KEEP IN MIND
Hugging Face urges users to rotate access tokens
The AI platform is investigating a breach where internal data and service credentials were accessed. The company now recommends that users change their access tokens and review account activity.
Publicerad 19 July 2026, 08.04

Hugging Face, a platform where developers share and use AI models and datasets, says an attacker gained access to parts of the company's production environment. The attacker gained unauthorized access to a limited number of internal data sets as well as several service credentials and digital keys.
According to the company, the breach began in the system that processes uploaded datasets. Hugging Face says the attack was powered by an autonomous system of AI agents that performed thousands of actions. That description comes from the affected vendor's ongoing investigation and is not yet a completed independent forensic conclusion.
The company has closed the two avenues of attack, rebuilt affected systems, and recalled or replaced exposed keys. Hugging Face says it has seen no evidence of manipulation of public models, datasets, Spaces, container images or published software packages.
It is still unclear whether partner or customer data was affected. As a precaution, Hugging Face recommends all users to change their access tokens, i.e. digital keys that allow other tools to use the account, and to review recent account activity.
Därför spelar det roll
An access token can give automated systems access to data and services without someone entering a password each time. If the key ends up wrong, it can therefore be used until it is blocked. NIST, the United States' Institute of Standards and Technology, notes at the same time that AI agents create new security risks and that basic cybersecurity needs to be adapted as programs gain more latitude.
Det här kan du göra
- Exchange your Hugging Face access tokens as recommended by the company.
- Review recent account activity and look for unexpected calls or logins.
- Check which apps and servers are using each key before blocking the old one.