Hugging Face disclosed a security breach conducted entirely by autonomous AI agents that exploited the platform's infrastructure for several days, marking what the company says is the first attack of its kind to be fully executed by self-operating systems without direct human intervention.
The attack began when malicious code embedded in a dataset activated within Hugging Face's infrastructure, after which autonomous AI agents independently escalated privileges, extracted cloud credentials, and moved laterally across internal clusters. The operation spanned multiple days and involved thousands of automated actions, with the attackers gaining access to internal datasets and service credentials. Hugging Face did not determine which specific model the threat actors used to conduct the breach.
The incident underscores emerging cybersecurity risks as AI systems become more autonomous and capable of self-directed operations. In a twist of irony, another AI agent detected the attack itself, highlighting both the vulnerabilities and defensive potential of autonomous systems in enterprise security. Hugging Face has characterized the breach as a watershed moment in cybersecurity, demonstrating that fully autonomous attacks by multiple coordinated AI agents are now operationally feasible.