---
title: "Bee Cheng Hiang Hit by Singapore’s First AI-Related Breach"
date: 2026-09-30
author: "Sofia Ramirez"
featured_image: "https://sqmagazine.co.uk/wp-content/uploads/2026/09/bee-chiang-hiang-data-breach.jpg"
categories:
  - name: "Cybersecurity"
    url: "/cybersecurity.md"
tags:
  - name: "News"
    url: "/tag/news.md"
---

# Bee Cheng Hiang Hit by Singapore’s First AI-Related Breach

Singapore’s Personal Data Protection Commission (PDPC) said on September 30, 2026 that a Bee Cheng Hiang email exposed 95,364 customers’ addresses to other recipients. It is the first AI-related data breach notified to the regulator.

## The Brief

- Bee Cheng Hiang, a Singapore maker of Chinese-style pork jerky, sent the April email using code an AI tool wrote.
- The employee asked for a batch email program but did not specifically tell the AI tool to hide recipients’ addresses.
- The PDPC accepted a voluntary undertaking from the company to improve its compliance with the Personal Data Protection Act.
- Bee Cheng Hiang now requires at least **2** staff members to verify all bulk email communications.

## One missing instruction exposed the list

The employee asked the AI tool to generate a Python script that would send a marketing email to a local mailing list in batches. The prompt left out any instruction to hide each recipient’s address from the others. The code the tool wrote left every address visible to everyone on the send, the PDPC said.

Testing missed it. The employee checked activity logs and never reviewed the contents of an actual test email, so the script went live with the flaw intact.

The PDPC said it found no evidence of further misuse. It added that no AI-powered process managed, processed or generated the affected data, so the AI tool’s job was writing the script.

> Bee Cheng Hiang customers’ e-mail addresses exposed in first case of AI-related data breach in S’pore <https://t.co/WEZClS9x48>
> 
> — The Straits Times (@straits\_times) [September 30, 2026](https://x.com/straits_times/status/2105233913220133142?ref_src=twsrc%5Etfw)

 ## The PDPC puts the failure on the prompt and the test

The PDPC said the incident was “**not a malfunction in the AI tool**” in a statement posted to its website on September 21. It traced the error to the employee’s prompt and called it human error in building the email code. The regulator also noted that the project was Bee Cheng Hiang’s first attempt at bringing AI tools into its business operations.

The PDPC’s advice to other organizations is to assess data protection impact before adopting [AI tools](https://sqmagazine.co.uk/ai-tools-usage-statistics/). Companies should then set policies and processes and put testing and review in place, so staff use the tools responsibly.

Bee Cheng Hiang took these steps after the error, the regulator said:

- **It halted the bulk marketing email process at once.**
- **It corrected the faulty script.**
- **It informed the affected customers.**

The log check explains much of the gap. A log confirms that a send happened, but only the message shows who can see whom. The new verification rule puts a second reader on exactly that step.

The PDPC weighed the circumstances of the case and accepted the company’s voluntary undertaking. Which AI tool the employee used remains unstated.

Bee Cheng Hiang’s fix is procedural: staff now verify every bulk email before it goes out. The company has already informed affected customers. They can treat unexpected messages that mention the brand with extra caution, which helps reduce exposure to [phishing emails](https://sqmagazine.co.uk/phishing-email-statistics/).