AI Data: A routine marketing email turned into a major data-protection incident after an employee at Singaporean food company Bee Cheng Hiang used a generative AI tool to help create code for sending bulk emails.
The incident exposed the email addresses of 95,364 customers. Singapore’s Personal AI Data Protection Commission, or PDPC, described it as the first AI-related data breach notified to the regulator.
The breach happened on April 25, 2026, and the company notified the PDPC two days later.
The important detail is easy to miss. The AI tool did not directly process the customers’ email addresses.
The problem arose because an employee used AI to generate an email-distribution script, the script contained an error, and the company’s testing process failed to detect it before deployment.
This distinction matters because it changes the lesson from “AI leaked data” to something more practical: AI-generated code still needs the same security review as human-written code.
What Happened in the Bee Cheng Hiang Data Breach?
The employee used a generative AI tool to help write a Python program for sending marketing emails from a local mailing list.
The emails were distributed in batches of about 1,000 recipients.
A mistake in the generated code caused the addresses of recipients in each batch to appear together in the email’s recipient field.
As a result, customers receiving the same marketing message were able to see the email addresses of other customers in that batch. A total of 95,364 email addresses were affected.
The PDPC said the incident resulted from human error in developing the email-distribution code with an AI tool. It specifically said the incident was not caused by an AI malfunction.
The employee had tested the program before deployment, but the testing focused on activity logs rather than checking the contents of an actual test email.
That meant the company confirmed that the program was sending messages without confirming whether the messages were being addressed correctly.
Why Did Bee Cheng Hiang’s AI-Generated Code Fail?
The technical failure was small, but its impact was large.
According to reports based on the PDPC findings, the difference between the faulty and intended code involved the placement of brackets. That small programming mistake changed how the recipient list was handled.
The larger failure was procedural.
Bee Cheng Hiang did not have a formal review process for the employee’s work. It also lacked a governance framework for employees using generative AI tools for business tasks.
The employee therefore had several layers of responsibility concentrated in one workflow:
Writing or generating the code.
Testing the code.
Deciding whether the test was sufficient.
Deploying the code.
Sending a large customer communication.
A stronger development process would separate at least some of these responsibilities.
The case shows why AI-assisted coding creates a particular security problem. The code might look professional and execute successfully while still producing the wrong result.
For an email system, “the program ran” is not the same as “the program protected customer information.”
What Personal Data Was Exposed?

The affected information consisted of customer email addresses.
The PDPC said the email addresses were the only personal data affected.
It also said the information was not managed, processed or generated by an AI-powered operation or process. There was no evidence of further misuse of the exposed addresses.
Email addresses are less sensitive than passwords, financial information or medical records, but they still have security value.
An exposed email address gives scammers another piece of information for targeted phishing, spam and impersonation attempts.
For affected customers, the practical risk is therefore less about the original marketing email itself and more about what someone might attempt afterward.
Why Is This Called an Data Breach?
An AI data breach does not necessarily mean an AI system directly stole or exposed personal information.
The term describes a data-security incident connected to the use of an AI system.
In the Bee Cheng Hiang case, AI entered the workflow through software development. The employee used an AI tool to generate code. The generated code then contributed to the disclosure of customer email addresses.
This is an important distinction.
The AI model did not independently access the customer database and publish the information.
Instead, AI-assisted code became part of a system handling personal data.
That creates a new category of operational risk. Employees might use AI for programming, spreadsheets, database queries, automation, email campaigns or internal tools without recognising the security implications of the resulting output.
The PDPC’s response reflects this broader concern. It urged organisations adopting AI tools to conduct data-protection impact assessments, establish policies and processes, and introduce testing and review mechanisms.
Will ChatGPT Leak My Data?
The Bee Cheng Hiang incident does not establish that ChatGPT or another AI chatbot will automatically leak a user’s information.
The important issue is how an organisation uses an AI service and what information employees place into it.
OpenAI states that personal ChatGPT users have data controls for model improvement.
Users can turn off “Improve the model for everyone,” while Temporary Chat is not used to improve OpenAI models while it remains temporary.
Temporary chats also do not appear in chat history, although OpenAI states it may retain a copy for up to 30 days for safety purposes.
OpenAI also states that business products such as ChatGPT Business, ChatGPT Enterprise and the API do not use inputs and outputs to improve models by default.
For users, the practical rule is simple: avoid entering passwords, payment credentials, confidential customer databases or other sensitive information into an AI service unless your organisation has approved the workflow and understands the applicable data controls.
The Bee Cheng Hiang case also shows why privacy risk exists even when sensitive data never enters the AI model itself. An AI-generated script still needs human review before it interacts with personal information.
What Is the Biggest Data Breach in the World?
There is no single answer unless “biggest” refers to a specific measurement, such as accounts affected, records exposed or people affected.
Yahoo’s 2013 breach is frequently cited among the largest breaches by number of affected accounts. Yahoo initially disclosed that more than one billion accounts were affected, then said in 2017 that all of the approximately three billion accounts existing at the time had been affected by the 2013 theft.
The Bee Cheng Hiang incident is far smaller by volume.
Its significance comes from another measurement: it represents Singapore’s first AI-related data breach notified to the PDPC.
That distinction matters. Cybersecurity incidents are not important only because of how many records they expose. The method behind a breach often provides an early warning about risks other organisations are beginning to face.
How Did SingHealth Get Hacked?
The SingHealth incident was fundamentally different from the Bee Cheng Hiang case.
In 2018, attackers carried out a targeted cyberattack against SingHealth’s patient database. About 1.5 million patients had their personal particulars illegally accessed and copied, while outpatient medication records for about 160,000 patients were also exfiltrated.
Singapore’s authorities said the attackers gained access through a front-end workstation and later obtained privileged account credentials that allowed access to the database.
The SingHealth attack involved deliberate intrusion by attackers.
The Bee Cheng Hiang incident involved an employee using AI-assisted code for a legitimate business task.
Both incidents demonstrate the importance of access controls, monitoring and testing, but they represent different threat models.
One involved a targeted cyberattack.
The other involved an internal process failure.
Why Did the Bee Cheng Hiang Breach Happen?
The PDPC findings point to several connected failures.
First, the AI prompt did not specify the required privacy behaviour for individual recipients.
Second, the generated code was not independently reviewed.
Third, testing relied on activity logs instead of the actual email output.
Fourth, the organisation lacked formal policies governing employees’ use of generative AI.
Fifth, a single employee handled too much of the development and verification process.
This is why blaming the AI alone misses the main security lesson.
A human selected the tool.
A human wrote the prompt.
A human accepted the generated code.
A human tested the program.
A human deployed it.
The organisation’s process failed to place sufficient controls between those steps.
What Did Bee Cheng Hiang Do After the Breach?

After discovering the problem, Bee Cheng Hiang stopped the bulk email distribution process, corrected the faulty code and notified affected customers.
The company also introduced a requirement for at least two employees to verify bulk email communications before sending them.
The PDPC accepted a voluntary undertaking from Bee Cheng Hiang to strengthen compliance with Singapore’s Personal Data Protection Act.
The company’s planned improvements include independent technical review of AI-generated code involving personal data, stronger software security testing, dummy-account testing for emails, a formal data-breach procedure and automated controls designed to prevent multiple email addresses from being placed into a single recipient field.
What This AI Breach Means for Companies
The biggest lesson is operational.
Companies adopting AI need to treat AI-generated output as untrusted until it passes normal verification.
For software development, this means code review.
For marketing, it means test emails.
For databases, it means access controls and test environments.
For spreadsheets, it means checking formulas and outputs.
For customer service, it means reviewing AI-generated responses before sensitive information is disclosed.
The technology does not remove the organisation’s responsibility for the final action.
The PDPC has also highlighted the wider risk of “Shadow AI,” where employees independently introduce AI tools into workplace processes without clear organisational controls. Such use creates uncertainty around what data enters an AI service, where information flows and who is responsible for reviewing the output.
The Future Risk Is AI-Assisted Automation
The Bee Cheng Hiang incident points toward a broader issue as companies give AI more control over business workflows.
Generating an email draft is one thing.
Generating the code that sends 100,000 emails is another.
The same distinction applies to AI-generated database queries, financial automation, customer-data processing and software deployments.
As AI moves from producing text into executing business operations, the consequences of a small mistake increase.
That means future AI governance will need to focus less on whether employees are “allowed to use AI” and more on what AI-generated output is permitted to do.
A low-risk AI-generated marketing headline requires limited review.
AI-generated code connected to personal data requires technical review, controlled testing and human approval before deployment.
The Bee Cheng Hiang case provides a clear example of why those controls matter.
What Should Customers Do If Their Email Address Was Exposed?
Customers affected by the incident should remain alert for unusual emails, especially messages pretending to come from Bee Cheng Hiang or another company.
Do not enter passwords or payment information through unexpected email links.
Check the sender address carefully.
Avoid opening suspicious attachments.
Use the company’s official website or app instead of following an unexpected link in an email.
The PDPC said there was no evidence of further misuse of the exposed addresses, but exposed contact information still deserves caution.
The Bigger Story Behind the Bee Cheng Hiang AI Breach
This incident is not evidence that AI independently decided to expose customer information.
It is evidence of something more practical.
AI-generated software needs human oversight, especially when the software handles personal data.
The mistake itself was small. The affected customer list was not.
That gap between a tiny technical error and a large real-world consequence is where AI governance becomes important.
For companies, the lesson is straightforward: if AI-generated code touches personal data, review it like production software, test the actual output, and require independent approval before deployment.
For customers, the lesson is equally practical: an email address is personal data, and unexpected follow-up messages deserve scrutiny.
The Bee Cheng Hiang case is therefore less about whether AI is safe or unsafe. It is about whether organisations build enough control around AI-assisted work before giving generated output access to real customers and real data.
























Leave a Reply