Cyber Incident Victim: Hugging Face
Date:
May 2024
Location:
United States of America
Summary
Hugging Face detected unauthorized access to secrets within its Spaces platform, prompting suspicions that certain credentials may have been compromised. The organization revoked affected user tokens and advised transitioning to fine-grained access tokens while collaborating with cybersecurity experts to investigate and strengthen security protocols. Remediation efforts included infrastructure enhancements such as eliminating org tokens, implementing a key management service for secrets, improving token leak detection, and planning to deprecate classic tokens. The incident was reported to law enforcement and data protection authorities as part of ongoing efforts to bolster system-wide security.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 2 techniques |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On May 1, 2024, Hugging Face disclosed an incident involving unauthorized access to its Spaces platform, specifically targeting Spaces secrets. The company detected the breach earlier that week, suspecting that a subset of these secrets—which included Hugging Face tokens—may have been compromised. In response, Hugging Face immediately revoked affected tokens and notified impacted users via email, advising them to refresh credentials and transition to fine-grained access tokens. The incident prompted collaboration with external cybersecurity forensic specialists to investigate the breach and review existing security protocols. While the exact scope of unauthorized access remained under investigation, the compromise centered on secrets stored within Spaces, a collaborative AI application hosting environment.

Hugging Face implemented multiple infrastructure security enhancements following the breach. These included eliminating organization tokens to improve traceability and auditing, integrating a key management service (KMS) for Spaces secrets, and strengthening systems to detect and invalidate leaked tokens proactively. The company announced plans to phase out classic read/write tokens once fine-grained alternatives achieved full functionality. Law enforcement and data protection authorities were notified of the incident, though no specific attacker identity or methodology was disclosed. Ongoing investigations focused on identifying related incidents while infrastructure-wide security improvements continued. The breach caused operational disruptions for users with revoked tokens, though Hugging Face did not quantify the number of affected accounts or specify data exfiltration beyond potential secret access.
