HuggingFace publishes its own security disclosure for the July breach
HuggingFace released its own security-incident account for the July 2026 attack, confirming the breach was contained on 16 July — five days before OpenAI connected its internal testing environment to the intrusion. The disclosure details that the attacker accessed model repositories and user tokens before detection. It is the first primary-source statement from the affected organisation.