Search Everything in One Place

Explore the web, images, videos, news, and more – all in one place.

Finance

The Hugging Face breach is a warning for every company betting big on AI

The Hugging Face Breach Is a Warning for Every Company Betting Big on AI

Illustration: Adobe Stock

Experts have long warned that hackers could use AI agents to autonomously run campaigns. Now it appears to have happened.

Experts have long warned that hackers could use AI agents to autonomously run campaigns. Now it appears to have happened.

Hugging Face has been hacked—and the perpetrator was an AI agent.

A GitHub-like platform and community for open-source AI models and data, Hugging Face published a blog post on Friday disclosing the breach. Perhaps the most shocking part was Hugging Face’s disclosure that the hack was likely carried out by an autonomous agent framework.

“The campaign was run by an autonomous agent framework (appearing to be built on an agentic security-research harness—used LLM still not known) executing many thousands of individual actions,” the blog reads. “This matches the ‘agentic attacker’ scenario the industry has been forecasting.”

As AI has grown more sophisticated, experts have begun warning that it will make sophisticated cyberattacks cheaper and easier to pull off. Agentic AI in particular is expected to enable cybercriminals to enlist agents to do their dirty work at machine speed. This prediction has already proven true, and the attack on Hugging Face is just one more example.

Hugging Face wrote that the hacker gained a foothold into the system through a malicious dataset, and then began harvesting credentials to other parts of the system. Hugging Face moved to close the paths used to infiltrate the system and eliminated the attacker’s foothold in other parts of the system before revoking credentials and tokens. It then tightened up security. 

Importantly, Hugging Face stated that the attack was actually identified with the help of AI, and LLM-powered AI agents helped to reconstruct the timeline of the attack so the company could respond more quickly. 

“Thanks to this approach, we were able to do in hours what would usually take days, and match the adversary’s speed,” the blog states.

It wasn’t all smooth sailing. Hugging Face first turned to frontier models behind commercial APIs, but ran into roadblocks because certain actions were “blocked by the providers’ safety guardrails, which cannot distinguish an incident responder from an attacker,” according to the blog. It ultimately used its own model on its own infrastructure. 

But a different company without the same tools as Hugging Face may not have been able to do the same. The company advises cybersecurity defenders to have their own model, “vetted and ready before an incident” to avoid some of the stumbling blocks it encountered. And although Hugging Face informed the LLM providers of its experience, the company emphasized in the blog that it’s not arguing against guardrails.

“Autonomous, AI-driven offensive tooling is no longer theoretical. It lowers the cost of running a broad, patient, multi-stage campaign, and it operates at machine speed,” the blog states. “Defending an online platform now means treating the data and model surface as a first-class attack surface, and using AI on defense to keep pace.”

This post originally appeared at inc.com.

“Click here to subscribe to the Inc. newsletter: inc.com/newsletters"

Read full story on Inc.

Related News

More stories you might be interested in.

Top