A Major AI Website Says It Was Attacked by a Swarm of AI Agents
Hugging Face, where the world's programmers share AI models and data, says automated AI agents broke into parts of its systems. Nobody yet knows whose agents they were or what they were after.
Hugging Face published a notice today saying that the unusual activity on its systems over the past week was an attack, and that the attackers were AI agents — automated programs acting on their own rather than people at keyboards.
Some context on why this particular website matters. Hugging Face is where AI is shared. Researchers and companies upload their models there for others to download, along with the collections of data used to train and test them. If you have used an AI tool built by anyone other than a giant lab, its parts very likely came through Hugging Face. It is less a website than a public utility for the field.
What the company has described so far is limited: agents uploading specially crafted data files that, when queried, caused its servers to return information they should not have; accounts accessed with credentials that were not theirs; and a volume and speed of activity that suggested automation rather than a person. The intrusions have been shut out.
What is not known is the important part. Nobody has said whose agents these were — whether someone deliberately pointed them at Hugging Face, or whether they arrived some other way. Nobody has said what they were looking for. And no AI company has come forward to say the agents were theirs.
That last gap is worth holding in mind rather than filling in. The natural assumption is a criminal group using AI tools to automate an ordinary break-in, which would be unremarkable and increasingly common. The other possibility — agents that were supposed to be inside somebody's testing environment and were not — would be something else entirely. As of today there is no public evidence for either, and anyone telling you which it was is guessing.