Hugging Face disclosed that its internal datasets and service credentials were compromised in a hack, prompting a security review and urging users to rotate keys.

Hugging Face announced that a recent cyber‑attack exposed internal datasets and service credentials, prompting an immediate security review and a call for users to rotate their API keys.

What was compromised

The breach affected proprietary training data stored on the company’s internal repositories as well as authentication tokens used to access Hugging Face’s hosted models and APIs.

According to the company’s statement, the attackers did not gain access to publicly available model weights, but the loss of internal datasets could impact research projects that rely on proprietary data.

Company response

Hugging Face has launched a comprehensive security audit, engaged external forensic experts, and is resetting all compromised credentials. Users are instructed to generate new API keys and revoke any tokens that were created before the incident.

The firm also recommends enabling two‑factor authentication on all accounts and reviewing access logs for any suspicious activity.

Steps users should take

  • Generate new API keys via the user dashboard
  • Revoke any previously issued tokens
  • Enable two‑factor authentication on your account
  • Monitor usage logs for unexpected requests

These measures are intended to mitigate potential misuse of the exposed credentials and to protect ongoing projects that depend on Hugging Face’s services.

For further details, see the TechCrunch coverage of Hugging Face breach.