{
  "id": 11179156,
  "title": "95,364 Bee Cheng Hiang members' data exposed after employee used AI to send mass email",
  "url": "https://urgent.news/2026/10/01/95-364-bee-cheng-hiang-members-data-exposed-after-employee-used-ai-to",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-01T11:44:52.000Z",
  "source": {
    "name": "Mothership",
    "slug": "mothership",
    "url": "https://mothership.sg/2026/10/bee-cheng-hiang-members-data-breach-ai/"
  },
  "original_language": "en",
  "account": "An employee at Bee Cheng Hiang's marketing department inadvertently caused a personal data breach affecting 95,364 members. This occurred due to an AI tool being misused in sending mass marketing emails. The Personal Data Protection Commission (PDPC) reported that each member's email address was exposed to up to 999 other recipients within the same batch. The breach was identified on April 25, but the PDPC only became aware of it two days later. This marks the first AI-related data breach reported to the PDPC in Singapore.\n\nUpon investigation, the PDPC found that the issue stemmed from a human error involving a Python script created with an AI tool. The script's configuration error - the missing of a bracket - resulted in recipient email addresses being grouped together as a single object in the \"To\" field instead of being listed as individual recipients. The PDPC clarified that the error was not due to a malfunction in the AI tool, but rather due to the AI tool's prompt lacking specific instructions to prevent the exposure of other recipients' email addresses to each individual recipient. The employee, unaware of the error, proceeded to deploy the script.\n\nThe PDPC noted that the breach could have been avoided if Bee Cheng Hiang Marketing had implemented more rigorous testing and review processes for the email distribution script and for the use of generative AI tools. The company had not conducted sufficient testing before deploying the script and lacked a review process for supervisory checks of the employee's work. Additionally, there were no policies or procedures in place to guide employees on the responsible use of AI tools for work.\n\nIn response to the breach, Bee Cheng Hiang Marketing took immediate action. They halted the bulk email distribution to prevent further email activity and corrected the erroneous script. They also notified all affected members and introduced double-verification checks for all bulk email communications. As part of a voluntary undertaking, the company committed to further steps to ensure data security and the PDPC will verify their compliance.",
  "summary": "The employee did not realise the error as no one reviewed the contents of the actual test email.",
  "key_points": [
    "95,364 Bee Cheng Hiang members' data exposed in data breach",
    "Employee misused AI tool to send mass marketing emails",
    "PDPC reports first AI-related data breach in Singapore"
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}