News

Hugging Face Confirms Data Breach, Advises Users to Rotate Access Tokens

Hugging Face has confirmed a security breach affecting internal datasets and credentials stored on its platform. The company is urging users to take immediate action by rotating any access tokens and reviewing their account activity for any suspicious behavior.

The breach was confirmed by Hugging Face, a popular platform for hosting machine learning models and datasets. While details about the extent of the compromise remain limited, the company has taken steps to alert its user base about potential risks to their credentials.

Users are advised to:

  • Rotate all access tokens stored on the Hugging Face platform
  • Review account activity for any unauthorized access
  • Consider revoking and regenerating API keys
  • Enable additional security measures where available

This incident highlights the ongoing security challenges faced by platforms hosting AI models and sensitive datasets. Users who have shared credentials or tokens with third-party services should consider rotating those as well, as a precaution.

Sources