The attack is one of the first public cases of an AI agent conducting an operation from beginning to end.

Following the breach, the company secured its systems and contacted law enforcement. It also has some actions for registered users to take.

Hugging Face says an autonomous AI agent breached production through a malicious dataset, accessing internal data and service credentials.