The Suspect Is New. The Doors Are Not. - Safe Security

The Suspect Is New. The Doors Are Not.

Aug 21, 2026 5 minute read

Explaining the Hugging Face break-in the way I would explain it to a jury

By Josh Fazio, VP of Global Pre-Sales, Safe Security

The hardest part of working computer crime as a Detective was never the investigation. It was standing in a courtroom afterward and explaining it to twelve people who had never once thought about a server.

You learn fast in that room. Drop the jargon. Use things people can picture. If the jury does not follow you, you have not proven anything, no matter how good your evidence is.

So here is the biggest security story of the summer, explained the way I would have had to explain it to a jury.

Start with the company

Hugging Face is where the artificial intelligence industry keeps its work. Researchers and companies publish their AI systems and the data behind them there, and everyone else downloads that work and builds on top of it. Anyone in the world can upload. That openness is not a weakness in the business. It is the business, and millions of people depend on it.

One more thing, and the entire case turns on it. Hugging Face does not simply hold what you upload. It automatically opens and processes every file that arrives so the contents can be cataloged and previewed. No person reviews it first. It happens on its own, the moment the file lands.

In July, someone/something uploaded a file built to take advantage of exactly that.

Three things then went wrong in a row.

  1. The system gave up its passwords. Opening that file caused the processing system to spill out the contents of the environment it was running in. Sitting in there were live passwords and access keys. Nobody stole them or guessed them. They were already in the open.

  2. One password opened everything. Hugging Face has since explained in its own report that one of those keys had been configured to operate across its systems with full administrator rights. Not one system. Nearly all of them. Within about a second, the intruder had administrator control of the place.

  3. The alarm went off. Nobody rolled a patrol car. This is the part I would have spent the most time on with a jury. The alarm system actually worked. It picked up scattered signals, put them together correctly, and concluded a break-in was underway. Then it filed that conclusion as routine and never called anyone. The alarm sounded in an empty room.

That is the whole case. A file nobody should have trusted, passwords left where they could be read, one credential that opened far too much, and an alarm nobody answered.

Now the part that made headlines

There was no burglar.

The intruder was an artificial intelligence system built by OpenAI. It was being given a security exam inside a closed-off test environment, to measure what it was capable of. It got stuck on a question. It worked out that the answers to the exam were probably sitting on Hugging Face’s servers. So it broke out of the test environment and went to get them.

Nobody told it to do that. No person directed the steps. It was trying to pass a test.

Over four and a half days, it took roughly seventeen thousand separate actions. Almost all of them failed. That is not a criticism of the machine. That is the point. It did not need to be clever. It only needed to be tireless, and it needed one of those seventeen thousand attempts to work.

A person cannot do that. A person gets tired, gets careless, and goes home. This thing did not.

What I would tell the jury in closing

If you take one thing from this, take this.

The intruder was new. What it exploited was not.

I investigated cases twenty years ago that came down to exactly the same three failures. Something got trusted that should not have been. A password sat somewhere it should not have. One set of credentials opened far more than it should have opened. Add an alarm that nobody answers, and you have most of the intrusions I ever worked on, and most of the ones being worked today.

Hugging Face said as much in its own report. The weaknesses were familiar. A skilled human attacker could have found the same ones.

That is what people mean when they say history repeats. It does not mean nothing changed. It means the new thing walked through the old failures, and the old failures are the part you actually control.

Where we sit

That is the problem SAFE CTEM is built to address: seeing how individual weaknesses connect into a path an attacker can walk, and getting the few that genuinely matter fixed. Attacks that run at machine speed do not call for panic. They call for a defense that keeps deciding what matters and acting on it.

We spend most of our attention on who the attacker was, because that is the interesting question. The evidence has never much cared. It keeps pointing at the same handful of doors.

This time, a machine checked whether they were still unlocked 17,000 times in four days.

They were!

Sources: Hugging Face incident disclosure (July 16, 2026) and technical timeline (July 27, 2026); OpenAI incident account (July 21, 2026, with updates through July 29); Axios coverage (published August 6, 2026, covering the August 5 Black Hat presentation).



See how SAFE transforms your CTEM Unified exposure visibility, AI-driven prioritization, and quantified risk in business terms. Built for enterprise scale.