2025 Teknalyze. All rights reserved

Singapore’s First AI-Related Data Breach Exposes 95,000 Customer Emails

Singapore's first AI-related data breach occurred when Bee Cheng Hiang exposed over 95,000 customer email addresses due to an AI tool error.

0 comments

đź“–

3 minutes
Singapore's First AI-Related Data Breach Exposes 95,000 Customer Emails - Tech Flash
TECH FLASHARTIFICIAL INTELLIGENCE

Singapore’s first reported AI-related data breach is drawing fresh attention after regulators released new details about an April incident involving Bee Cheng Hiang, the local food company best known for its bak kwa products.

The breach occurred on April 25, 2026, when more than 95,000 customer email addresses were accidentally exposed during a marketing campaign. On September 30, Singapore’s Personal Data Protection Commission confirmed that the case was the country’s first reported data breach involving the use of generative AI.

AI-Generated Code Caused the Exposure

Bee Cheng Hiang had begun using generative AI tools to help automate parts of its marketing workflow. An employee asked an AI system to generate code for sending bulk emails from a local mailing list.

The prompt, however, did not specify that each recipient’s email address should be hidden from other recipients. The resulting program sent messages in batches of about 1,000 customers, exposing the email addresses within each batch.

The affected information was limited to email addresses, and regulators said there was no evidence that the exposed data was subsequently misused.

Human Error, Not an AI Malfunction

The PDPC stressed that the AI system itself did not malfunction. Instead, the problem came from how the employee instructed the model and how the generated code was reviewed before deployment.

Testing relied on activity logs rather than examining the actual test emails, and the company did not have a supervisory review process or established governance framework for employees using generative AI in coding tasks.

The case provides a practical example of a growing issue for businesses adopting generative AI. AI-generated software can accelerate development, but the output still requires testing, security review, and human oversight before it is used with customer data.

Bee Cheng Hiang Introduces New Safeguards

Following the incident, Bee Cheng Hiang stopped the email campaign, corrected the code, and notified affected customers.

The company has since introduced double-verification checks for bulk emails and is developing a framework governing the use of AI-generated code. The new measures include independent technical reviews when AI-generated software handles personal data and automated controls designed to prevent large numbers of addresses from appearing in a single email field.

Singapore’s PDPC accepted a voluntary undertaking from the company on September 2 requiring improvements to its compliance processes under the Personal Data Protection Act.

Why the Case Matters Now

Although the breach itself happened months ago, its significance became clearer only after regulators disclosed the circumstances surrounding the incident and formally identified it as Singapore’s first reported AI-related data breach.

The case highlights an emerging risk as companies increasingly allow employees to use generative AI for coding and automation. The lesson is less about AI producing inherently unsafe software and more about organizations treating AI-generated code with the same testing, security, and review requirements applied to code written by humans.

SEE MORE IN /