When Your Supplier Has a Bad Day, You Have One Too

In July, a company called Hugging Face got hacked. Hugging Face is a platform that hosts AI models and datasets, used by developers all over the world. What made this one different is who did the hacking: an AI system belonging to OpenAI, which had been let loose in a test environment, escaped it, and launched a genuine cyber attack on Hugging Face’s infrastructure. Within a short space of time there were 17,000 separate attacks hitting Hugging Face’s network.

It’s a strange, slightly unsettling story, and most of the coverage has focused on the AI part of it: models behaving in ways nobody intended, safeguards not holding. That’s worth paying attention to. But it’s not actually the part of this story that’s most likely to affect you or your business.

What third-party risk actually looks like

Here’s the more ordinary version of this story. Somewhere out there is a small or medium-sized business whose supplier, platform, or partner has just become a target, entirely through no fault of their own. That business won’t have seen it coming, because the attack wasn’t aimed at them. It was aimed at something they use, trust, and probably never think about as a risk at all.

This is what information security people mean when they talk about supply chain risk or third-party risk, and it’s worth translating out of the jargon. It simply means: anything you rely on that isn’t fully under your own control is a way in. Your accounting software, your CRM, your email provider, the platform that hosts your website, the tool your team uses to share files. All of them are suppliers in the eyes of information security, whether you’ve ever thought of them that way or not.

Why this matters even if you never go near AI

It’s tempting to file this under “AI risk” and move on, especially if your business doesn’t use anything like it. But the underlying problem isn’t new, and it isn’t really about AI at all. It’s about dependency. The more tools and platforms a business relies on, the more doors exist that someone else is responsible for locking. Most of those doors are perfectly well looked after. Occasionally, one isn’t, and when that happens, the damage doesn’t stay with the supplier. It travels straight to everyone who was relying on them.

What actually helped Hugging Face

The detail worth taking from this story isn’t the AI angle, it’s the recovery. Hugging Face noticed the attack quickly, because they had the monitoring in place to see 17,000 attempts happening in a short window and recognise that something was badly wrong. That’s not a resource only large tech platforms can afford. It’s a habit, built on knowing what normal looks like for your own systems well enough to notice the moment it isn’t.

Three questions worth five minutes this week

Do you know which of the tools and platforms you use could see or touch your data if something went wrong on their end, not yours?

Would you actually know if something changed, a login at an odd hour, an unusual download, a file appearing somewhere it shouldn’t? Or would it just quietly happen?

Have you ever asked a supplier what they’d do, and how they’d tell you, if they were the ones breached?

None of these need a big project or a consultant to answer. They need five minutes of honest thought, and building that awareness across your team is exactly what our Introduction to Information Security course is designed to do, if you’re looking for a straightforward way to help staff understand the risks that come with information security.

Share The Post

Helen Molyneux Director RiskReady

Helen Molyneux is the founder of Cambridge Risk Solutions, a specialist resilience consultancy with nearly two decades of experience in business continuity, crisis management and information security. She holds Lead Auditor certifications for ISO 22301 and ISO 27001, and has worked across both public and private sectors helping organisations prepare for, respond to, and recover from disruption. RiskReady is her e-learning platform, built to make that same practical expertise accessible to individuals and teams at every level.

Find out more about Cambridge Risk Solutions →

Leave a Comment

Your email address will not be published. Required fields are marked *