Hugging Face disclosed that last week's cyberattack resulted in the compromise of internal data sets and service credentials. The attack began when a dataset uploaded to the platform executed malicious code through a security vulnerability, allowing attackers to escalate privileges and gain broader access to the company's internal systems.
The company revoked and replaced the compromised credentials and urged users to review and, if necessary, change all keys stored on the platform. Additionally, the security vulnerability exploited in the attack has been patched. Hugging Face analyzed the attack using its own local large language model, enabling analysis without having to upload sensitive server logs to a third-party AI provider.
The company claimed the attack was carried out by an external AI agent, but provided no evidence to support this assertion. The incident has also brought to light challenges faced by security experts regarding some leading AI models restricting cybersecurity research. Hugging Face reported the incident to authorities and invited cybersecurity experts to investigate the breach.
