The Wire
BusinessTechnologyArtificial IntelligenceCybersecurity

Hugging Face says breach exposed internal data, service credentials

Hugging Face disclosed a July intrusion that exposed internal data and service credentials.

Why it matters: Hugging Face is a core platform for AI builders, so exposed service credentials can create access risk for enterprise teams using its tools. The company’s token-rotation warning signals customers should check connected systems and recent activity now.

  • Hugging Face disclosed the incident on July 16, 2026, saying it detected unauthorized access earlier that week.
  • The company said the intrusion affected a limited set of internal datasets and several service credentials, but not public models, datasets or Spaces.
  • Hugging Face said it revoked and rotated affected credentials, closed the vulnerable code-execution paths and rebuilt compromised nodes.
  • The company urged users to rotate access tokens and review recent account activity.

Hugging Face said it found unauthorized access to a limited set of internal datasets and several credentials used by its services after detecting an intrusion into part of its production infrastructure earlier that week. In its public disclosure, the company said it saw no evidence that public, user-facing models, datasets or Spaces were tampered with.

The company said the attack began in its data-processing pipeline, where a malicious dataset took advantage of code-execution paths used when processing datasets. In simpler terms, that means the attacker appears to have used data meant for ingestion to trigger code in the system that handled it.

Hugging Face said it identified a remote-code dataset loader and a template-injection issue in a dataset configuration as part of the attack path. It also said the attacker gained access to internal systems and moved through several internal clusters over the course of the incident.

The company said it logged more than 17,000 attacker events and observed many thousands of automated actions across short-lived sandboxes. Sandboxes are isolated test environments used to run code safely before it reaches production systems.

Hugging Face said it revoked and rotated affected credentials and tokens, closed the vulnerable code-execution paths, rebuilt compromised nodes and began broader precautionary secret rotation. It also said it reported the incident to law enforcement and brought in outside cybersecurity forensic specialists.

The company told users to rotate access tokens and review recent account activity. BleepingComputer echoed that guidance and said the breach involved internal datasets and credentials tied to Hugging Face's systems. TechCrunch reported the company was still investigating whether any customer or partner data was stolen.

Hugging Face also said its software supply chain, including container images and published packages, was verified clean.

By the numbers

  • 17,000+ - attacker events logged by Hugging Face during the incident
  • Thousands - automated actions observed across short-lived sandboxes
  • Earlier that week - when Hugging Face said it detected the intrusion before its July 16 disclosure

Yes, but: Hugging Face said it saw no evidence that public models, datasets or Spaces were tampered with, but the company is still investigating the full scope of the intrusion.

What's next: Hugging Face said it has broadened secret rotation and is working with outside forensic specialists and law enforcement.

Based on reporting from

  • BBC News
  • TechCrunch

See how this story touches your network - open The Wire in Jane.

Open in Jane