The company says the attack was carried out end to end by an autonomous AI-agent system.

Following the breach, the company secured its systems and contacted law enforcement. It also has some actions for registered users to take.

Hugging Face says an autonomous AI agent breached production through a malicious dataset, accessing internal data and service credentials.