Bee Cheng Hiang customers’ e-mail addresses exposed in Singapore’s first case of AI-related data breach
There is no evidence of further misuse, says the Personal Data Protection Commission
Over 95,000 customers of Bee Cheng Hiang had their email addresses exposed in Singapore's first instance of an AI-related data breach, according to the Personal Data Protection Commission (PDPC). The incident occurred in April after an employee used an incorrect prompt in an AI tool, resulting in the generation of marketing emails with visible recipient addresses.
This was the first reported AI-related data breach to the PDPC, and the first time the traditional food company had used an AI tool for business operations. The exposed email addresses were the only personal data affected and were not managed, processed, or generated by any AI-powered operation or process. The PDPC clarified that the incident was due to a human error in developing the email distribution code with the AI tool, not a malfunction in the tool itself.
The commission recommended that organizations conduct appropriate data protection impact assessments, develop policies, and implement testing and review mechanisms to ensure responsible AI tool usage and safeguard personal data. Bee Cheng Hiang has since implemented double-verification checks for all bulk email communications and will establish a framework to govern the use of AI for coding.
Written by urgent.news from The Business Times - Companies & Markets's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.