HuggingFace confirms unauthorized access to its systems: it was powered by an AI agent “from start to finish”

HuggingFace has confirmed a unauthorized access to your systems powered “from start to finish” by an artificial intelligence (AI) agent that has affected an internal data set.

The platform specialized in machine learning detected an intrusion early last week that was initiated from a set of malicious data that it obtained install and run code on a compute node.

As they explain in a statement shared on their blog, the particular thing about this security incident is that “was powered, from start to finish, by an autonomous AI agent system,” of which the base model is not known at the moment.

That agent, once inside the node, managed escalate privileges, harvest cloud credentials, and spread laterally by several internal clusters. This allowed some internal HuggingFace data and credentials to be stolen, but

It was their AI systems that detected the intrusion. They also used LLM-based agents to analyze the attacker’s entire log, with more than 17,000 events.

“This allowed us to reconstruct the timeline, extract indicators of compromise, map the affected credentials, and differentiate the real impact from decoy activity. Thanks to this approach, we achieved in hours what would normally take days, matching the speed of the adversary,” they indicated.

For HuggingFace, this attack is a sign that “AI-based autonomous offensive tools are no longer a theory.” Therefore, they point out that “defending an online platform now involves treating the data and model surface as a first-order attack surface, and using AI in defense to keep up.”

By Editor

One thought on “HuggingFace confirms unauthorized access to its systems: it was powered by an AI agent “from start to finish””

Leave a Reply