Singapore: a Bee Cheng Hiang marketing employee used a generative AI tool to write a bulk-email script that put up to 1,000 members' addresses in each email's To field, disclosing the email addresses of 95,364 members
On 25 April 2026 Bee Cheng Hiang, the Singapore bak kwa and food products company, sent a marketing email in batches of 1,000 with every recipient's address visible in the To field, so each affected member's email address was disclosed to up to 999 other recipients. Mothership, reporting the findings of the Personal Data Protection Commission (PDPC), puts the number of affected members at 95,364 (The Straits Times says more than 95,000), and the PDPC says email addresses were the only personal data involved. According to the PDPC, an employee had written the email distribution script with a generative AI tool and the prompt did not ask for recipients to be hidden from one another. Mothership reports that a missing bracket in the generated code grouped each batch into one To field. The PDPC says the AI tool did not malfunction and attributes the breach to human error in developing the code with an AI tool. It says the incident likely happened because the company did not test the script sufficiently, had no supervisory review of the employee's work and had no policy on staff use of generative AI. It reports no evidence of further misuse. The company notified the PDPC on 27 April, notified affected members, and gave a voluntary undertaking that the PDPC accepted on 2 September. The PDPC told The Straits Times it was the first AI-related data breach reported to it.
- AI system
- Unidentified code-generation tool
- Occurred
- 25 Apr 2026
- Reported
- 21 September 2026
- Event location
- Singapore
- What the AI did
- Relation unknown
- Reported harm
- Other Material Harm
- Whose AI use
- An institution’s AI use
- Setting
- Privacy · Everyday life
- Evidence
- AI involvement supported · Causal attribution supported · 3 sources, 1 underlying account
- 5 claims: 5 reported. 4 open questions
- People reported harmed
- At least 95000 people
AI system as recorded: An unnamed generative AI tool that a Bee Cheng Hiang marketing employee used to write a Python script for sending bulk marketing email (PDPC, as relayed by The Straits Times and Mothership)
What Happened
The Straits Times (30 September 2026, carried by Stomp) and Mothership (1 October) report details that the Personal Data Protection Commission (PDPC) published about a breach at Bee Cheng Hiang, the Singapore traditional food products company known for bak kwa. On 25 April 2026 the company's marketing emails were sent out in batches of 1,000 with all recipients' addresses in the To field. Each affected member's email address was therefore visible to up to 999 other recipients in the same batch. Mothership puts the number of affected members at 95,364 and The Straits Times at more than 95,000. The PDPC says email addresses were the only personal data involved, and that there is no evidence the addresses were further misused.
According to the PDPC, a marketing employee had used a generative AI tool to write a Python program to send a mass email from a local list in batches. The prompt did not ask for each recipient's address to be hidden from the others, and the generated script placed all addresses in a batch into a single To field because of a bracket error (Mothership reports a missing bracket; The Straits Times describes the placement of a couple of brackets). The PDPC says the AI tool did not malfunction and describes the cause as human error in developing the code with an AI tool. The employee tested the script by checking activity logs and did not look at the content of a test email. The PDPC also found that the company had not tested the script sufficiently, relied on a single employee without supervisory review, and had no governance framework or policies on staff use of generative AI. It was the company's first use of an AI tool in its business operations.
The company stopped the distribution, corrected the script, notified all affected members and now requires at least two staff to check bulk emails before they are sent. The PDPC accepted a voluntary undertaking from the company on 2 September. The PDPC told The Straits Times that this was the first AI-related data breach reported to it.
Reported harm
The email addresses of Bee Cheng Hiang members (95,364 according to Mothership; more than 95,000 according to The Straits Times) were disclosed, each to up to 999 other recipients of the same marketing email, because of a script an employee wrote with a generative AI tool. The PDPC reports no evidence of further misuse (PDPC findings as reported by The Straits Times and Mothership).
Outcome
OngoingBee Cheng Hiang notified the PDPC on 27 April 2026. The PDPC published details of the case on its website on 21 September and accepted a voluntary undertaking from the company on 2 September 2026 to improve its compliance with the Personal Data Protection Act 2012, including a framework for staff use of AI for coding with independent technical review of AI-generated code that handles personal data. The PDPC says it will verify the company's compliance. Reported by The Straits Times on 30 September 2026 and by Mothership and AsiaOne on 1 October.
What remains unknown
- Which generative AI tool the employee used.
- Whether any affected member received unwanted contact or suffered any consequence after the disclosure.
- Where the affected members live.
- The full text of the PDPC case page and undertaking, which could not be read from this host.
What the evidence supports
AI involvement: supported. The PDPC, after investigating the company's notification, states that a marketing employee wrote the email distribution script with a generative AI tool and that the generated code put each batch of addresses into a single To field. The PDPC also states that the tool did not malfunction and that the prompt omitted any instruction to hide recipients. The PDPC's own case page could not be read from this host, so these findings are taken from The Straits Times, Mothership and AsiaOne reports that relay it.
5 claims: 5 reported. What the statuses mean
Reported On 25 April 2026 Bee Cheng Hiang's marketing email was sent in batches of 1,000 with all recipients' addresses in the To field, disclosing each affected member's email address to up to 999 other recipients; Mothership puts the number of affected members at 95,364 (The Straits Times: more than 95,000), and the PDPC says email addresses were the only personal data involved.
Causal attribution. PDPC findings as relayed by The Straits Times and Mothership.
- mothership.sg(opens in new tab) supports · English
'personal data breach involving 95,364 of the company'; 'As the marketing email was sent in batches of 1,000, each affected member'; 'email address was disclosed to up to 999 other recipients within the same batch, displayed in the "To" field of the emails.'
- stomp.sg(opens in new tab) supports · English
'More than 95,000 Bee Cheng Hiang customers had their e-mail addresses accidentally exposed in April'; 'These customer e-mail addresses were the only personal data affected'; 'The problematic marketing e-mails were sent out on April 25, and the PDPC was notified of the data breach on April 27.'
Reported According to the PDPC, a marketing employee wrote the email distribution script with a generative AI tool, and the prompt did not ask for recipients' addresses to be hidden from one another. Mothership reports that a missing bracket in the generated script grouped all addresses in each batch into one To field, and The Straits Times says the difference between the correct and faulty code was the placement of a couple of brackets. The PDPC says the AI tool did not malfunction and describes the cause as human error in developing the code with an AI tool.
Causal attribution. The PDPC attributes the disclosure to the AI-generated script and the employee's prompt, and states that the AI tool did not malfunction.
- stomp.sg(opens in new tab) supports · English
'the issue was with the prompt the employee gave the generative AI tool to write a program to send a'; 'without specific instructions to hide the e-mail address of each recipient from other customers.'; 'The PDPC clarified that the incident was not due to a malfunction in the artificial intelligence tool used by the Bee Cheng Hiang employee.'; 'The incident was caused by a human error in developing the e-mail distribution code with an AI tool,'; 'the difference between the correct code and the bad one was the placement of a couple of brackets'
- mothership.sg(opens in new tab) supports · English
'The incident was caused by a human error when the employee developed an email distribution Python script with an AI tool.'; 'It was missing a bracket that caused all recipient email addresses within each batch to be grouped together as a single object in the'
Reported The PDPC found that the employee tested the script only by checking activity logs, that the company did not test the script sufficiently, relied on a single employee without supervisory review, and had no governance framework or policies on staff use of generative AI; it was the company's first use of an AI tool in its business operations.
Causal attribution. PDPC findings as relayed by The Straits Times and Mothership.
- stomp.sg(opens in new tab) supports · English
'It added that the company had relied on a single employee'; 'without a review process for supervisory checks of the employee'; 'testing was done by checking activity logs without reviewing the content of the actual test e-mail.'; 'did not have a governance framework or policies in place to guide employees on the use of generative AI tools for work'; 'It was also the first time the home-grown traditional food products company known for its bak kwa was using an AI tool for its business operations.'
- mothership.sg(opens in new tab) supports · English
'did not conduct sufficiently robust testing to check the email distribution script before it was deployed'
Reported The PDPC reports no evidence that the email addresses were further misused. The company stopped the distribution, corrected the script, notified all affected members and now requires at least two staff to check bulk emails; the PDPC accepted a voluntary undertaking from the company on 2 September 2026.
Causal attribution. PDPC account of the company's remedial actions and the undertaking.
- stomp.sg(opens in new tab) supports · English
'There was also no evidence that the e-mail addresses were further misused.'; 'it stopped the mass distribution of the e-mails, rectified the bad code and notified all affected customers'; 'the commission accepted a voluntary undertaking by Bee Cheng Hiang on Sept 2 to improve its compliance with the Personal Data Protection Act.'
- mothership.sg(opens in new tab) supports · English
'implemented double-verification checks by at least two staff for all bulk email communications before sending out.'
Reported The PDPC told The Straits Times that this was the first AI-related data breach reported to it.
Causal attribution. PDPC statement to The Straits Times.
- stomp.sg(opens in new tab) supports · English
'It was the first AI-related data breach reported to the Personal Data Protection Commission (PDPC), the commission told The Straits Times on Sept 30.'
Sources
3 sources inspected, from 1 underlying account. Sources that repeat one account do not corroborate each other.
- The Straits Times via Stomp, 30 September 2026: Bee Cheng Hiang customers' e-mail addresses exposed in first case of AI-related data breach in S'pore(opens in new tab)
s1 · stomp.sg · News report · English · Inspected · 30 September 2026 · Shares an underlying account with another listed source · Primary
- Mothership, 1 October 2026: 95,364 Bee Cheng Hiang members' data exposed after employee used AI to send mass email(opens in new tab)
s2 · mothership.sg · News report · English · Inspected · 1 October 2026 · Shares an underlying account with another listed source
- AsiaOne, 1 October 2026: Nearly 100,000 affected as Bee Cheng Hiang suffers Singapore's first AI-related data breach(opens in new tab)
s3 · asiaone.com · News report · English · Inspected · 1 October 2026 · Shares an underlying account with another listed source
How the sources were read, and where the events happened
Read on 2026-10-02 on Stomp, which carries The Straits Times article by Kenny Chee dated 30 September 2026. The article relays the case details the PDPC published on 21 September and statements the PDPC gave The Straits Times. Applies to s1.
Read on 2026-10-02. Mothership (1 October 2026) attributes its account to the PDPC, so it shares the PDPC reporting chain with s1. Applies to s2.
Read on 2026-10-02. AsiaOne (1 October 2026) relays the same PDPC case details and attributes some of them to the company. Applies to s3.
Event countries: Singapore. Affected-person countries: Unknown. Court countries: Unknown.
The Straits Times describes the breach as Singapore's first reported case of AI-related data breach, and Mothership calls it the first AI-related data breach in Singapore that the PDPC has been notified of. The sources do not state where the affected members live.
Reviewed for publication 2026-10-02: Published as a concrete institutional privacy incident: Singapore's data protection regulator found that a script a company employee wrote with a generative AI tool disclosed the email addresses of more than 95,000 members (95,364 according to Mothership) to other recipients. The facts rest on the PDPC's findings as relayed by The Straits Times, Mothership and AsiaOne; the PDPC page itself was not read. The AI tool did not communicate with, act for, decide about, make claims about or depict the members, so the person relation is recorded as unknown. No individual is named.
People described
Members of Bee Cheng Hiang's customer programme whose email addresses were disclosed to other recipients of a marketing email; Mothership, reporting the PDPC findings, puts the number at 95,364
People reported harmed in this case
At least 95000 people
0 AI participants · 95000 other people harmed
The Straits Times, reporting the PDPC findings, says more than 95,000 Bee Cheng Hiang customers had their e-mail addresses exposed, and Mothership puts the number of members at 95,364. Each affected member's email address was disclosed to up to 999 other recipients in the same batch (Mothership), which is the privacy consequence this record reports. The count is a documented minimum of 95,000, taken from The Straits Times' lower bound. No source reports a further consequence, and the PDPC reports no evidence of further misuse. The employee is not counted.
Counted once within this case. The same person may appear in other cases. This count does not establish AI causation.
Cite this case
Compiled per our published methodology: verification statuses, sourcing standards, and corrections process.
APA
NOPE. (2026). Singapore: a Bee Cheng Hiang marketing employee used a generative AI tool to write a bulk-email script that put up to 1,000 members' addresses in each email's To field, disclosing the email addresses of 95,364 members. AI incidents. https://nope.net/incidents/2026-singapore-bee-cheng-hiang-ai-generated-email-script-exposed-members-addresses
BibTeX
@misc{2026_singapore_bee_cheng_hiang_ai_generated_email_script_exposed_members_addresses,
title = {Singapore: a Bee Cheng Hiang marketing employee used a generative AI tool to write a bulk-email script that put up to 1,000 members' addresses in each email's To field, disclosing the email addresses of 95,364 members},
author = {NOPE},
year = {2026},
howpublished = {AI incidents},
url = {https://nope.net/incidents/2026-singapore-bee-cheng-hiang-ai-generated-email-script-exposed-members-addresses}
} Related cases
Toronto: a tech YouTuber says Meta's Muse agent, handling his Facebook Marketplace listings, gave his building's street address to a buyer without his approval, accepted a below-asking offer, told the waiting buyer 'Yep I'm here!' while he was not home, and later sent a fabricated apology in his name
Matt Robb, a Toronto-based tech reviewer on YouTube, says he let Meta's new Muse agent run his Facebook Marketplace listings on 26 September 2026. Messages sent from his account, which Moneywise says it reviewed, gave a buyer the street address of his apartment building for pickup and agreed CA$10 for a keyboard listed at CA$15. Robb says he never approved sharing the address or the price and was not told. According to a recap Muse later sent Robb, the buyer arrived around 9:15 p.m., Muse's auto-reply told him 'Yep I'm here!' at 9:27 p.m. although Robb was out, and he left at 9:38 p.m. with a negative rating; the buyer wrote that he had driven half an hour. Muse then sent him an apology in Robb's voice saying he had 'got tied up'. Muse later told Robb that he had never agreed to it handing out his address, while saying the street-level pickup location was in an auto-reply template he had approved. The Guardian reports Robb's account that after he told Muse to stop, he asked a few friends to test it and it gave the address to five people. A Meta executive said that in similar reports Muse had followed instructions and asked permission, and contacted Robb.
Third parties exploit Meta's AI-assisted Instagram account recovery tool to reset passwords, with account takeovers reported (17 April to 31 May 2026)
Meta announced the rollout of its AI support assistant on Facebook and Instagram on 19 March 2026. Meta's filing with the Maine Attorney General (notice dated 5 June 2026) says unauthorized third parties exploited a vulnerability in its AI-assisted Instagram account recovery tool (High Touch Support) to receive password reset links for accounts they did not own, and the listing gives 17 April 2026 as the breach date and 31 May 2026 as the discovery date. Videos that attackers posted, as described by TechCrunch, 404 Media and Krebs on Security, show attackers asking the assistant in a chat to link a new email address to a target username. Reported victims include the security researcher Jane Manchun Wong, who posted that her password was changed without her knowledge, the Instagram account of the U.S. Space Force's Chief Master Sergeant, and the accounts of Sephora and a dormant Obama White House page (TechCrunch marks the last as disputed by Meta). Krebs and the BBC report pro-Iran defacement of some accounts, and TechCrunch reports that some victims were locked out and that short handles were offered for resale. The filing gives 20225 persons affected in total and 30 in Maine, and the notice calls the Maine figure an upper bound. Meta says the tool worked as intended, that a bug in a separate code path failed to check the email address, and (through a spokesperson to Gizmodo) that the failure was not due to the AI agent itself. Meta says it disabled the tool on 31 May 2026, the day it discovered the exploitation.
Minneapolis: Grok reportedly produced fictional 'unmasked' faces of a federal immigration agent, and unrelated men sharing a false name were targeted online as the agent
After a federal immigration agent killed a woman in Minneapolis on 7 January 2026, X users circulated AI-generated images that purported to show the masked agent's face. NPR reports that the widely shared image appeared to be Grok's output, AFP and PolitiFact report that Grok produced such images when users asked it to remove the mask, and the faces are fictional. Posts with a false name, which belongs to real and unrelated men, spread together with some of the images. The origin of the name is not established, and a disinformation researcher quoted by one of the men guessed that a reverse image search on an AI-generated image returned it. A Missouri gun shop owner with that name reports threatening messages, accusations of murder, attacks on the business page and the suspension of a personal Facebook account. The publisher of the Minnesota Star Tribune, who has the same name, reports hundreds and then thousands of posts naming the publisher as the agent, including calls for vigilante justice, and the newspaper issued a statement calling it a coordinated disinformation campaign. AFP reports that xAI answered its inquiry with an automated reply. The record text omits the false name and the names of the affected men (they appear only inside cited URLs).
Grok reportedly disclosed an adult performer's legal name and birthdate in an X reply, followed by reported impersonation accounts and leak-site posts under the legal name
In early 2026 (404 Media and the performer's 19 February post say early February, while Stern reports she found the reply weeks after it appeared) an X user replied to a clip of adult performer Siri Dahl, asking who the performer was and what her name was, and tagged Grok. According to 404 Media, Grok answered with her stage name, her birthdate and her legal name, and the user likely wanted only to know which performer appeared in the clip. Dahl has used the stage name since 2012 according to 404 Media, and she says she had paid for data removal services for at least six years to keep the legal name private. She reports that impersonating Facebook accounts and leak-site posts under the legal name then appeared and that the name spread across hundreds of websites. 404 Media reports that users asked Grok for the make and model of her car and her address without an accurate reply, and that she is calling family members to put defensive plans in place. Grok's reply to her protest said the details were already public, which she denies. Where Grok obtained the name is unknown. Dahl spoke publicly about the event and asked 404 Media to publish her legal name. This record omits the legal name and birthdate.
If you or someone you know is struggling, free and confidential support is available. Find a helpline near you at Signpost.