Key Points
95,364 customer emails exposed in April after incomplete AI prompt.
Employee failed to instruct AI to hide recipient addresses from each other.
PDPC confirmed Singapore's first AI-related data breach on September 30.
Bee Cheng Hiang now requires two staff to verify all bulk emails before sending.
Bee Cheng Hiang accidentally exposed the email addresses of 95,364 customers in April when a marketing employee used a generative AI tool to write code for bulk emails without instructing it to hide recipient addresses from each other. The Personal Data Protection Commission confirmed on September 30 this was Singapore’s first reported AI-related data breach. Only email addresses were affected, and no evidence of further misuse has emerged.
How the breach happened
On April 25, a Bee Cheng Hiang employee asked a generative AI tool to write a Python script to send mass marketing emails in batches of 1,000 customers. The employee did not specify that each recipient’s email address should be hidden from others. The resulting code contained a missing bracket that grouped all 1,000 recipient addresses into a single field visible to everyone in that batch. The employee tested the script by checking activity logs but did not review the actual test email content, so the error went undetected before deployment.
Why the AI tool was not at fault
The Personal Data Protection Commission clarified that the breach resulted from human error in the prompt, not a malfunction in the AI tool itself. The employee failed to give specific instructions to conceal email addresses. According to the PDPC, if the prompt had included those instructions, the correct code would have sent individual emails to each customer rather than batches of 1,000. This was Bee Cheng Hiang’s first attempt at using AI tools in business operations.
Company response and safeguards
Bee Cheng Hiang immediately stopped the bulk email distribution and corrected the erroneous script. The PDPC noted the company took prompt remedial action and informed affected customers. The company introduced a requirement for at least two staff members to verify all bulk email communications before sending. The PDPC conducted a voluntary undertaking with Bee Cheng Hiang on September 2 to improve compliance.
What the PDPC found
The affected data was not managed, processed, or generated by any AI-powered operation or process, the commission said. No other personal data beyond email addresses was exposed. The PDPC found no evidence of further misuse of the disclosed email addresses. The breach was reported to the commission on April 27, two days after it occurred.
Final Thoughts
The breach underscores the gap between AI tool capability and user intent. Organizations adopting generative AI must provide precise instructions and implement robust testing before deployment. For Singapore businesses, this case signals regulators will scrutinize AI adoption closely.
FAQs
95,364 customers had their email addresses exposed. Each customer’s address was visible to up to 999 other recipients in the same batch of 1,000.
The breach occurred on April 25, 2026, when the faulty marketing emails were sent. The PDPC was notified two days later on April 27.
Yes. The Personal Data Protection Commission confirmed on September 30 this was the first AI-related data breach it had been notified of in Singapore.
Only email addresses were exposed. No other personal data was affected, and there is no evidence the exposed addresses were misused.
Disclaimer:
The content shared by Meyka AI PTY LTD is solely for research and informational purposes. Meyka is not a financial advisory service, and the information provided should not be considered investment or trading advice.
About Author

Danny Kontos
Co FounderDanny Kontos has been a stock investor since 2007 and co-founded Meyka in 2023. He keeps a small, focused portfolio and only moves when the numbers are hard to argue with. He has waited years on a single position before. Before Meyka, he ran a web hosting company and a mortgage lending platform, so he knows what a well-run business actually looks like under the hood. This article did not come from a news cycle. It came from someone who has been watching this space for a long time.
What brings you to Meyka?
Pick what interests you most and we will get you started.
I'm here to read news
Find more articles like this one
I'm here to research stocks
Ask Meyka Analyst about any stock
I'm here to track my Portfolio
Get daily updates and alerts (coming March 2026)