Hugging Face detected and responded to a security intrusion into part of its production infrastructure driven entirely by an autonomous AI agent system, the platform announced on July 16, 2026. The company stated that it used its own artificial intelligence tools to detect and analyze the attack.
Unauthorized access was identified across a limited set of internal datasets and several service credentials. Hugging Face found no evidence of tampering with public models, datasets, or Spaces, and confirmed its software supply chain was clean.
Attack mechanics
The attack began when a malicious dataset exploited two code-execution paths inside the data-processing pipeline to run code on a worker node. The system escalated to node-level access, harvested cloud credentials, and moved laterally into internal clusters over a weekend.
An autonomous agent framework executed thousands of actions across short-lived sandboxes with command-and-control staged on public services. Hugging Face reconstructed the timeline by running AI analysis agents over an attacker action log containing more than 17,000 recorded events.
Forensic response
Commercial API providers blocked initial analysis attempts because safety guardrails flagged the exploit payloads as malicious commands. Responders instead conducted the investigation using GLM-5.2, an open-weight model hosted on internal infrastructure.
Engineering teams closed the dataset vulnerability, rebuilt compromised nodes, and revoked affected credentials. Hugging Face engaged external forensic specialists, reported the intrusion to law enforcement, and recommended that users rotate access tokens. The company stated that it does not know which model powered the attacker's system.
