An artificial intelligence (AI) company, Hugging Face, has revealed that it recently suffered a cyberattack carried out not by a human but by an AI agent. Is AI attacked by AI?
Hackers have been adapting to AI to find security flaws in online infrastructure and exploit them; However, what happened with Hugging Face had never been experienced before.
The New York-based company said: “The cyberattack was powered, from start to finish, by an autonomous AI agent system.”
It seemed like an AI on AI attack, as the company defended itself by using its own large language model (LLM) to analyze the attack, find the loophole in its infrastructure, and defend itself.
What makes this stand out is not really the method, code injection via a malicious file is a familiar trick. It’s the fact that an AI agent ran the entire operation alone, deciding what to aim at and how to move, at a speed that no human hacker could match when typing commands.
The company still doesn’t know exactly what AI model was behind the attack, whether it was a jailbroken version of a commercial system or an open model with no built-in restrictions.
As for the damage, Hugging Face says a limited number of internal data sets and several service credentials were accessed without authorization.




