Hugging Face Confirms AI-Driven Cyber Attack, Investigation Underway
On 16 July, Hugging Face, a platform that hosts artificial intelligence models and tools, disclosed that it had been the target of a sophisticated cyber attack. The company stated that the breach was carried out using an AI system capable of autonomous actions, marking a new challenge for cybersecurity.
According to Hugging Face's announcement, the attackers used an AI agent that executed approximately 17,000 actions over a period of less than two days. The company described the method as involving a 'swarm of sandboxes' and 'self-migrating command and control', indicating a high level of automation and speed that exceeded typical human-driven attacks.
The breach resulted in the theft of proprietary data, though the company has not specified the exact nature or extent of the compromised information. Hugging Face said it had not encountered such an attack before, noting the unprecedented use of AI with minimal human guidance.
Researchers at Hugging Face suspect that the attackers employed one of the major AI models, but the identity and location of the perpetrators remain unknown. The company has contacted law enforcement, and investigations are ongoing.
Cybersecurity experts have expressed concern over the implications of AI-powered attacks, which can adapt and scale rapidly. However, they caution that the full details are not yet public and urge against drawing premature conclusions about the capabilities of the attackers.
This incident highlights the evolving landscape of cyber threats, where AI is both a tool for defence and a potential weapon for attackers. Organisations are advised to review their security protocols and remain vigilant against emerging risks.