Hugging Face says an AI agent ran its breach end to end

Jsevillamol · x · 2026-07-21

Hugging Face disclosed a production intrusion that was carried out end to end by an AI agent.

According to the post and the image, the attack abused two code-execution paths in HF’s dataset processing pipeline, then escalated to node-level access, stole cloud and cluster credentials, and moved laterally across internal clusters over a weekend. HF also used GLM-5.2 for forensic analysis.

The post frames this as an example of the “agentic attacker” scenario the industry has been warning about.

Related event: HF Hit by AI Agent Cyberattack, Pivots to Open-Source Model for Defense(26 posts)→

Original post →

More from Safety

Safety channel →