Nearly 100,000 affected as Bee Cheng Hiang suffers Singapore's first AI-related data breach


Nearly 100,000 Bee Cheng Hiang customers had their email addresses exposed after an employee used an AI tool to generate code for a mass marketing email.
The incident is reportedly Singapore's first AI-related data breach notified to the Personal Data Protection Commission (PDPC).
The incident took place on April 25. Bee Cheng Hiang notified the PDPC two days later.
PDPC Commission accepted a voluntary undertaking by Bee Cheng Hiang in September, to improve its compliance with the Personal Data Protection Act 2012.
The email was sent out in batches of about 1,000 customers, so recipients were able to see the email addresses of other people in the same batch.
Bee Cheng Hiang said the employee had used a generative AI tool to help create a programme for sending marketing emails from a local mailing list.
However, the instructions given to the AI did not specify that recipients' email addresses should be hidden from one another.
The resulting code therefore caused multiple customers' addresses to appear in the same email.
The PDPC said the incident was not caused by a malfunction in the AI tool, but by human error in developing the email distribution code.
The affected email addresses were the only personal data involved, and the PDPC said there was no evidence that they were subsequently misused.
The employee had tested the programme before it was deployed, but only checked activity logs instead of examining the content of an actual test email.
This meant the problem was not detected before the marketing emails were sent.
Bee Cheng Hiang, which is known for their bak kwa, stopped the bulk email distribution after discovering the issue, corrected the code and informed affected customers.
The company has since introduced a requirement for at least two employees to check all bulk email communications before they are sent, according to the PDPC.
The PDPC also noted that this was Bee Cheng Hiang's first attempt at incorporating AI tools into its business operations.
Following the incident, the company gave a voluntary undertaking to improve its compliance with the Personal Data Protection Act. The PDPC accepted the undertaking on Sept 2.
As part of the undertaking, Bee Cheng Hiang will establish a framework governing employees' use of AI for coding.
This includes requiring independent technical reviews of AI-generated code that involves personal data.
The company will also strengthen its software testing procedures, including testing emails using dummy accounts before deployment.
It plans to formalise its response to the incident into a data breach procedure, as well as introduce automated measures to prevent emails containing multiple addresses from being sent in a single email field.
The PDPC reportedly said organisations should conduct appropriate data protection impact assessments before adopting AI tools to improve business processes.
It also recommended that companies establish clear policies and processes, alongside testing and review mechanisms, to ensure employees use AI responsibly and protect personal data.
The case highlights that while AI may be used to assist with coding and other business functions, organisations remain responsible for checking how AI-generated outputs handle personal data before putting them into use.
[[nid:746208]]
asyiqin.nadzri@asiaone.com