< Back to all clusters
[TECHNOLOGY] · Singapore · 2 sources

started · updated

Bee Cheng Hiang suffers Singapore’s first AI-related data breach

Bee Cheng Hiang, a Singapore-based food products company, has experienced the nation’s first reported data breach linked to the use of generative artificial intelligence. The incident occurred on April 25, when an employee used an AI tool to assist in writing Python code for a mass marketing email campaign.

A coding error, caused by the incorrect placement of brackets in the AI-generated script, resulted in the email addresses of 95,364 customers being exposed. While the emails were sent in batches of approximately 1,000, the error allowed recipients within each batch to see the email addresses of others. The Personal Data Protection Commission (PDPC) noted that the breach was due to human error in prompting the AI and a lack of oversight, rather than a malfunction of the AI tool itself.

The exposed data was limited to email addresses, and there is currently no evidence that the information has been misused. In response, Bee Cheng Hiang has implemented new protocols, including a mandatory two-person verification process for mass emails and the establishment of a regulatory framework for AI usage. The PDPC has accepted a voluntary undertaking from the company to improve its software development and AI governance processes.

Entities

Bee Cheng Hiang · Personal Data Protection Commission