Nearly 100,000 customers of Singapore food retailer Bee Cheng Hiang had their email addresses exposed in April after an employee used an artificial intelligence tool to generate code for a mass marketing email, in what regulators described as the first AI-related data breach notified in Singapore.
The incident affected 95,364 customers. Their email addresses became visible to other recipients who received the same marketing message, with emails sent in batches of about 1,000 people. No other personal data was involved, and there was no evidence that the exposed addresses were subsequently misused.
The breach occurred on April 25, when an employee used a generative AI tool to help create a programme for sending marketing emails from a local mailing list. The employee’s instructions did not specifically tell the AI-generated code to keep recipients’ addresses hidden from one another.
The resulting code therefore placed multiple customer addresses in a way that made them visible to everyone in the same email batch. The regulator said the problem was caused by human error in developing the email distribution code rather than a malfunction of the AI tool itself.
Testing also failed to identify the problem before the emails were sent. The employee checked activity logs during testing but did not examine the contents of an actual test email, meaning the exposure was not detected before the marketing campaign went out.
The company notified the Personal Data Protection Commission two days later, on April 27. After discovering the error, it stopped the bulk email distribution, corrected the code and informed affected customers.
The regulator said the incident occurred during the company’s first attempt to incorporate AI tools into its business operations. It also found that there had been insufficient testing, no supervisory review of the employee’s work and no formal governance framework guiding employees on the use of generative AI for business purposes.
Since the incident, the company has introduced a double-verification process requiring at least two employees to check bulk email communications before they are sent. It will also establish a framework governing the use of AI for coding and require independent technical reviews of AI-generated code involving personal data.
Additional measures include testing emails with dummy accounts, strengthening security reviews throughout software development, introducing technical controls to prevent multiple addresses from being exposed in a single email field and providing data-protection training for employees involved in developing and deploying systems that handle personal information.
The regulator accepted the company’s voluntary undertaking on Sept. 2 as part of efforts to improve its compliance with Singapore’s Personal Data Protection Act. Under the law, organisations that breach data-protection requirements can face significant financial penalties.
The case highlights the need for human review when AI-generated code is used to handle personal information. The regulator has advised organisations to conduct appropriate data-protection assessments, establish clear AI-use policies and introduce testing and review mechanisms before deploying AI-assisted systems.