Hugging Face, a platform that hosts AI models and datasets, announced that its internal datasets and service credentials were compromised in a hack last week. The company disclosed the breach on Friday, but said it was still investigating whether any customer or partner data was stolen during the incident.
The company said in a blog post that datasets uploaded to the platform exploited security vulnerabilities to execute malicious code on the server, which allowed the attacker to escalate privileges and gain broad access to Hugging Face's internal systems.
The company said it has revoked and rotated the stolen credentials that were accessed. It urged users to do the same with keys stored on the platform and check for suspicious activity on their accounts.
Hugging Face said it has fixed the vulnerability exploited during the cyber attack. While it is common for hackers to attempt to break into a company's network using stolen employee credentials, keys, or weaknesses in the security perimeter, this incident highlights the challenges companies like Hugging Face face when hackers attempt to exploit their platforms and tools to access and steal sensitive internal data.
Hugging Face blamed the breach on an external AI agent, which it claimed carried out “thousands of individual actions across a fleet of short-lived sandboxes with self-transitioning command and control set in a public service.”
The company did not immediately provide proof of this claim in response to TechCrunch's questions.
Hugging Face said it discovered the attack through proprietary anomaly detection and used AI models to analyze server logs that store records of cyberattacks.
The company initially used a commercial provider's Frontier AI model, but the company, which declined to name the company, said it found its analysis efforts were being hampered by the provider's guardrails. Instead, the company said it used its own local large-scale language model, offering the added benefit of not having to upload sensitive attack logs to the AI company's servers.
Security researchers have previously complained that some frontier models, like Anthropic's Mythos and Fable, have significant limitations that prevent defenders from interrogating almost everything related to cybersecurity, including defense and investigation.
Frontier AI model makers such as Anthropic are at odds with the Trump administration over concerns and fears that these models could be used in offensive cyberattacks. Anthropic was even forced to withdraw the Fabre from public use after the US government tightened export controls on the model.
Hugging Face said it reported the incident to law enforcement and brought in cybersecurity forensic experts to investigate the breach and review its security.
It's unclear whether Hugging Face conducted a security audit of its systems before launching. A spokesperson for Hugging Face did not respond to a request for comment Monday.
If you buy through links in our articles, we may earn a small commission. This does not affect editorial independence.

