Hugging Face is urging users to rotate any access tokens stored on the platform and review account activity.

Following the breach, the company secured its systems and contacted law enforcement. It also has some actions for registered users to take.

Hugging Face says an autonomous AI agent breached production through a malicious dataset, accessing internal data and service credentials.

This latest incident is a rather dramatic escalation in agentic AI cybersecurity breaches.

and what we should do about it