Switch to main content

Communications lessons from the Hugging Face cyberattack

Crisis & Reputation Management 24 Jul 2026 |

Hadvisorsus Ellie Taylor 64X64Px
Ellie Taylor
Abernathy Abigail Ruck 64X64
Abigail Ruck
Hadvisors Us Ai Cyberattack Insights

On July 16, 2026, Hugging Face, an open-source developer platform, reported an unusual intrusion into part of its production infrastructure driven by an autonomous AI agent. Five days later, it was revealed by OpenAI that the “attacker” was its own models — GPT-5.6 Sol and a more capable pre-release system. This alarming incident will be remembered as one of the first of its kind, and certainly not the last. There has been a 89% increase in attacks by AI-enabled adversaries already. As AI becomes increasingly powerful and continues to operate with autonomy, AI is proving as powerful of a menace as human bad actors, posing unprecedented operational and reputational threats.

Here’s how our crisis team is counseling clients to stay prepared:

Include nuances for AI attackers in cyber incident communications plans.

Cyberattacks of the past few decades were largely generated by humans, but this new wave of cyberattacks can include a minimal or nonexistent human element. The existing cyber playbook doesn’t need to be thrown out the window, but it must be readily updated to reflect the latest threats, take into account what needs to—or should—be disclosed, anticipate shorter timelines for an event becoming public and prepare for a lack of human interaction previously held with ransomware negotiators and their proxies.

Hugging Face’s blog post disclosure described challenges using commercial APIs (Application Programming Interfaces) to mitigate the attack because commercial models’ safety guardrails couldn’t “distinguish an incident responder from an attacker.” Hugging Face drew from this a “practical lesson for defenders” to be “ready before an incident” by identifying “a capable model you can run on your own infrastructure.” Taken one step further, organizations must ask themselves how long-term incident response and preparation for the accompanying communications, not just in-the-moment mitigation and updates, may differ if the cyberattack is driven by AI rather than humans.

How might the communications approach differ if the threat actor is artificial intelligence? No matter who is attacking, incident response requires organization-wide mobilization and coordination, particularly between the executive, legal, IT and communications teams—and it will be increasingly important to socialize cybersecurity preparation plans when dealing with compressed timelines. Communications in “old school” cyberattacks often confirm the identity of an attacker and reassure stakeholders that law enforcement is involved in mitigating the threat. With AI-driven attacks, proper disclosure will still build trust, but this approach may also single out a competitor, collaborator or prominent tech company as an adversary. If your organization can identify the attacker, will you publicize the attacker’s name or handle a response privately? It may depend on the scope of the breach, any existing relationships and regulatory requirements.

Manage complexity in public disclosures.

In the early days of these new cyberattacks, breaches are likely to attract nationwide attention, as seen with the proliferation of media coverage and speculation on social media about the impact and significance of the Hugging Face/OpenAI incident. This heightens the importance of clear disclosures and a proactive communications strategy.

Hugging Face, as the “victim” of the attack, kept a notably clear and accessible tone to its communications, even to readers who may not have technical proficiency. OpenAI, which had a bit more explaining to do, did provide further detail in its communications, but this was less discernible for a non-technical audience, which risks heightening the perception of impropriety. To ensure all audiences have a clear understanding of the incident, public-facing materials that are likely to be picked up by media should be “plain text” and able to be clearly understood by a non-technical audience. Target technical audiences who are likely to dive in deeper and understand the nitty-gritty details through direct channels.

Litigation or collaboration? Consider the path forward.

The latest from OpenAI signals that the two parties are collaborating on a forensic investigation and incident response. It will be interesting to see how this develops throughout the investigation as its implications are discovered. If one company’s AI agent causes widespread operational disruption, damages customer relationships or significantly harms a company’s reputation, litigation may be a reasonable avenue to recoup lost revenue or preserve a public image. Imagining thresholds of incident severity and the proportional response—outside of the “fog of war”—can help provide a preliminary roadmap in the event of an incident and assist companies in navigating this increasingly complex environment with as little disruption to business and stakeholders as possible.