Meyka Pro banner
Global Market Insights

Bee Cheng Hiang’s AI Breach Exposes 95,364 Emails in Singapore First

October 1, 2026
07:51 PM
3 min read

Key Points

95,364 customer emails exposed in April after incomplete AI prompt.

Employee failed to instruct AI to hide recipient addresses from each other.

PDPC confirmed Singapore's first AI-related data breach on September 30.

Bee Cheng Hiang now requires two staff to verify all bulk emails before sending.

Be the first to rate this article

Bee Cheng Hiang accidentally exposed the email addresses of 95,364 customers in April when a marketing employee used a generative AI tool to write code for bulk emails without instructing it to hide recipient addresses from each other. The Personal Data Protection Commission confirmed on September 30 this was Singapore’s first reported AI-related data breach. Only email addresses were affected, and no evidence of further misuse has emerged.

How the breach happened

On April 25, a Bee Cheng Hiang employee asked a generative AI tool to write a Python script to send mass marketing emails in batches of 1,000 customers. The employee did not specify that each recipient’s email address should be hidden from others. The resulting code contained a missing bracket that grouped all 1,000 recipient addresses into a single field visible to everyone in that batch. The employee tested the script by checking activity logs but did not review the actual test email content, so the error went undetected before deployment.

Why the AI tool was not at fault

The Personal Data Protection Commission clarified that the breach resulted from human error in the prompt, not a malfunction in the AI tool itself. The employee failed to give specific instructions to conceal email addresses. According to the PDPC, if the prompt had included those instructions, the correct code would have sent individual emails to each customer rather than batches of 1,000. This was Bee Cheng Hiang’s first attempt at using AI tools in business operations.

Company response and safeguards

Bee Cheng Hiang immediately stopped the bulk email distribution and corrected the erroneous script. The PDPC noted the company took prompt remedial action and informed affected customers. The company introduced a requirement for at least two staff members to verify all bulk email communications before sending. The PDPC conducted a voluntary undertaking with Bee Cheng Hiang on September 2 to improve compliance.

What the PDPC found

The affected data was not managed, processed, or generated by any AI-powered operation or process, the commission said. No other personal data beyond email addresses was exposed. The PDPC found no evidence of further misuse of the disclosed email addresses. The breach was reported to the commission on April 27, two days after it occurred.

Final Thoughts

The breach underscores the gap between AI tool capability and user intent. Organizations adopting generative AI must provide precise instructions and implement robust testing before deployment. For Singapore businesses, this case signals regulators will scrutinize AI adoption closely.

FAQs

How many Bee Cheng Hiang customers were affected by the data breach?

95,364 customers had their email addresses exposed. Each customer’s address was visible to up to 999 other recipients in the same batch of 1,000.

When did the Bee Cheng Hiang data breach occur?

The breach occurred on April 25, 2026, when the faulty marketing emails were sent. The PDPC was notified two days later on April 27.

Was this the first AI-related data breach in Singapore?

Yes. The Personal Data Protection Commission confirmed on September 30 this was the first AI-related data breach it had been notified of in Singapore.

What personal data was exposed in the breach?

Only email addresses were exposed. No other personal data was affected, and there is no evidence the exposed addresses were misused.

Disclaimer:

The content shared by Meyka AI PTY LTD is solely for research and informational purposes.  Meyka is not a financial advisory service, and the information provided should not be considered investment or trading advice.

About Author

Author

Danny Kontos

Co Founder

Danny Kontos has been a stock investor since 2007 and co-founded Meyka in 2023. He keeps a small, focused portfolio and only moves when the numbers are hard to argue with. He has waited years on a single position before. Before Meyka, he ran a web hosting company and a mortgage lending platform, so he knows what a well-run business actually looks like under the hood. This article did not come from a news cycle. It came from someone who has been watching this space for a long time.

What brings you to Meyka?

Pick what interests you most and we will get you started.

I'm here to read news

Find more articles like this one

I'm here to research stocks

Ask Meyka Analyst about any stock

I'm here to track my Portfolio

Get daily updates and alerts (coming March 2026)