An employee at Singapore food retailer Bee Cheng Hiang used generative AI to create code for a bulk marketing campaign, exposing the email addresses of more than 95,000 customers.
The incident is Singapore’s first reported AI-related data breach notified to the Personal Data Protection Commission (PDPC). The regulator said the AI tool itself did not malfunction. Instead, the employee’s prompt failed to tell the tool to hide recipients’ addresses, while weak testing and a lack of supervisory review allowed the faulty code to reach production.
AI-generated email code exposed 95,000 addresses
The breach occurred on April 25, when Bee Cheng Hiang used a program generated with the help of an AI tool to send marketing emails in batches of about 1,000 customers. Because the prompt did not specify that each recipient’s email address should remain hidden, customers could see other addresses included in the same batch. The company reported the breach to the PDPC two days later.
The Straits Times reported that the difference between the correct and faulty code came down to the placement of a few brackets, which changed how the program handled recipients. More than 95,000 email addresses were exposed, although no other personal information was involved and the PDPC found no evidence that the data was later misused.
Importantly, the exposed data was not generated, processed, or managed by AI. AI’s role was limited to helping write the code that caused the disclosure.
Testing failures mattered as much as the prompt
The employee tested the program before deployment, but only reviewed activity logs rather than opening an actual test email to see how recipients appeared.
Bee Cheng Hiang also relied on a single employee to develop and test the code without a supervisory review process or formal policies governing the use of generative AI for work. The PDPC attributed the incident to human error in developing the email distribution code rather than a failure of the AI system.
According to AsiaOne, Bee Cheng Hiang stopped the bulk email distribution after discovering the problem, fixed the code, and notified affected customers. The company has since introduced a requirement for at least two employees to review bulk email communications before they are sent.
The case shows why security teams should treat AI-generated code like any other untrusted software output. A program that appears to work can still expose personal data if developers validate logs without checking what end users will actually receive.
Singapore pushes stronger controls around AI-generated code
The PDPC accepted a voluntary undertaking from Bee Cheng Hiang to improve its compliance with Singapore’s Personal Data Protection Act. The undertaking was executed on Sept. 2, 2026.
Bee Cheng Hiang will introduce a framework for employee use of AI in coding, including independent technical reviews when AI-generated code handles personal data. Other measures include stronger software testing, dummy-account checks, a formal breach response process, staff training, and automated controls designed to block emails containing multiple addresses in a single recipient field.
Singapore’s PDPA allows penalties of up to S$1 million or 10% of an organization’s annual turnover in Singapore, whichever is higher.
Bloomberg, citing The Straits Times, reported that the case was the first AI-related breach notification received by Singapore’s privacy regulator and noted that Bee Cheng Hiang had never used AI in its business operations before the incident.
What the breach means for security teams across APAC
Singapore’s case is specific to its PDPA, but the security problem is relevant well beyond one jurisdiction.
Companies across APAC allowing employees to use generative AI for coding, automation, or data handling need controls around what happens after the AI produces an answer.
The PDPC recommended that organizations conduct data protection impact assessments before using AI tools in business processes. Bee Cheng Hiang’s remediation also provides a practical checklist for security teams:
- Require independent review of AI-generated code that touches personal data.
- Test actual outputs with dummy accounts instead of relying only on logs.
- Add automated safeguards that stop obvious privacy failures before deployment.
The breach did not require a sophisticated attack or an AI system behaving unexpectedly. A missing instruction, limited testing, and no second review were enough to expose tens of thousands of customer email addresses. For organizations adopting AI across APAC, keeping human review and security testing in the workflow remains essential.
For another recent breach involving exposed email data, read how the McKesson data leak included 6.4 million email addresses after an alleged $55.2 million extortion demand.





