Security incident disclosure — July 2026
TL;DR AI
2 min readKey summary
Hugging Face disclosed an intrusion into part of its production infrastructure detected earlier in July 2026.
Attackers used a malicious dataset to trigger code execution, steal cloud and cluster credentials, and move laterally with an autonomous agent framework.
The company says public models, datasets, Spaces, and its software supply chain were not compromised.
Hugging Face has closed the initial flaw, rebuilt affected nodes, rotated credentials, strengthened defenses, and engaged forensic experts and law enforcement.



