95,364 Bee Cheng Hiang members' data exposed after employee used AI to send mass email - Mothership

Direct Source Verification: This story is aggregated from Mothership.sg (mothership.sg). Full reporting rights and copyright belong to the primary publisher.
The employee did not realise the error as no one reviewed the contents of the actual test email.

The employee did not realise the error as no one reviewed the contents of the actual test email.

An employee of Bee Cheng Hiang's marketing department mistakenly caused a personal data breach involving 95,364 of the company's members when they used an artificial intelligence (AI) tool to send mass marketing emails.

Only the members' email addresses were affected, according to the Personal Data Protection Commission (PDPC).

As the marketing email was sent in batches of 1,000, each affected member's email address was disclosed to up to 999 other recipients within the same batch, displayed in the "To" field of the emails.

Bee Cheng Hiang Marketing notified the PDPC of the incident, which happened on Apr. 25, two days later.

It is the first AI-related data breach in Singapore that the PDPC has been notified of.

The commission investigated the incident and conducted a voluntary undertaking from Bee Cheng Hiang on Sep. 2 to improve its compliance with the PDPC.

They found that the affected data was not managed, processed, or generated by any AI-powered operation or process.

There was also no evidence of further misuse of the affected personal data.

The incident was caused by a human error when the employee developed an email distribution Python script with an AI tool.

There was a configuration error in the generated script.

It was missing a bracket that caused all recipient email addresses within each batch to be grouped together as a single object in the “To” field, rather than as individual, isolated recipient entries.

PDPC underscored that the error was due not to a malfunction in the AI tool, but to the prompt given, as it did not include specific instructions to make sure other recipients' email addresses was not visible to each recipient.

The employee did not realise the error before deploying the script, PDPC said.

They tested it by checking activity logs without reviewing the contents of the actual test email.

The incident likely happened because Bee Cheng Hiang Marketing did not conduct sufficiently robust testing to check the email distribution script before it was deployed, according to the PDPC.

The company also did not have a review process for supervisory checks of the employee’s work, nor a governance framework or policies in place to guide employees on the use of generative AI tools for work.

It was the first time the company had attempted to incorporate AI tools in its business operations.

The PDPC advised organisations to take precautions before adopting AI tools to enhance their operational efficiency.

They should carry out appropriate data protection impact assessments, develop policies and processes for the AI use, and implement testing and review mechanisms.

This way, they can better ensure that their employees use AI tools responsibly and safeguard personal data.

Bee Cheng Hiang Marketing "took prompt remedial actions" when they discovered the error, PDPC said.

They included immediately halting the bulk marketing email distribution process to prevent further email activity, and rectifying the erroneous script.

The company also notified all affected members, and implemented double-verification checks by at least two staff for all bulk email communications before sending out.

As part of the voluntary undertaking, the company has taken and will take a few further steps to ensure data security, and the PDPC will verify their compliance.

Original Source
https://mothership.sg/2026/10/bee-cheng-hiang-members-data-breach-ai/
Visit Mothership.sg ↗
SHARE STORY:
𝕏 f in

Related Coverage in Business