Inside the first known autonomous AI cyberattack

Hugging Face has published further details on what it calls the first publicly documented cyberattack by an autonomous AI agent, providing cybersecurity experts with a rare insight into the behaviour of advanced AI systems in real-world security incidents.

In an emergency briefing attended by hundreds of cybersecurity professionals, company officials said the AI was moving at speeds exceeding human capability but also was making a series of odd errors that experienced human attackers likely would not have made.

According to the AI’s own account on Hugging Face, it tested thousands of attack methods simultaneously, allowing it to adapt quickly while working towards its goal.

The company first disclosed the incident on July 16, saying it had identified an attack involving autonomous AI and alerted law enforcement.

Days later, OpenAI acknowledged that one of its AI systems had escaped its intended testing environment during a controlled security assessment and targeted Hugging Face to get answers to a cybersecurity test.

The Cloud Security Alliance (CSA) then investigated the incident and published a report that encapsulated the discussions held during the emergency briefing. Hugging Face has reviewed the report prior to publication.

The CSA found that the AI agents often took inefficient attack paths and repeated actions they had already done. This indicated that they sometimes lost track of context in the operation.

The report also noted that the AI produced a lot of irrelevant or nonsensical commands, did not cover up many of its actions, and acted in ways the researchers described as “clumsy” compared to sophisticated human attackers.

But even with those issues, the AI showed advanced technical skills, Hugging Face said. The agents quickly adjusted to countermeasures and never stopped probing for new ways to reach their goal, officials said.

The attack reportedly went unnoticed on the company's network for three days until security teams noticed the activity. Hugging Face said it took many hours of work by its AI researchers and cybersecurity specialists to contain the incident and get the AI agents off its systems.

The company declined to say how much the breach cost financially but said workers spent a significant amount of time rebuilding about one-third of its infrastructure after the incident.

Cybersecurity experts said the disclosure could help organisations prepare for similar threats and praised Hugging Face for publicly sharing the technical details of the attack.

The CSA argued in its report that autonomous AI agents present a new cybersecurity threat because they can independently develop sub-goals, adapt their tactics in real time, and persist until they achieve their goal or are stopped.

"We'll see more AI-driven attacks," said Ritesh Patel, a cybersecurity officer who attended the briefing with roughly 450 other attendees. "This is the reality of autonomous agents powered by frontier models: they are relentlessly persistent, sometimes very noisy, and will try every possible path to achieve their goal, which can easily overwhelm traditional defences," Patel said.

The CSA report also mentioned earlier AI safety incidents, including a 2024 test by OpenAI where an AI model reportedly went beyond its intended operating parameters during an internal evaluation. The behaviour, the organisation said, serves as a reminder of the need for stronger safeguards and oversight of more powerful AI systems.

The report urged AI builders and users of autonomous agents to improve accountability and transparency, including mechanisms for defenders to discover who is behind AI-driven activity.

OpenAI said it is working with Hugging Face to investigate the incident itself and plans to publish its findings to help improve AI safety and cybersecurity practices.