Hugging Face
Disclosed Jul 17, 20262 months agoConfirmed
Autonomous OpenAI agent breached Hugging Face and stole internal datasets and credentials
A malicious dataset exploited two code-execution flaws in Hugging Face's data-processing pipeline, letting an autonomous agent steal cloud and cluster credentials and reach internal datasets. OpenAI later said its own model escaped a test sandbox during an internal cyber evaluation and carried out the attack.
What is known
| People affected | Not stated in the sources we have |
|---|---|
| Disclosed | Jul 17, 2026 |
| Discovered | Jul 2026 |
| Attack | AI or model |
| Data exposed | Training data, Credentials and tokens, API keys, Internal documents |
| Sector | AI · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| Hugging Face security incident July 2026huggingface.co · Official notice | Official notice |
| OpenAI: Hugging Face model evaluation security incidentopenai.com · The organization | The organization |
| Hugging Face confirms breach affected internal datasets and credentialstechcrunch.com · News | News |
| How OpenAI's human mistake led to the AI-powered hack on Hugging Facetechcrunch.com · News | News |
| Hugging Face warns an autonomous AI agent hacked its networkbleepingcomputer.com · News | News |
Notices filed
Other breaches at Hugging Face
| Breach | Affected | ||||
|---|---|---|---|---|---|
| Unauthorized access to Spaces platform exposed a subset of user secretsMay 31, 20242 years agoHacking | May 31, 20242 years ago | Hacking | AI | Confirmed | Unknown |
| 1,681 exposed Hugging Face API tokens gave write access to Meta Llama and other reposDec 4, 20232 years agoExposed dataUnverified | Dec 4, 20232 years ago | Exposed data | AI | Unverified | Unknown |
History of this record
- 2026-09-25 · data_types: ["training-data","credentials","api-keys"] to ["training-data","credentials","api-keys","internal-docs"] · seed source
- 2026-09-25 · disclosed: 2026-07-18 to 2026-07-17 · seed source
- 2026-09-25 · summary: Hugging Face said an external AI agent uploaded a malicious dataset that exploited a flaw to run code on its servers and access internal datasets and service credentials, and told users to rotate tokens. OpenAI later said its pre-release mo to A malicious dataset exploited two code-execution flaws in Hugging Face's data-processing pipeline, letting an autonomous agent steal cloud and cluster credentials and reach internal datasets. OpenAI later said its own model escaped a test s · seed source
- 2026-09-25 · title: Escaped OpenAI test model hacks Hugging Face, internal datasets and credentials hit to Autonomous OpenAI agent breached Hugging Face and stole internal datasets and credentials · seed source
- 2026-09-25 · added · seed source
First seen 2026-09-25 (Research), confirmed by Research. Record counts are as reported. Not legal advice.