{"meta":{"exportedAt":"2026-10-02T15:46:38.744Z","formatVersion":2,"selection":{"q":"pdpc","system":"","harm":"","context":"","country":"","role":"","relation":"","evidence":"","year":"","response":"","severity":"","verification":"","view":"incidents","sort":"added"},"totalIncidents":1,"coverage":{"cases":1,"countries":1,"languages":1,"unknownLocation":0,"locationPending":0,"unknownLanguage":0,"unknownDate":0,"lawsuits":0,"regulatory":1,"minors":0,"coreRelations":0,"contextualRelations":0,"mixedRelations":0,"unknownRelations":1,"relationPending":0,"relationUnknown":1},"countingNote":"Distinct public cases in this selection. People counts apply within individual cases only; cross-case person overlap has not been resolved. No population incidence estimate.","affectedCountNote":"Interpret person counts with affectedCountStatus and the reported effects. Unquantified zeros are placeholders, not a measured zero.","source":"AI incidents","publisher":"NOPE","url":"https://nope.net/incidents","license":"CC BY 4.0"},"incidents":[{"id":"2026-singapore-bee-cheng-hiang-ai-generated-email-script-exposed-members-addresses","caseFacts":{"claims":[{"id":"c1","status":"reported","evidence":[{"locator":"'personal data breach involving 95,364 of the company'; 'As the marketing email was sent in batches of 1,000, each affected member'; 'email address was disclosed to up to 999 other recipients within the same batch, displayed in the \"To\" field of the emails.'","relation":"supports","source_id":"s2"},{"locator":"'More than 95,000 Bee Cheng Hiang customers had their e-mail addresses accidentally exposed in April'; 'These customer e-mail addresses were the only personal data affected'; 'The problematic marketing e-mails were sent out on April 25, and the PDPC was notified of the data breach on April 27.'","relation":"supports","source_id":"s1"}],"assertion":"On 25 April 2026 Bee Cheng Hiang's marketing email was sent in batches of 1,000 with all recipients' addresses in the To field, disclosing each affected member's email address to up to 999 other recipients; Mothership puts the number of affected members at 95,364 (The Straits Times: more than 95,000), and the PDPC says email addresses were the only personal data involved.","causal_attribution":"PDPC findings as relayed by The Straits Times and Mothership."},{"id":"c2","status":"reported","evidence":[{"locator":"'the issue was with the prompt the employee gave the generative AI tool to write a program to send a'; 'without specific instructions to hide the e-mail address of each recipient from other customers.'; 'The PDPC clarified that the incident was not due to a malfunction in the artificial intelligence tool used by the Bee Cheng Hiang employee.'; 'The incident was caused by a human error in developing the e-mail distribution code with an AI tool,'; 'the difference between the correct code and the bad one was the placement of a couple of brackets'","relation":"supports","source_id":"s1"},{"locator":"'The incident was caused by a human error when the employee developed an email distribution Python script with an AI tool.'; 'It was missing a bracket that caused all recipient email addresses within each batch to be grouped together as a single object in the'","relation":"supports","source_id":"s2"}],"assertion":"According to the PDPC, a marketing employee wrote the email distribution script with a generative AI tool, and the prompt did not ask for recipients' addresses to be hidden from one another. Mothership reports that a missing bracket in the generated script grouped all addresses in each batch into one To field, and The Straits Times says the difference between the correct and faulty code was the placement of a couple of brackets. The PDPC says the AI tool did not malfunction and describes the cause as human error in developing the code with an AI tool.","causal_attribution":"The PDPC attributes the disclosure to the AI-generated script and the employee's prompt, and states that the AI tool did not malfunction."},{"id":"c3","status":"reported","evidence":[{"locator":"'It added that the company had relied on a single employee'; 'without a review process for supervisory checks of the employee'; 'testing was done by checking activity logs without reviewing the content of the actual test e-mail.'; 'did not have a governance framework or policies in place to guide employees on the use of generative AI tools for work'; 'It was also the first time the home-grown traditional food products company known for its bak kwa was using an AI tool for its business operations.'","relation":"supports","source_id":"s1"},{"locator":"'did not conduct sufficiently robust testing to check the email distribution script before it was deployed'","relation":"supports","source_id":"s2"}],"assertion":"The PDPC found that the employee tested the script only by checking activity logs, that the company did not test the script sufficiently, relied on a single employee without supervisory review, and had no governance framework or policies on staff use of generative AI; it was the company's first use of an AI tool in its business operations.","causal_attribution":"PDPC findings as relayed by The Straits Times and Mothership."},{"id":"c4","status":"reported","evidence":[{"locator":"'There was also no evidence that the e-mail addresses were further misused.'; 'it stopped the mass distribution of the e-mails, rectified the bad code and notified all affected customers'; 'the commission accepted a voluntary undertaking by Bee Cheng Hiang on Sept 2 to improve its compliance with the Personal Data Protection Act.'","relation":"supports","source_id":"s1"},{"locator":"'implemented double-verification checks by at least two staff for all bulk email communications before sending out.'","relation":"supports","source_id":"s2"}],"assertion":"The PDPC reports no evidence that the email addresses were further misused. The company stopped the distribution, corrected the script, notified all affected members and now requires at least two staff to check bulk emails; the PDPC accepted a voluntary undertaking from the company on 2 September 2026.","causal_attribution":"PDPC account of the company's remedial actions and the undertaking."},{"id":"c5","status":"reported","evidence":[{"locator":"'It was the first AI-related data breach reported to the Personal Data Protection Commission (PDPC), the commission told The Straits Times on Sept 30.'","relation":"supports","source_id":"s1"}],"assertion":"The PDPC told The Straits Times that this was the first AI-related data breach reported to it.","causal_attribution":"PDPC statement to The Straits Times."}],"effects":[{"label":"the email addresses of 95,364 members were each disclosed to up to 999 other recipients of a marketing email","claim_id":"c1","direction":"negative"}],"sources":[{"id":"s1","url":"https://www.stomp.sg/trending-now/bee-cheng-hiang-customers-e-mail-addresses-exposed-first-case-ai-related-data-breach-spore","kind":"news_report","access":"read","language":"en","translation_note":"Read on 2026-10-02 on Stomp, which carries The Straits Times article by Kenny Chee dated 30 September 2026. The article relays the case details the PDPC published on 21 September and statements the PDPC gave The Straits Times.","independence_group":"pdpc-bee-cheng-hiang"},{"id":"s2","url":"https://mothership.sg/2026/10/bee-cheng-hiang-members-data-breach-ai/","kind":"news_report","access":"read","language":"en","translation_note":"Read on 2026-10-02. Mothership (1 October 2026) attributes its account to the PDPC, so it shares the PDPC reporting chain with s1.","independence_group":"pdpc-bee-cheng-hiang"},{"id":"s3","url":"https://www.asiaone.com/singapore/bee-cheng-hiang-customers-email-addresses-exposed-ai-generated-code-breach","kind":"news_report","access":"read","language":"en","translation_note":"Read on 2026-10-02. AsiaOne (1 October 2026) relays the same PDPC case details and attributes some of them to the company.","independence_group":"pdpc-bee-cheng-hiang"}],"version":1,"ai_roles":["institutional_use"],"contexts":["privacy","everyday_life"],"unknowns":["Which generative AI tool the employee used.","Whether any affected member received unwanted contact or suffered any consequence after the disclosure.","Where the affected members live.","The full text of the PDPC case page and undertaking, which could not be read from this host."],"geography":{"basis":"The Straits Times describes the breach as Singapore's first reported case of AI-related data breach, and Mothership calls it the first AI-related data breach in Singapore that the PDPC has been notified of. The sources do not state where the affected members live.","court_countries":[],"event_countries":["SG"],"affected_person_countries":[]},"publication":{"basis":"Published as a concrete institutional privacy incident: Singapore's data protection regulator found that a script a company employee wrote with a generative AI tool disclosed the email addresses of more than 95,000 members (95,364 according to Mothership) to other recipients. The facts rest on the PDPC's findings as relayed by The Straits Times, Mothership and AsiaOne; the PDPC page itself was not read. The AI tool did not communicate with, act for, decide about, make claims about or depict the members, so the person relation is recorded as unknown. No individual is named.","reviewed_on":"2026-10-02"},"ai_involvement":{"basis":"The PDPC, after investigating the company's notification, states that a marketing employee wrote the email distribution script with a generative AI tool and that the generated code put each batch of addresses into a single To field. The PDPC also states that the tool did not malfunction and that the prompt omitted any instruction to hide recipients. The PDPC's own case page could not be read from this host, so these findings are taken from The Straits Times, Mothership and AsiaOne reports that relay it.","status":"supported"},"person_relations":["unknown"]},"name":"Singapore: a Bee Cheng Hiang marketing employee used a generative AI tool to write a bulk-email script that put up to 1,000 members' addresses in each email's To field, disclosing the email addresses of 95,364 members","summary":"On 25 April 2026 Bee Cheng Hiang, the Singapore bak kwa and food products company, sent a marketing email in batches of 1,000 with every recipient's address visible in the To field, so each affected member's email address was disclosed to up to 999 other recipients. Mothership, reporting the findings of the Personal Data Protection Commission (PDPC), puts the number of affected members at 95,364 (The Straits Times says more than 95,000), and the PDPC says email addresses were the only personal data involved. According to the PDPC, an employee had written the email distribution script with a generative AI tool and the prompt did not ask for recipients to be hidden from one another. Mothership reports that a missing bracket in the generated code grouped each batch into one To field. The PDPC says the AI tool did not malfunction and attributes the breach to human error in developing the code with an AI tool. It says the incident likely happened because the company did not test the script sufficiently, had no supervisory review of the employee's work and had no policy on staff use of generative AI. It reports no evidence of further misuse. The company notified the PDPC on 27 April, notified affected members, and gave a voluntary undertaking that the PDPC accepted on 2 September. The PDPC told The Straits Times it was the first AI-related data breach reported to it.","incidentDate":"2026-04-25","incidentKind":"single_event","incidentDatePrecision":"day","exposurePattern":"unknown","reportedDate":"2026-09-21","aiSystem":"An unnamed generative AI tool that a Bee Cheng Hiang marketing employee used to write a Python script for sending bulk marketing email (PDPC, as relayed by The Straits Times and Mothership)","aiProduct":"Unidentified code-generation tool","severity":"low","verificationStatus":"credible","harmCategories":[],"harmOutcomes":["other_material_harm"],"harmOutcomeSummary":"The email addresses of Bee Cheng Hiang members (95,364 according to Mothership; more than 95,000 according to The Straits Times) were disclosed, each to up to 999 other recipients of the same marketing email, because of a script an employee wrote with a generative AI tool. The PDPC reports no evidence of further misuse (PDPC findings as reported by The Straits Times and Mothership).","frameworkFacets":[],"causationStatus":"supported","participantUsersAffectedMin":0,"otherPeopleHarmedMin":95000,"affectedCountStatus":"documented_minimum","affectedCountEvidence":"The Straits Times, reporting the PDPC findings, says more than 95,000 Bee Cheng Hiang customers had their e-mail addresses exposed, and Mothership puts the number of members at 95,364. Each affected member's email address was disclosed to up to 999 other recipients in the same batch (Mothership), which is the privacy consequence this record reports. The count is a documented minimum of 95,000, taken from The Straits Times' lower bound. No source reports a further consequence, and the PDPC reports no evidence of further misuse. The employee is not counted.","victimAgeRange":"unknown","jurisdiction":"SG","platformType":"assistant","outcomeType":"regulatory_action","outcomeStatus":"ongoing","primarySourceUrl":"https://www.stomp.sg/trending-now/bee-cheng-hiang-customers-e-mail-addresses-exposed-first-case-ai-related-data-breach-spore","primarySourceLabel":"The Straits Times via Stomp, 30 September 2026: Bee Cheng Hiang customers' e-mail addresses exposed in first case of AI-related data breach in S'pore","firstPublishedAt":"2026-10-02T03:15:09.888989+00:00","updatedAt":"2026-10-02T03:15:09.888989+00:00","scopeVersion":"facts-v3","tags":["singapore","pdpc","data-breach","personal-data","ai-generated-code","email","institutional-use"]}]}