Urgent.News

What's breaking now, across thousands of outlets.

Tech

95,364 Bee Cheng Hiang members' data exposed after employee used AI to send mass email

The employee did not realise the error as no one reviewed the contents of the actual test email.

95,364 Bee Cheng Hiang members' data exposed after employee used AI to send mass email

An employee at Bee Cheng Hiang's marketing department inadvertently caused a personal data breach affecting 95,364 members. This occurred due to an AI tool being misused in sending mass marketing emails. The Personal Data Protection Commission (PDPC) reported that each member's email address was exposed to up to 999 other recipients within the same batch. The breach was identified on April 25, but the PDPC only became aware of it two days later. This marks the first AI-related data breach reported to the PDPC in Singapore.

Upon investigation, the PDPC found that the issue stemmed from a human error involving a Python script created with an AI tool. The script's configuration error - the missing of a bracket - resulted in recipient email addresses being grouped together as a single object in the "To" field instead of being listed as individual recipients.

The PDPC clarified that the error was not due to a malfunction in the AI tool, but rather due to the AI tool's prompt lacking specific instructions to prevent the exposure of other recipients' email addresses to each individual recipient. The employee, unaware of the error, proceeded to deploy the script.

The PDPC noted that the breach could have been avoided if Bee Cheng Hiang Marketing had implemented more rigorous testing and review processes for the email distribution script and for the use of generative AI tools. The company had not conducted sufficient testing before deploying the script and lacked a review process for supervisory checks of the employee's work. Additionally, there were no policies or procedures in place to guide employees on the responsible use of AI tools for work.

In response to the breach, Bee Cheng Hiang Marketing took immediate action. They halted the bulk email distribution to prevent further email activity and corrected the erroneous script. They also notified all affected members and introduced double-verification checks for all bulk email communications. As part of a voluntary undertaking, the company committed to further steps to ensure data security and the PDPC will verify their compliance.

Written by urgent.news from Mothership's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at mothership.sg →

More in Tech

More from Thursday 1 October →