Bee Cheng Hiang exposes 95,364 members' emails in Singapore's first AI-related data breach
A faulty AI-generated mailing script exposed 95,364 Bee Cheng Hiang members' email addresses to one another in Singapore's first AI-related data breach.
- Victim
- Bee Cheng Hiang
- records
- 95.4K
On 30 September 2026, Singapore's Personal Data Protection Commission (PDPC) disclosed that Bee Cheng Hiang β the long-established Singaporean retailer best known for its barbecued pork (bak kwa) β had exposed the email addresses of 95,364 members in what the regulator described as the country's first AI-related data breach. The exposure stemmed not from a malicious intrusion but from a flawed marketing email that a staff member had assembled with the help of a generative-AI tool.
The incident occurred on 25 April 2026, when an employee in the company's marketing department used an AI tool to generate a Python script for sending a promotional email to a mailing list. Because the email was dispatched in batches of 1,000, and the script failed to conceal recipients from one another, each affected member's address was disclosed to up to 999 other recipients in the same batch, all visible in the message's "To" field. Bee Cheng Hiang notified the PDPC two days later, on 27 April 2026.
How it happened
According to the PDPC, the fault lay with the instructions the employee gave the AI tool rather than with the tool itself. The prompt did not specify that recipients' email addresses should be hidden from one another β for example by using blind carbon copy β and the generated code grouped the addresses in each batch together instead of sending to each recipient individually. The regulator stated that the error was "not a malfunction in the AI tool, but to the prompt given." Compounding the mistake, the script was not properly tested: the employee reviewed only the sending activity logs and not the actual content of a test message, and no supervisory review caught the flaw before the campaign went out. The company had no AI-governance policy in place at the time.
Response
After discovering the exposure, Bee Cheng Hiang halted its bulk email distribution, corrected the script, and notified the affected members. It also introduced double-verification checks, requiring at least two employees to review all bulk email communications before they are sent. In September 2026, the PDPC accepted a voluntary undertaking from the company to strengthen its compliance with Singapore's Personal Data Protection Act 2012, closing the matter without a financial penalty.
Why it matters
Only email addresses were exposed β no financial or more sensitive personal data was involved β but the case is a landmark because it is the first the PDPC has publicly attributed to the use of artificial intelligence. It illustrates a fast-emerging risk as organisations let employees generate production code with AI assistants: a single imprecise prompt, shipped without human review or governance controls, can turn an ordinary marketing send into a reportable breach. With the script fixed, members notified, new review controls in place and the regulator's undertaking accepted, the incident was recorded as resolved.
Timeline
A marketing email built with an AI-generated script exposes members' email addresses to one another.
Bee Cheng Hiang notifies Singapore's Personal Data Protection Commission of the incident.
The PDPC accepts a voluntary undertaking from the company to improve its data-protection compliance.
The PDPC publicly discloses the case as Singapore's first AI-related data breach.
Sources
- mothership.sghttps://mothership.sg/2026/10/bee-cheng-hiang-members-data-breach-ai/
- asiaone.comhttps://www.asiaone.com/singapore/bee-cheng-hiang-ai-data-breach-emails
- stomp.sghttps://www.stomp.sg/trending-now/bee-cheng-hiang-customers-e-mail-addresses-exposed-first-case-ai-related-data-breach-spore