More than 95,000 customers of Bee Cheng Hiang, a Singapore-based traditional food products company, had their e-mail addresses unintentionally exposed in April due to an error involving the use of an artificial intelligence (AI) tool. The incident, which came to light on September 30, marks Singapore’s first reported AI-related data breach, according to the Personal Data Protection Commission (PDPC).
The breach occurred after an employee used an improper prompt to direct a generative AI tool to create code for sending marketing e-mails. This code broadcasted the recipients’ e-mail addresses openly to all e-mail recipients in each batch of 1,000 customers, rather than keeping them confidential. The problematic e-mails were sent on April 25, and Bee Cheng Hiang notified the PDPC of the breach two days later.
The PDPC clarified that the breach resulted from human error in developing the e-mail distribution code rather than a malfunction of the AI tool itself. Specifically, the prompt given to the AI lacked instructions to conceal individual recipients’ addresses, leading to the inadvertent exposure. A minor difference in the coding syntax—involving the placement of brackets—altered the program’s behaviour, causing it to reveal all addresses instead of sending individualized e-mails.
The commission noted that the company did not carry out sufficient testing or supervisory checks before deploying the code. Testing focused on reviewing activity logs without verifying the actual content in test e-mails. Bee Cheng Hiang’s reliance on a single employee without a review framework contributed to the oversight. At the time, this was the company’s initial use of AI tools in its operations.
Following discovery of the breach, Bee Cheng Hiang halted the distribution, corrected the code, and informed affected customers. The company has since implemented double-verification procedures requiring at least two employees to review all bulk e-mail communications before dispatch.
The PDPC underscored that organisations should conduct data protection impact assessments before incorporating AI tools into business processes. It also recommended establishing policies, review mechanisms, and staff training to ensure responsible AI use and safeguard personal data. Bee Cheng Hiang agreed to a voluntary undertaking on September 2 to enhance compliance with the Personal Data Protection Act.
In response, the company committed to several measures, including instituting a governance framework for AI-generated code involving personal data, performing independent technical reviews, embedding security protocols throughout software development stages, and formalising data breach response procedures. It also plans to implement automated technical safeguards to prevent e-mails exposing multiple addresses and expand data protection training for relevant staff.
Under Singapore law, organisations that fail to comply with data protection regulations may face fines up to SGD 1 million or 10% of their annual turnover, whichever is higher. The PDPC’s findings highlight the need for rigorous controls when integrating AI technologies into operational workflows to prevent data exposure risks.
