‘This was unlike anything we had handled before’: Hugging Face confirms it was hit by a cyberattack powered by an AI agent



  • Hugging Face reveals a cyberattack in which malicious code hidden in a data set exploited flaws in its systems, allowing privilege escalation and credential theft.
  • The incident was unique because it was orchestrated end-to-end by an autonomous AI agent, which launched thousands of short-lived sandboxes and migrated C2 infrastructure between utilities.
  • No customer data or public models were altered, but the attack highlights the emerging “agent attacker” scenario long predicted by the industry.

Hugging Face, one of the largest artificial intelligence (AI) and machine learning (ML) platforms, revealed that it recently suffered a supercharged cyberattack by an AI agent.

“This was different from anything we’d handled before in one important way: It was powered, end-to-end, by an autonomous AI agent system, and we largely detected and dissected it with our own AI,” Hugging Face explained in its announcement, noting that the attackers hid malicious code within a data set, which they then uploaded to the platform.

Leave a Comment

Your email address will not be published. Required fields are marked *