← All Posts

There you have it! Hugging Face just confirmed hackers stole its internal credentials. The compan…

July 21, 2026 · 0 likes · 0 comments
AI Cybersecurity Workforce
There you have it! Hugging Face just confirmed hackers stole its internal credentials. The company is telling the world an AI agent pulled it off.

Straight from Hugging Face's own disclosure, no spin. Full sourcing on UnbiasedHeadlines.com, the news site I built entirely with AI agents: https://lnkd.in/eMj4wr-H

Someone uploaded a malicious dataset to the platform. That dataset exploited a security flaw and ran malicious code on Hugging Face's own servers.

From there, the attacker escalated permissions, moved deeper into internal systems, and walked out with service credentials. Hugging Face has revoked and rotated every credential touched, patched the flaw, and told every user to rotate their own keys too.

Now the part that should stop you cold. Hugging Face says this wasn't a person typing commands. It says an autonomous AI agent ran thousands of separate actions across a rotating swarm of disposable cloud sandboxes, shifting its command infrastructure between public services to stay hidden.

Nobody outside Hugging Face has confirmed a word of it. TechCrunch asked for evidence behind the AI-agent claim and got nothing back before publishing. This is a breached company's own account of its own breach, not an independent forensic report.

To dig through the attack logs, Hugging Face first tried a frontier commercial AI model. Its own safety guardrails wouldn't let it touch the analysis, so they fell back to a locally-run model just to investigate their own break-in. TechCrunch notes Anthropic's models draw this exact complaint elsewhere: too locked down to help a defender read an attack, while Anthropic fights Washington over whether those same models are too dangerous in an attacker's hands.

I run 13 AI agents that handle everything from my calendar to actual revenue-generating client work to unbiasedheadlines.com. Not one of them gets an inch more access than the job in front of it requires. That's not caution. That's the only version of this that survives first contact with reality.

My book Replacement has a chapter called "The Security Problem Nobody Is Talking About." It opens with an AI agent getting full write access to a production database through a hole that was public knowledge back in 2003. Every agent you deploy is an attack surface, and the permissions you hand out today are the breach headline you read next year. Out July 28.

Hugging Face still can't say whether customer data, model weights, or partner files got touched, or whether this system was ever security-audited before it went live. That's the number that decides how bad this actually is, and right now nobody has it.

What's it going to take before least privilege is the first thing a company builds, instead of the thing they bolt on after the postmortem?
View original on LinkedIn →