it shows how attackers can exploit trusted platform features, in this case a malicious dataset upload, to escalate access deep into a company's internal systems, and it has prompted Hugging Face to urge all users to rotate their own keys and check for suspicious account activity.
According to a blog post from the company, published after the breach was disclosed on Friday, the attackers used a security vulnerability in an uploaded dataset to run malicious code on Hugging Face's servers before escalating their privileges. The company said it has since revoked and rotated the compromised credentials and patched the flaw involved. It attributed the intrusion to an external AI agent capable of thousands of automated actions across short-lived sandboxes, though it offered no evidence for this claim, and said its own anomaly detection and a locally run AI model, rather than a guardrail-restricted commercial one, were used to analyse the attack logs. Hugging Face has reported the incident to law enforcement and brought in outside forensic specialists, though it did not confirm whether it had audited its security prior to the breach, and a spokesperson did not respond to requests for comment.
- Hugging Face confirms hackers stole internal datasets and credentials
- Malicious dataset upload exploited a flaw to escalate server access
- Company urges users to rotate keys and check account activity