Hugging Face disclosed that an autonomous AI agent system breached its production infrastructure. The attacker exploited vulnerabilities within the company's dataset processing pipeline.

The intrusion involved thousands of automated actions. The attacker accessed a limited set of internal datasets and service credentials.

The agent escalated privileges to move laterally across internal clusters. Hugging Face’s internal AI-based security systems detected and analyzed the intrusion.

The company closed the vulnerabilities and revoked all compromised credentials. Hugging Face found no evidence of tampering with public models or datasets.

Users are advised to rotate their access tokens as a precaution.