Hugging Face data breach leaks user uploads

Published August 17, 2026

Hugging Face, a platform for sharing AI models, had a security breach that exposed user-uploaded data. Attackers accessed private datasets and model files shared on the site.

Report priority
Medium
Involves
Hugging Face

What is known

An attacker exploited a misconfigured storage system to access private datasets and model files uploaded by Hugging Face users.

What to do

Check if you uploaded private datasets or AI models to Hugging Face before the breach.

Review your uploaded data on Hugging Face and remove or secure any sensitive information. Hugging Face has not provided a specific fix, but they recommend monitoring your account for unusual activity.

Reported details

Adam Shostack, president of Shostack & Associates and an affiliate professor at the University of Washington, talks with the Dark Reading News Desk about why he was "blown away" by OpenAI's revelations regarding the Hugging Face attack.