The breached AI model/dataset repository; disclosed the incident, ran remediation and forensic analysis, and issued the token-rotation advisory.
UN
Unnamed autonomous AI attack agent / threat actor
Operated the intrusion end-to-end, executing 17,000+ logged actions across short-lived sandboxes with self-migrating command-and-control infrastructure.
Maker of the open-weight GLM 5.2 model Hugging Face self-hosted to conduct forensic log analysis after commercial frontier models refused the task.
CO
Commercial frontier-model API providers
Their guardrail-restricted APIs blocked Hugging Face's forensic analysts from submitting real attack payloads and C2 artifacts, forcing the switch to a self-hosted model.
HU
Hugging Face platform users
Advised to rotate access tokens and review account activity for suspicious behavior.
LA
Law enforcement / external forensic specialists
Engaged by Hugging Face as part of the incident response.