Skip to content
Security & Trust

First AI-related breach reported to Singapore's regulator: a missing instruction

The AI tool worked as asked. Bee Cheng Hiang's gap was in the request and in the review of its output.

W
WebPulse Newsroom
AI-assisted · 4 min read
Share on X LinkedIn
First AI-related breach reported to Singapore's regulator: a missing instruction

AI-generated image for WebPulse. About our images

In brief
  • Singapore's PDPC says an AI-written email script exposed customer addresses at Bee Cheng Hiang. The tool did not malfunction. The instructions and the code checks were the problem.
  • The case shows that AI-generated code moves the risk to the request and the review. Testing logs instead of a real email let the error pass.
  • Leaders should ask who reviews AI-written code, what the review must show, and whether policy covers employee use of generative AI.

A tool that does exactly what you ask can still cause a breach. That is the lesson from a case in Singapore. The risk did not sit in the software. It sat in the gap between what a person meant and what a person typed.

What happened

Singapore's Personal Data Protection Commission (PDPC) traced the breach to April 25. On that day, an employee at Bee Cheng Hiang used a generative AI tool to write a Python script for marketing emails. The request was for a program to send a "mass email using a local list" in batches.

The script sent each message to about 1,000 customers at once. Everyone in a batch could see the other addresses. That meant each address was open to as many as 999 other customers.

On Sept. 30, the regulator described the case to The Straits Times as the first AI-related data breach it had received a report of. It said only email addresses were exposed. It also said it had no evidence of later misuse.

Up to 999
Other customers who could see one address
Source: Singapore PDPC, via VnExpress International (October 4, 2026)

How the mistake worked

The employee never told the AI to keep recipients hidden from each other. So the tool did what the request literally said. It sent mail in batches from a list.

Email has a hidden-recipient option, known as blind copy. Code that leaves it out shows every address to the whole batch. The source does not say which field the script used. Blind copy is the general safeguard, not a confirmed detail of this case.

The mechanism is plain. A person asks for a result and leaves out a safeguard that seems obvious to them. A human colleague might have asked about it. Here, the request did not include it, and the tool did not add it.

The PDPC was direct on this point. The AI tool had not malfunctioned. The error came from the instructions given to it and from weak checks of the code before use.

About 1,000
Customers per email batch
Source: Singapore PDPC, via VnExpress International (October 4, 2026)

The check that missed it

Testing did happen. The employee looked at activity logs. But the employee did not open an actual test email. A test email would have shown the visible addresses at once.

This is a quiet failure in many reviews. Logs show that a program ran. They do not show what a customer would see. The PDPC found that the company had not tested the AI-generated code enough. It also found no supervisory checks and no policies on staff use of generative AI.

What it means for leaders

The thesis here is simple. AI makes writing code cheap, so the control that matters moves to the request and the review. The source does not say how experienced the employee was. But anyone can now generate a working script without a software team's review habits.

That is where AI multiplies risk in this case. It did not add a new attack. It let a routine task reach customers without the checks that usually surround code. A vague request and a thin test were enough.

The company's fix is modest and clear. After finding the breach, Bee Cheng Hiang stopped the campaign, corrected the code and told affected customers. Bulk emails now need sign-off from two or more employees before sending.

At least 2
Employees now required to verify bulk emails
Source: Singapore PDPC, via VnExpress International (October 4, 2026)

Channel News Asia reported that the regulator took a voluntary undertaking from the firm on Sept. 2. In it, the company committed to improve its compliance with the data protection law. The PDPC said firms adopting AI tools should first run data protection assessments. They should also put policies, testing and review procedures in place. Under Singapore's Personal Data Protection Act, fines can reach S$1 million (US$780,000) or 10% of annual turnover in Singapore.

Questions to put to your team

First, who in the company can use AI to write code that touches customer data? Could your leadership answer that today? Second, is there a written policy for that use?

Third, what must a reviewer see before AI-written code goes live? For anything that sends messages, the answer should include a real sample of the output, not only logs. Fourth, do bulk sends to customers need a second person, as Bee Cheng Hiang now requires?

This is one case, and the exposure was limited to email addresses. It still shows how a small gap in a request can reach up to 1,000 recipients per email. The tool did what it was told. The company has to be sure it told it enough.

Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: VnExpress International.

Share this insight