A recent cyberattack on AI platform Hugging Face has underscored a new era of cybersecurity threats, with the company revealing that the breach was likely carried out by an autonomous AI agent. According to Hugging Face, the attacker used an agentic security-research framework to execute thousands of coordinated actions at machine speed, demonstrating that AI-powered offensive cyberattacks have moved from theory to reality.
The attackers reportedly gained initial access through a malicious dataset uploaded to the platform before harvesting credentials and attempting to expand access across Hugging Face's infrastructure. The company quickly revoked compromised credentials, removed the attacker's foothold, and strengthened its security controls. The incident highlights that AI platforms themselves are becoming high-value targets with unique attack surfaces that require specialized protection.
Hugging Face also revealed that AI played a crucial role in defending against the attack. The company used large language model-powered agents to reconstruct the attack timeline and accelerate its incident response, completing in hours work that would traditionally take days. However, it found that some commercial AI models refused to assist because their safety guardrails blocked actions needed for defensive cybersecurity, forcing the company to rely on its own open-weight models instead.
The incident serves as a warning for organizations rapidly adopting AI technologies. Security experts say businesses should treat AI models, datasets, and training pipelines as critical attack surfaces, prepare AI-assisted incident response capabilities before an attack occurs, and recognize that autonomous AI-driven cyberattacks are becoming a practical threat rather than a future possibility.