A total of 95,364 Bee Cheng Hiang members had their email addresses exposed after an employee used an AI tool to write code for a mass marketing email.
The incident happened in April 2026 and has been described by the Personal Data Protection Commission (PDPC) as the first AI-related data breach reported to it in Singapore.
Before you start side-eyeing the bak kwa, the issue was not that AI suddenly went rogue. PDPC attributed the breach to human error in how the email-sending code was developed.
Employee Used AI to Generate Python Script
According to reports citing PDPC, an employee of Bee Cheng Hiang Marketing used an AI tool to generate a Python script to send marketing emails.
The script was meant to send emails in batches of up to 1,000 recipients.
However, because of a configuration error, recipients’ email addresses were visible to other people in the same email batch.
In other words, the marketing email went out, but so did something that should not have gone out: the email addresses of other recipients.
PDPC said the employee had prompted the AI tool to write a programme to send a mass email using a local list in batches, but the prompt did not include specific instructions to conceal the email addresses of other recipients.
The commission said the breach was not caused by the AI tool malfunctioning.
95,364 Members Affected
Bee Cheng Hiang Marketing notified PDPC of the personal data breach on 27 April 2026.
The affected personal data comprised email addresses belonging to 95,364 Bee Cheng Hiang members.
After the company discovered and confirmed the error, it stopped the mass email distribution, corrected the code and notified the affected customers.
No other types of personal data were reported in the available public reports as being exposed.
PDPC Accepted a Voluntary Undertaking
PDPC accepted a voluntary undertaking from Bee Cheng Hiang Marketing on 2 September 2026.
A voluntary undertaking is a formal commitment by an organisation to take steps to improve its compliance with Singapore’s Personal Data Protection Act.
In this case, Bee Cheng Hiang Marketing is expected to strengthen its data protection practices following the incident.
The case is notable because it shows that using AI for routine office tasks does not remove the company’s responsibility for checking the output before deploying it.
Or in less atas terms: AI can help write the code, but someone still has to check whether the code is about to CC the whole kampung.
Why This Matters
This case comes as more companies use publicly available AI tools to write, automate and speed up work.
The problem is that AI-generated output can still contain mistakes, especially if the prompt is incomplete or if the code is not properly reviewed before use.
For businesses, the lesson is fairly clear: AI tools may save time, but staff still need proper checks when personal data is involved.
For customers, the exposed information here was email addresses. That may sound less sensitive than NRIC numbers or bank details, but email addresses can still be used in phishing attempts, spam or scams.
So if you are a Bee Cheng Hiang member and receive unusual emails, it would be wise to treat links and requests for personal information carefully.