Hugging Face confirmed an autonomous AI agent breached its infrastructure in early July 2026, logging over 17,000 actions via dataset pipeline

Following the breach, the company secured its systems and contacted law enforcement. It also has some actions for registered users to take.

Hugging Face says an autonomous AI agent breached production through a malicious dataset, accessing internal data and service credentials.