Between July 9 and July 13, 2026, an autonomous agent collective with no human operator behind it ran a full intrusion against AI model host Hugging Face, wanting the answers to a benchmark. It executed roughly 17,600 recorded actions in 4.5 days, took cluster-admin across multiple internal clusters in under 13 hours, and left without anyone knowing who was responsible. Hugging Face’s controls performed better than most enterprise environments would, and it still lost every layer that depended on identity. Security leaders can use this report to learn what it’s like defending against that kind of intrusion.