Hugging Face says AI agent behind internal breach
Add Axios as your preferred source to
see more of our stories on Google.

Photo: Riccardo Milani / Hans Lucas / AFP via Getty Images
Hugging Face, a platform that hosts AI models and datasets, says an AI agent framework was behind a recent breach of some of its internal databases and service credentials.
Why it matters: The breach appears to be one of the first documented cases of an AI agent driving a cyberattack — marking a shift from AI-assisted hacking to AI-led operations.
Driving the news: Hugging Face said in a blog post late last week that it caught an intrusion in part of its production environment that was "driven, end to end, by an autonomous AI agent system."
- Hugging Face said the AI agent framework executed tens of thousands of automated actions.
- Over the course of a weekend, the attacker's agents uploaded a malicious data set, exploited vulnerabilities in Hugging Face's data-processing pipeline, escalated its privileges and stole cloud and other sensitive internal credentials.
Threat level: The company said it hasn't seen evidence of the attacker tampering with public, user-facing models, datasets, its cloud-hosted platform Spaces and its broader software supply chain.
The big picture: Previous attacks used AI to generate code, write phishing emails or automate individual tasks.
- Hugging Face says this attack used an autonomous agent system to execute the intrusion from start to finish.
The intrigue: Hugging Face says AI helped detect the intrusion and later reconstruct how it happened.
- When it first started analyzing the attack, Hugging Face turned to frontier models, but their safety guardrails blocked tasks tied to malware analysis and incident-response analysis.
- Then, Hugging Face turned to GLM-5.2, a recently released Chinese open-weight model, and ran it on its own infrastructure to analyze the malware locally without safety restrictions.
- "The practical lesson for defenders: have a capable model you can run on your own infrastructure vetted and ready before an incident, both to avoid guardrail lockout and to keep attacker data and credentials from leaving your environment," Hugging Face wrote in its blog post.
Yes, but: The Trump administration is weighing a ban on open-source models, sources tell Axios.
Between the lines: The incident offers an early glimpse of the future many cybersecurity experts have been anticipating: One where defenders use their own AI tools to quickly detect and stop adversaries' AI tools.
- But it will take time for defenders to find and build the right AI tools to fend off all of the attacks coming their way — especially as both nation-state hackers and cybercriminals start to develop their own multi-modal AI harnesses.
What to watch: HuggingFace is investigating whether the intruders accessed customer or partner datasets.
- The company also has not publicly attributed the attack or what kind of model was used.
Go deeper: AI-powered cybercrime is getting easier
