A host platform for AI models and datasets confirmed it had experienced a data breach.

Steve Johnson via Unsplash
Hugging Face, a host platform for AI models and datasets, confirmed it had experienced a data breach. Furthermore, the organization asserted the breach had been carried out entirely by an AI agent.
“We identified unauthorized access to a limited set of internal datasets and to several credentials used by our services,” the platform stated in a post regarding the matter. “We are still completing our assessment of whether any partner or customer data was affected, and we will contact any affected parties directly as required. We have found no evidence of tampering with public, user-facing models, datasets, or Spaces, and our software supply chain (container images and published packages) was verified clean.”
According to the organization’s statement, the intrusion began with a malicious dataset exploiting two code-execution paths in the platform’s dataset processing so code could be run on a processing worker. The attack then rose to node-level access, enabling the attacker to harvest cluster and cloud credentials before shifting laterally into multiple internal clusters.
The statement asserts that the attack was carried out by an “autonomous agent framework,” enacting “many thousands of individual actions across a swarm of short-lived sandboxes, with self-migrating command-and-control staged on public services.”
“This matches the ‘agentic attacker’ scenario the industry has been forecasting,” the statement warns.
Rohit Valia, CEO of Tumeryk, comments, “Open source model repositories like Hugging Face now represent a meaningful supply chain risk. As adversaries increasingly target training and fine-tuning data rather than source code, organizations need to test open source models for behavioral drift, not just code-level vulnerabilities. An AI trust score gives enterprises a way to verify a model hasn’t been altered and is safe to use, while aligning to frameworks like the Cloud Security Alliances RiskRubric v2 which provide the structured testing methodology.”
Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!
Jordyn Alger is the managing editor for Security magazine. Alger writes for topics such as physical security and cyber security and publishes online news stories about leaders in the security industry. She is also responsible for multimedia content and social media posts. Alger graduated in 2021 with a BA in English – Specialization in Writing from the University of Michigan. Image courtesy of Alger
| # | Наименование новости | Тональность | Информативность | Дата публикации |
|---|---|---|---|---|
| 1 | OpenAI AI agent hacked Hugging Face, went undetected for days: Report | 0 | 5.17 | 26-07-2026 |
| 2 | Hugging Face experienced cyberattack carried out end-to-end by agentic AI | 0 | 5 | 20-07-2026 |
| 3 | В ходе тестирования автономный AI-агент OpenAI без явной указки взломал инфраструктуру Hugging Face | 0 | 10.16 | 22-07-2026 |
| 4 | Healthcare Software Provider Craneware Announces Data Breach | 0 | 4.9 | 21-07-2026 |
| 5 | ИИ-модель OpenAI атаковала систему сторонней компании | 0 | 18.33 | 22-07-2026 |
| 6 | 55M Impacted by Suno Data Breach | 0 | 8.62 | 22-07-2026 |
| 7 | Claims of 2.4M Impacted by VRChat Breach Revealed False | 0 | 5 | 11-06-2026 |
| 8 | Reuters: OpenAI была не в курсе, что её ИИ-агент вышел из-под контроля и провёл серию кибератак | 0 | 16.41 | 25-07-2026 |
| 9 | OpenAI agent goes rogue in ‘unprecedented cyber incident,’ hacks into rival AI startup during security test | 0 | 8.68 | 22-07-2026 |
| 10 | Šumperk se stal terčem kybernetického útoku. Chod úřadu je omezen, pátrá se po uniklých datech | 0 | 6.19 | 28-07-2026 |