Bee Cheng Hiang exposed 95,000+ customers' e-mail addresses via code written from a bad generative AI prompt
More than 95,000 Bee Cheng Hiang customers had their e-mail addresses exposed when an employee used a generative AI tool to write mass e-mail code without instructions to hide recipients. The marketing e-mails went out in batches of 1,000 with all addresses visible. The PDPC said the AI tool did not malfunction and blamed human error, weak testing, no supervisory review and no governance for generative AI use. The company stopped the e-mails, notified customers and gave the PDPC a voluntary undertaking to improve compliance, including review of AI-generated code.
What the AI did
An employee used a generative AI tool to write code for sending marketing e-mails in bulk, without instructing it to hide recipients' addresses. The resulting code sent the e-mails in batches of 1,000 with every recipient's address visible, and Singapore's data protection regulator found the AI tool did not malfunction.
First reported September 21, 2026 · Added to the register October 4, 2026 · 2 sources
- Customers whose e-mail addresses were exposed
- More than 95,000
- Customers whose email addresses were exposed
- Nearly 100,000
- Deployer
- Bee Cheng Hiang
- Affected
- Bee Cheng Hiang customers
- Country
- Singapore
- When it happened
- April 25, 2026
- First reported
- September 21, 2026
What this means for you
Could this affect you?
More than 95,000 Bee Cheng Hiang customers had their e-mail addresses exposed, and any organisation letting staff use AI-written code on personal data without review could suffer a similar breach.
What to check
- Have AI-generated code that touches personal data independently reviewed and tested, for example with dummy accounts.
- Adopt a policy on how staff may use generative AI tools.
- Run data protection impact assessments before using AI-generated code on personal data.
- Add automated blocks that stop bulk e-mails from showing multiple recipients' addresses.
Areas of your AI programme this touches
Timeline
- April 25, 2026Happened
- September 21, 2026First reported
- October 1, 2026The PDPC accepted Bee Cheng Hiang's voluntary undertaking on Sept 2, under which it will set up a framework governing employees' AI-assisted coding, including independent technical reviews of AI-generated code involving personal data and testing emails with dummy accounts.[2]
Every fact and its source (7)
- Date problematic e-mails were sentApril 25“The problematic marketing e-mails were sent out on April 25, and the PDPC was notified of the data breach on April 27.”[1]
- Regulator actionPDPC accepted voluntary undertaking on Sept 2“the commission accepted a voluntary undertaking by Bee Cheng Hiang on Sept 2 to improve its compliance with the Personal Data Protection Act”[1]
- Regulator finding on causeHuman error, not AI malfunction“The incident was caused by a human error in developing the e-mail distribution code with an AI tool”[1]
- Company responseDouble-verification checks for bulk e-mails“the company has implemented “double-verification checks” by at least two employees for all bulk e-mail communications”[1]
- Undertaking commitmentFramework governing employees' use of AI for coding“Bee Cheng Hiang will establish a framework governing employees' use of AI for coding.”[2]
- Batch size of emailsAbout 1,000 customers per batch“The email was sent out in batches of about 1,000 customers”[2]
- Company responseTwo-employee check on bulk emails“introduced a requirement for at least two employees to check all bulk email communications before they are sent”[2]
Sources
- Bee Cheng Hiang exposes customer e - mail addresses due to bad AI promptstraitstimes.com · October 1, 2026
- Nearly 100,000 affected as Bee Cheng Hiang suffers Singapore's first AI-related data breachasiaone.com · October 1, 2026
How this record is classified. Severity S (4/5): real harm to one organisation, data exposed, or a containment failure. OECD level: incident, an event in which an AI system led to actual harm. Evidence: Confirmed, meaning a company, official or court statement.
The facts in At a glance and in Every fact and its source are quoted from the sources listed. The summary, What the AI did and What this means for you are written from those sources and checked against them automatically before publication. Records reflect what has been disclosed, not everything that has happened. Incidents are found through news feeds and the GDELT Project.

