Hugging Face has confirmed that a recent security incident affected internal datasets and service credentials on its platform. The company said it is still reviewing whether any customer or partner information was accessed during the breach.
According to the company, a dataset uploaded to the platform exploited a vulnerability that allowed malicious code to run on its servers. That chain of events reportedly gave the attacker broader access to internal systems.
Hugging Face said the exposed credentials have been revoked and rotated, and it is urging users to update any keys stored on the platform and check their accounts for unusual activity. The vulnerability used in the incident has also been fixed.
The company added that its own anomaly detection identified the attack, and that it used AI tools to analyze server logs during the investigation. It later shifted to a local large language model to avoid sending sensitive logs to an external provider.
Hugging Face has reported the case to law enforcement and brought in cybersecurity specialists to support the forensic review. The incident highlights how AI platforms are becoming central to both innovation and the need for stronger digital safeguards. In the future, this kind of response may help shape more resilient AI infrastructure across the industry.