{
  "id": 10908629,
  "title": "Bad AI prompt exposes Bee Cheng Hiang customers’ e-mail addresses in first case of AI-related data breach",
  "url": "https://urgent.news/2026/09/30/bad-ai-prompt-exposes-bee-cheng-hiang-customers-e-mail-addresses-in",
  "topic": "ai",
  "section": "AI",
  "published": "2026-09-30T09:40:00.000Z",
  "source": {
    "name": "Straits Times",
    "slug": "straits-times",
    "url": "https://www.straitstimes.com/tech/bad-ai-prompt-exposes-bee-cheng-hiang-customers-e-mail-addresses-in-first-case-of-ai-related-data"
  },
  "original_language": "en",
  "account": "In a rare case of AI-related data breach, over 95,000 customers' email addresses of Bee Cheng Hiang were exposed in April after an employee used a bad prompt in an AI tool. This marked Singapore's first reported incident of data breach due to AI. The poorly formed prompt resulted in code that sent out marketing emails displaying all recipients' addresses. Bee Cheng Hiang, known for its traditional food products, was the first to utilize an AI tool for business operations. The company's marketing emails were dispatched in batches of 1,000 customers. The customers' email addresses were the only personal data affected and were not managed or generated by any AI-powered operation. There was no evidence of misuse of the email addresses. The Personal Data Protection Commission (PDPC) clarified that the cause was not a malfunction in the AI tool, but rather a human error in the prompt given to the generative AI tool. The PDPC reported that the incident was due to a lack of robust testing of the email distribution code, reliance on a single employee without a review process, and the absence of policies and governance frameworks for AI tool use. The company rectified the error, stopped mass distribution, and notified all affected customers. Since then, Bee Cheng Hiang has introduced double-verification checks for all bulk email communications and incorporated a framework for responsible AI tool usage. The PDPC accepted a voluntary undertaking from Bee Cheng Hiang to enhance its compliance with the Personal Data Protection Act, which carries penalties up to $1 million or 10% of the organization's annual turnover.",
  "summary": "It was also the first time the company known for its bak kwa was using an AI tool for its business operations.",
  "key_points": [
    "Over 95,000 Bee Cheng Hiang customers' email addresses exposed in April",
    "Bad AI prompt caused marketing emails to display recipients' addresses",
    "Company rectified error, introduced double-verification checks for emails"
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 2,
    "also_reported_by": [
      {
        "outlet": "The Business Times - Singapore",
        "title": "Bee Cheng Hiang customers’ e-mail addresses exposed in Singapore’s first case of AI-related data breach",
        "url": "https://urgent.news/2026/09/30/bee-cheng-hiang-customers-e-mail-addresses-exposed-in-singapores",
        "published": "2026-09-30T10:30:08.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}