Hugging Face, a platform that hosts AI models and datasets, mentioned its inside datasets and repair credentials had been compromised in a hack final week. The corporate disclosed the breach on Friday, however mentioned it was nonetheless investigating whether or not any buyer or associate knowledge was stolen throughout the incident.
In a blog post, the corporate mentioned a dataset uploaded to its platform abused a safety vulnerability to run malicious code on its servers, permitting the attackers to escalate their permissions and acquire broader entry to Hugging Face’s inside methods.
The corporate mentioned it has revoked and rotated the stolen credentials that had been accessed. It urged customers to do the identical with any keys saved on the platform, and evaluate any suspicious exercise on their accounts.
Hugging Face mentioned it has fastened the vulnerability that was abused throughout the cyberattack. Whereas it’s widespread for hackers to attempt to break into an organization’s community utilizing stolen worker credentials, keys, or a weak level of their safety perimeter, this incident underscores the challenges that firms like Hugging Face face when hackers attempt to abuse platforms and instruments to entry and steal delicate knowledge from inside.
Hugging Face blamed the breach on an exterior AI agent, which executed “many 1000’s of particular person actions throughout a swarm of short-lived sandboxes, with self-migrating command-and-control staged on public providers.”
The corporate didn’t instantly present proof for this declare when requested by TechCrunch.
Hugging Face mentioned its personal anomaly detection noticed the assault, and used an AI mannequin to investigate server logs that saved file of the cyberattack.
The corporate mentioned it initially used a frontier AI mannequin from a industrial supplier, although it didn’t title an organization, however discovered that the evaluation effort was blocked by the supplier’s guardrails. As an alternative, the corporate used its personal native massive language mannequin, which it mentioned offered the additional advantage of not having to add delicate assault logs to an AI firm’s servers.
Safety researchers have beforehand complained that some frontier fashions, like Anthropic’s Mythos and Fable, are closely constrained, and stop defenders from inquiring about nearly something regarding cybersecurity, together with for defense and investigations.
Frontier AI mannequin makers, together with Anthropic, have butted heads with the Trump administration over fears and issues concerning the potential to make use of these fashions for offensive cyberattacks. Anthropic was even forced to withdraw Fable from public use after the U.S. authorities enforced export controls on the mannequin.
Hugging Face mentioned it has reported the incident to regulation enforcement and roped in cybersecurity forensic specialists to analyze the breach and evaluate its safety.
It’s not clear if Hugging Face had carried out a safety audit of its methods earlier than it launched. A Hugging Face spokesperson didn’t reply to a request for touch upon Monday.
While you buy by means of hyperlinks in our articles, we may earn a small commission. This doesn’t have an effect on our editorial independence.

