Hugging Face Latest Company Dealing With AI Cyberattacks | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware


Hugging Face, whose platform hosts AI datasets, has reportedly suffered an AI-powered data breach.

As TechCrunch reported Monday (July 20), the company revealed the breach last week but said it was still determining if any customer or partner data had been stolen.

On its blog, Hugging Face said a dataset uploaded to its platform exploited a security vulnerability to run malicious code on its servers, letting hackers escalate their permissions and obtain broader access to the company’s internal systems.

“The campaign was run by an autonomous agent framework (appearing to be built on an agentic security-research harness – used LLM still not known) executing many thousands of individual actions across a swarm of short-lived sandboxes, with self-migrating command-and-control staged on public services,” the blog post said. “This matches the ‘agentic attacker’ scenario the industry has been forecasting.”

Hugging Face says it has revoked and rotated the stolen credentials that were accessed and implored users to do the same with their access tokens and to review suspicious activity on their accounts.

The TechCrunch report noted that although it’s not unusual for hackers to try to access a company’s network with things like stolen credentials or security weaknesses, this incident highlights the challenges companies like Hugging Face encounter when cybercriminals try to abuse platforms and tools to swipe sensitive data from within.

With this breach, Hugging Face joins a host of other companies who have reported or been affected by cyber incidents this year, amid a surge in artificial intelligence (AI)-related attacks, as PYMNTS wrote last week.

At the time, Fairlife, a dairy company owned by The Coca-Cola Co., had reported a ransomware event that impacted its systems.

“After detecting the issue, the company promptly activated its incident response and business continuity protocols,” Coca-Cola said in a news release. “The company’s investigation and assessment of the impact of the incident is ongoing, with the assistance of outside advisers and cybersecurity experts. The company has also notified law enforcement.”

The FBI’s Internet Crime Complaint Center (IC3) said in April that it received 22,364 internet crime complaints containing references to AI last year, leading to losses of $893 million.

“AI-enabled synthetic content is becoming increasingly difficult to detect and easier to make, which allows criminal actors to potentially conduct successful fraud schemes against individuals, businesses and financial institutions,” the FBI said in its 2025 Internet Crime Report.

Meanwhile, the PYMNTS Intelligence report “Is That Content Generated by AI or Humans? Hard to Tell” found that AI-created content can deceive both humans and AI systems, leaving businesses and regulators scrambling to address the growing threat.

——————————————————-


Click Here For The Original Source.

National Cyber Security

FREE
VIEW