Bee Cheng Hiang Data Breach: AI-Written Code Exposed 95,000 Emails
straitstimes.com

Bee Cheng Hiang Data Breach: AI-Written Code Exposed 95,000 Emails

Tech News
3 min read

Published by AINave Editorial

TL;DRA prompt that omitted an address-privacy requirement helped produce a bulk-email script that exposed more than 95,000 customer email addresses. Singapore’s PDPC attributed the incident to human error and inadequate testing, not an AI tool malfunction.

A bulk send exposed addresses to other customers

Bee Cheng Hiang exposed more than 95,000 customers’ email addresses in April 2026 when a marketing email script put recipients’ addresses where other recipients could see them. The emails went out on April 25, and the company notified Singapore’s Personal Data Protection Commission (PDPC) on April 27. The commission described it as the first AI-related breach reported to it, not necessarily the first such incident in Singapore. The incident details and dates

The messages were sent in batches of 1,000. The PDPC said email addresses were the only personal data affected and that there was no evidence they were further misused. It also clarified that the addresses themselves were not managed, processed or generated by an AI-powered operation. The PDPC’s account of the exposure

The missed requirement was visible in the workflow

An employee asked a generative AI tool to write a program for sending mass email using a local list in batches. The prompt did not specify that each customer’s address had to be hidden from the others. The resulting code sent the addresses together in batches, rather than sending each customer an individually addressed message. The prompt and code behavior

The PDPC attributed the incident to human error in developing code with an AI tool, not to a tool malfunction. That distinction matters: the system produced code for a task that lacked an explicit privacy requirement, while the company’s process did not catch the result before it reached customers. According to the commission, the employee checked activity logs but did not inspect the contents of the actual test email. The company also lacked sufficiently robust testing, supervisory review and policies for workplace use of generative AI. The PDPC’s reported findings

Safeguards target both people and the send mechanism

After confirming the error, Bee Cheng Hiang stopped the mass distribution, corrected the code and notified affected customers. It later introduced a requirement for at least two staff members to verify bulk emails before sending. The company’s response

The PDPC accepted a voluntary undertaking on September 2. Bee Cheng Hiang committed to a framework for employee use of AI in coding, including independent technical review when AI-generated code involves personal data. Other measures include testing emails with dummy accounts, formalising a data-breach procedure, training relevant staff and adding automated controls to block emails with multiple addresses in a single recipient field. The undertaking and planned controls

These measures address different failure points: review can challenge the code, test messages can reveal what recipients will actually see, and automated blocking can stop a risky send even if earlier checks fail. The case shows why AI-generated code needs to be assessed in the real workflow where it will run. Here, checking logs was not a substitute for checking the message itself.

FAQs

A marketing email script created with help from a generative AI tool sent messages with recipients’ addresses visible to other customers. The emails went out on April 25, 2026, and the company notified the PDPC on April 27. The reported timeline and breach

Sources

Latest Tech News