Find notable cyber news and cases, enriched with sources, timelines, and signals.

Hugging Face hit by network compromise

Incident
First reported
Last updated
Happening score
H score 10
2 unique sources, 2 articles

Summary

Hide ▲

Hugging Face confirmed a production infrastructure breach that exposed a limited set of internal datasets and service credentials, creating risk of further internal access. The intrusion began through malicious dataset code execution paths in a remote code loader and a template injection in a dataset configuration. The company said it found no evidence the attacker tampered with public models, datasets, or Spaces.

Related Happenings

TrustBastion Android malware campaign abusing Hugging Face for credential theft

Campaign
H score37 First: 30.01.2026 00:08 Last: 30.01.2026 00:08 Sources 1

About this happening: A new Android malware campaign is abusing Hugging Face as distribution infrastructure to deliver polymorphic APKs that steal credentials from users of financial and...

Timeline

  1. 20.07.2026 08:27 3 articles · 17h ago

    Hugging Face detects unauthorized access to internal datasets and service credentials

    Initial Disclosure

    Hugging Face said it detected and responded to a production-infrastructure intrusion earlier last week that resulted in unauthorized access to a limited set of internal datasets and several service credentials. The company said the compromise began in the data processing pipeline, where a malicious dataset abused a remote code dataset loader and a template injection in a dataset configuration to run code on a processing worker; it later addressed the root cause, rebuilt compromised nodes, revoked and rotated affected credentials and tokens, tightened cluster controls, and urged customers to rotate access tokens and review account activity.

    Show sources