Skip to main content
Promotional banner for the pentest readiness checklist
IncidentPeople used AI as a toolSeverity S: serious, 4/5Confirmed: a company, official or court statement

Bee Cheng Hiang exposed 95,000+ customers' e-mail addresses via code written from a bad generative AI prompt

More than 95,000 Bee Cheng Hiang customers had their e-mail addresses exposed when an employee used a generative AI tool to write mass e-mail code without instructions to hide recipients. The marketing e-mails went out in batches of 1,000 with all addresses visible. The PDPC said the AI tool did not malfunction and blamed human error, weak testing, no supervisory review and no governance for generative AI use. The company stopped the e-mails, notified customers and gave the PDPC a voluntary undertaking to improve compliance, including review of AI-generated code.

What the AI did

An employee used a generative AI tool to write code for sending marketing e-mails in bulk, without instructing it to hide recipients' addresses. The resulting code sent the e-mails in batches of 1,000 with every recipient's address visible, and Singapore's data protection regulator found the AI tool did not malfunction.

First reported September 21, 2026 · Added to the register October 4, 2026 · 2 sources

Customers whose e-mail addresses were exposed
More than 95,000
Customers whose email addresses were exposed
Nearly 100,000
Deployer
Bee Cheng Hiang
Affected
Bee Cheng Hiang customers
Country
Singapore
When it happened
April 25, 2026
First reported
September 21, 2026

What this means for you

Could this affect you?

Yes, if your staff use AI to write code that handles personal data

More than 95,000 Bee Cheng Hiang customers had their e-mail addresses exposed, and any organisation letting staff use AI-written code on personal data without review could suffer a similar breach.

What to check

  • Have AI-generated code that touches personal data independently reviewed and tested, for example with dummy accounts.
  • Adopt a policy on how staff may use generative AI tools.
  • Run data protection impact assessments before using AI-generated code on personal data.
  • Add automated blocks that stop bulk e-mails from showing multiple recipients' addresses.

Timeline

  1. April 25, 2026Happened
  2. September 21, 2026First reported
  3. October 1, 2026The PDPC accepted Bee Cheng Hiang's voluntary undertaking on Sept 2, under which it will set up a framework governing employees' AI-assisted coding, including independent technical reviews of AI-generated code involving personal data and testing emails with dummy accounts.[2]
Every fact and its source (7)
  1. Date problematic e-mails were sentApril 25
    “The problematic marketing e-mails were sent out on April 25, and the PDPC was notified of the data breach on April 27.”[1]
  2. Regulator actionPDPC accepted voluntary undertaking on Sept 2
    “the commission accepted a voluntary undertaking by Bee Cheng Hiang on Sept 2 to improve its compliance with the Personal Data Protection Act”[1]
  3. Regulator finding on causeHuman error, not AI malfunction
    “The incident was caused by a human error in developing the e-mail distribution code with an AI tool”[1]
  4. Company responseDouble-verification checks for bulk e-mails
    “the company has implemented “double-verification checks” by at least two employees for all bulk e-mail communications”[1]
  5. Undertaking commitmentFramework governing employees' use of AI for coding
    “Bee Cheng Hiang will establish a framework governing employees' use of AI for coding.”[2]
  6. Batch size of emailsAbout 1,000 customers per batch
    “The email was sent out in batches of about 1,000 customers”[2]
  7. Company responseTwo-employee check on bulk emails
    “introduced a requirement for at least two employees to check all bulk email communications before they are sent”[2]

Sources

  1. Bee Cheng Hiang exposes customer e - mail addresses due to bad AI prompt
    straitstimes.com · October 1, 2026
  2. Nearly 100,000 affected as Bee Cheng Hiang suffers Singapore's first AI-related data breach
    asiaone.com · October 1, 2026

How this record is classified. Severity S (4/5): real harm to one organisation, data exposed, or a containment failure. OECD level: incident, an event in which an AI system led to actual harm. Evidence: Confirmed, meaning a company, official or court statement.

The facts in At a glance and in Every fact and its source are quoted from the sources listed. The summary, What the AI did and What this means for you are written from those sources and checked against them automatically before publication. Records reflect what has been disclosed, not everything that has happened. Incidents are found through news feeds and the GDELT Project.

Promotional banner graphic asking if you are ready for PCI DSS 4.0 with a call-to-action to get the guide