Hug Face AI Latest companies to combat cyberattacks

AI For Business


Hugging Face, which provides a platform for hosting AI datasets, has reportedly suffered an AI-powered data breach.

As TechCrunch reported on Monday (July 20), the company disclosed the breach last week, but said it was still confirming whether any customer or partner data was stolen.

Hugging Face said in a blog post that datasets uploaded to its platform exploited security vulnerabilities to execute malicious code on its servers, allowing hackers to escalate privileges and gain broad access to internal systems.

“This campaign was executed by an autonomous agent framework (which appears to be built on an agent security research harness, and the LLM used is still unknown), performing thousands of individual actions across a fleet of short-lived sandboxes, and self-migrating command and control over public services,” the blog post states. “This is consistent with the ‘agent attacker’ scenario that the industry has been predicting.”

Hugging Face said it has revoked and rotated stolen credentials that were accessed and asked users to do the same with their access tokens and check for suspicious activity on their accounts.

The TechCrunch report said it’s not uncommon for hackers to use stolen credentials or security weaknesses to gain access to a company’s network, but this incident highlights the challenges companies like Hugging Face face when cybercriminals exploit platforms and tools to steal sensitive data from within.

As PYMNTS wrote last week, the breach puts Hugging Face among the many other companies that have reported or been affected by cyber incidents this year amid a surge in artificial intelligence (AI)-related attacks.

At the time, Fairlife, a dairy company owned by Coca-Cola, reported a ransomware event that affected its systems.

“After discovering the issue, Coca-Cola immediately activated its incident response and business continuity protocols,” Coca-Cola said in a news release. “The company is working with external advisors and cybersecurity experts to investigate and assess the impact of the incident. The company has also notified law enforcement.”

The FBI’s Internet Crime Complaint Center (IC3) announced in April that it had received 22,364 Internet crime complaints last year that included references to AI, resulting in $893 million in losses.

“AI-powered synthetic content is becoming increasingly difficult to detect and easier to create, allowing criminals to successfully carry out fraudulent schemes against individuals, businesses, and financial institutions,” the FBI said in its 2025 Internet Crime Report.

Meanwhile, a PYMNTS Intelligence report, “Is That Content Generated by AI or Humans? Hard to Tell,” found that AI-generated content can deceive both humans and AI systems, leaving businesses and regulators scrambling to respond to the growing threat.



Source link