Hugging Face Data Breach

dotmanish2 pts0 comments

Hugging Face confirms breach affected internal datasets and credentials, urges users to take action | TechCrunch

SearchSubmit

Site Search Toggle

Mega Menu Toggle

Topics

Latest

AI

Amazon

Apps

Biotech & Health

Climate

Cloud Computing

Commerce

Crypto

Enterprise

EVs

Fintech

Fundraising

Gadgets

Gaming

Google

Government & Policy

Hardware

Instagram

Layoffs

Media & Entertainment

Meta

Microsoft

Privacy

Robotics

Security

Social

Space

Startups

TikTok

Transportation

Venture

More from TechCrunch

Staff

Events

Startup Battlefield

StrictlyVC

Newsletters

Podcasts

Videos

Partner Content

TechCrunch Brand Studio

Crunchboard

Contact Us

Image Credits: Omer Taha Cetin/Anadolu / Getty Images

Security

Hugging Face confirms breach affected internal datasets and credentials, urges users to take action

Zack Whittaker

5:39 AM PDT · July 20, 2026

Hugging Face, a platform that hosts AI models and datasets, said its internal datasets and service credentials were compromised in a hack last week. The company disclosed the breach on Friday, but said it was still investigating whether any customer or partner data was stolen during the incident.

In a blog post, the company said a dataset uploaded to its platform abused a security vulnerability to run malicious code on its servers, allowing the attackers to escalate their permissions and gain broader access to Hugging Face’s internal systems.

The company said it has revoked and rotated the stolen credentials that were accessed. It urged users to do the same with any keys stored on the platform, and review any suspicious activity on their accounts.

Hugging Face said it has fixed the vulnerability that was abused during the cyberattack. While it’s common for hackers to try to break into a company’s network using stolen employee credentials, keys, or a weak point in their security perimeter, this incident underscores the challenges that companies like Hugging Face face when hackers try to abuse platforms and tools to access and steal sensitive data from within.

Hugging Face blamed the breach on an external AI agent, which executed "many thousands of individual actions across a swarm of short-lived sandboxes, with self-migrating command-and-control staged on public services."

The company did not immediately provide evidence for this claim when asked by TechCrunch.

Hugging Face said its own anomaly detection spotted the attack, and used an AI model to analyze server logs that kept record of the cyberattack.

The company said it initially used a frontier AI model from a commercial provider, though it didn’t name a company, but found that the analysis effort was blocked by the provider’s guardrails. Instead, the company used its own local large language model, which it said provided the added benefit of not having to upload sensitive attack logs to an AI company’s servers.

Security researchers have previously complained that some frontier models, like Anthropic’s Mythos and Fable, are heavily constrained, and prevent defenders from inquiring about almost anything relating to cybersecurity, including for defense and investigations.

Frontier AI model makers, including Anthropic, have butted heads with the Trump administration over fears and concerns about the ability to use these models for offensive cyberattacks. Anthropic was even forced to withdraw Fable from public use after the U.S. government enforced export controls on the model.

Hugging Face said it has reported the incident to law enforcement and roped in cybersecurity forensic specialists to investigate the breach and review its security.

It’s not clear if Hugging Face had performed a security audit of its systems before it launched. A Hugging Face spokesperson did not respond to a request for comment on Monday.

Topics

cyberattack, cybersecurity, data breach, Hugging Face, Security

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

Zack Whittaker

Security Editor

Zack Whittaker is the security editor at TechCrunch. He also authors the weekly cybersecurity newsletter, this week in security.

He can be reached via encrypted message at zackwhittaker.1337 on Signal. You can also contact him by email, or to verify outreach, at zack.whittaker@techcrunch.com.

View Bio

November 4

Boston

Last chance to save up to $190 on TechCrunch Founder Summit. Join 1,000+ founders and VCs at all stages for real-world scaling insights and connections that move the needle.

Savings end June 26, 11:59 p.m. PT .

REGISTER NOW

Most Popular

Coca-Cola suspended production at its Fairlife dairy after a ransomware attack

Zack Whittaker

Tesla driver in fatal Texas crash pressed accelerator 100%, NTSB confirms

Sean O'Kane

Amid hardware legal battle, OpenAI releases a $230 keyboard for Codex

Lucas Ropek

Anthropic, Blackstone bet the next trillion-dollar AI business is implementation, not just models

Rebecca...

face hugging security said company breach

Related Articles