“This one was unlike anything we’ve dealt with before”: Hugging Face confirms it was hit by AI agent-powered cyberattack


  • Hugging Face reveals a cyberattack in which malicious code hidden in a dataset exploited flaws in its systems, enabling privilege escalation and credential theft.
  • The incident was unique in that it was orchestrated end-to-end by an autonomous AI agent, which launched thousands of short-lived sandboxes and migrated C2 infrastructure across utilities.
  • No customer data or public models were tampered with, but the attack highlights the emerging scenario of an “agent attacker” long predicted by the industry.

Hugging Face, one of the largest artificial intelligence (AI) and machine learning (ML) platforms, recently revealed that it suffered a supercharged cyberattack by an AI agent.

“This was different from anything we had dealt with before in one important way: It was driven, end to end, by an autonomous AI agent system – and we detected and dissected it largely with our own AI,” Hugging Face explained in its announcement, noting that the attackers hid malicious code in a dataset, which they then uploaded to the platform.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top