Bad AI prompt exposes Bee Cheng Hiang customers’ e-mail addresses in first case of AI-related data breach糟糕的AI提示导致美珍香客户邮箱地址泄露,这是首例与AI相关的数据泄露事件。
Bee Cheng Hiang exposed over 95,000 customer e-mail addresses due to a bad AI prompt in Singapore’s first reported AI-related data breach. Read more at straitstimes.com.
Bee Cheng Hiang’s marketing e-mails were sent in batches of 1,000 customers, according to details published Sept 21 on the commission’s website.
ST PHOTO: LIM YAOHUI
Published Sep 30, 2026, 05:40 PM
Updated Sep 30, 2026, 05:40 PM
A bad AI prompt caused Bee Cheng Hiang to accidentally expose over 95,000 customers' e-mail addresses in Singapore's first AI-related data breach.
The breach resulted from human error in coding without proper testing or supervisory review, not from an AI tool malfunction.
Bee Cheng Hiang has since improved its AI use policies, added double-verification for bulk e-mails and committed to stronger data protection measures.
SINGAPORE – More than 95,000 of Bee Cheng Hiang customers had their e-mail addresses accidentally exposed in April after an employee used a bad prompt in an AI tool , in Singapore’s first reported case of AI-related data breach.
The bad prompt generated code that sent out marketing e-mails with all the recipients’ addresses visible to everyone.
It was the first AI-related data breach reported to the Personal Data Protection Commission (PDPC) , the commission told The Straits Times on Sept 30.
It was also the first time the homegrown traditional food products company known for its bak kwa was using an AI tool for its business operations.
Bee Cheng Hiang’s marketing e-mails were sent in batches of 1,000 customers, according to details published Sept 21 on the commission’s website .
These customer e-mail addresses were the only personal data affected, and they were not managed, processed or generated by any AI-powered operation or process, said the PDPC.
There was also no evidence that the e-mail addresses were further misused.
The PDPC clarified that the incident was not due to a malfunction in the AI tool used by the Bee Cheng Hiang employee.
Rather, the issue was with the prompt the employee gave the generative artificial intelligence tool to write a program to send a “mass e-mail using a local list” in batches, but without specific instructions to hide the e-mail address of each recipient from other customers.
“The incident was caused by a human error in developing the e-mail distribution code with an AI tool,” the commission told ST.
If the prompt had been adjusted, the correct code produced should have sent e-mails addressed to each individual customer, instead of 1,000 customers in each batch.
Visually, the difference between the correct code and the bad one was the placement of a couple of brackets, which changed the code’s behaviour.
The problematic marketing e-mails were sent out on April 25, and the PDPC was notified of the data breach on April 27.
The commission said that the incident likely happened as Bee Cheng Hiang did not conduct sufficiently robust tests to check the e-mail distribution code before it was deployed.
It added that the company had relied on a single employee “without a review process for supervisory checks of the employee’s work, and did not have a governance framework or policies in place to guide employees on the use of generative AI tools for work”.
The employee did not realise the error before deploying the code, as testing was done by checking activity logs without reviewing the content of the actual test e-mail.
After the company discovered and confirmed the error, it stopped the mass distribution of the e-mails, rectified the bad code and notified all affected customers, the PDPC said.
Since the incident, the company has implemented “double-verification checks” by at least two staff members for all bulk e-mail communications before sending them out.
The PDPC said that organisations should carry out appropriate data protection impact assessments before using AI tools to improve the efficiency of their business operations.
They should also develop policies and processes, as well as implement testing and review mechanisms, to ensure that their employees use AI tools responsibly and safeguard personal data, the PDPC added.
Considering the circumstances of the case, the commission accepted a voluntary undertaking by Bee Cheng Hiang on Sept 2 to improve its compliance with the Personal Data Protection Act.
Organisations that flout the Act can be fined up to $1 million or 10% of the organisation’s annual turnover in Singapore, whichever is higher.
Bee Cheng Hiang will implement a framework to govern how its employees use AI for coding, including an independent technical review of AI-generated code involving personal data.
The company’s other follow-up actions include:
Baking in security during each stage of software development and improving the process of reviewing the security of its software before deploying it, such as by testing e-mails sent to dummy accounts first
Formalising the actions it took for this incident into a data breach procedure for the organisation
Implementing automated technical measures that can block the mass distribution of e-mails containing multiple e-mail addresses in a single e-mail field, as well as design and deliver data protection training programmes for staff who develop, review and deploy systems that handle personal data
The Straits Times has contacted Bee Cheng Hiang for comments.
AI/artificial intelligence
Personal Data Protection Act
Artificial Intelligence
根据委员会网站 9 月 21 日公布的详细信息,美珍香的营销电子邮件是分批发送给 1000 名客户的。
ST 照片:林耀辉
发布于2026年9月30日下午5:40
更新于2026年9月30日下午5:40
由于人工智能提示错误,Bee Cheng Hiang 意外泄露了新加坡首例与人工智能相关的数据泄露事件中超过 95,000 名客户的电子邮件地址。
此次安全漏洞是由于编码过程中人为错误,且未进行适当的测试或监督审查造成的,并非人工智能工具故障所致。
此后,碧城香改进了人工智能使用政策,增加了批量电子邮件的双重验证,并承诺采取更强有力的数据保护措施。
新加坡——今年 4 月,美珍香餐饮集团一名员工在使用人工智能工具时使用了错误的提示,导致超过 95,000 名顾客的电子邮件地址意外泄露。这是新加坡首例有报道的与人工智能相关的数据泄露事件。
错误的提示生成了代码,该代码发送的营销电子邮件中包含了所有收件人的地址,所有人都能看到。
个人数据保护委员会 (PDPC) 于 9 月 30 日告诉《海峡时报》,这是该委员会接到的第一起与人工智能相关的数据泄露报告。
这也是这家以肉干闻名的本土传统食品公司首次在其业务运营中使用人工智能工具。
根据委员会网站 9 月 21 日公布的详细信息,美珍香的营销电子邮件是分批发送给 1000 名客户的。
菲律宾个人数据保护委员会表示,受影响的个人数据只有这些客户的电子邮件地址,而且这些电子邮件地址并非由任何人工智能驱动的操作或流程管理、处理或生成。
也没有证据表明这些电子邮件地址被进一步滥用。
菲律宾药品价格控制委员会澄清,该事件并非由于美珍香员工使用的AI工具出现故障所致。
问题在于,该员工给生成式人工智能工具的提示是编写一个程序,使用本地列表分批发送“群发电子邮件”,但没有给出具体指示来隐藏每个收件人的电子邮件地址,使其不被其他客户看到。
“该事件是由于使用人工智能工具开发电子邮件分发代码时出现人为错误造成的,”委员会告诉《海峡时报》。
如果调整提示,生成的正确代码应该会向每个客户单独发送电子邮件,而不是每次向 1,000 个客户发送邮件。
从视觉上看,正确代码和错误代码的区别在于几个括号的位置不同,这改变了代码的行为。
有问题的营销电子邮件于 4 月 25 日发出,PDPC 于 4 月 27 日接到数据泄露通知。
委员会表示,这起事件很可能是因为 Bee Cheng Hiang 在部署电子邮件分发代码之前没有进行足够严格的测试来检查代码。
报告还指出,该公司仅依靠一名员工,“没有对员工的工作进行监督检查的审查流程,也没有相应的治理框架或政策来指导员工在工作中使用生成式人工智能工具”。
该员工在部署代码之前没有意识到错误,因为测试是通过检查活动日志进行的,而没有查看实际测试电子邮件的内容。
菲律宾个人数据保护委员会表示,该公司在发现并确认错误后,停止了电子邮件的大规模分发,纠正了错误代码,并通知了所有受影响的客户。
自该事件发生以来,该公司已对所有批量电子邮件通信实施“双重核查”,在发送之前至少由两名员工进行核查。
菲律宾个人数据保护委员会表示,各组织在使用人工智能工具提高业务运营效率之前,应进行适当的数据保护影响评估。
菲律宾个人数据保护委员会补充说,他们还应该制定政策和流程,并实施测试和审查机制,以确保员工负责任地使用人工智能工具并保护个人数据。
考虑到案件的具体情况,委员会于9月2日接受了碧清香的自愿承诺,以改善其对《个人资料保护法》的遵守情况。
违反该法案的机构可被处以最高 100 万美元或该机构在新加坡年营业额的 10% 的罚款,以较高者为准。
Bee Cheng Hiang 将实施一套框架来规范其员工如何使用人工智能进行编码,其中包括对涉及个人数据的人工智能生成的代码进行独立的技术审查。
该公司采取的其他后续行动包括:
在软件开发的每个阶段都融入安全性,并改进部署前软件安全审查流程,例如先测试发送到模拟账户的电子邮件。
将针对此次事件采取的行动正式纳入组织的数据泄露处理流程。
实施自动化技术措施,以阻止批量发送在单个电子邮件字段中包含多个电子邮件地址的电子邮件;并为开发、审查和部署处理个人数据的系统的员工设计并提供数据保护培训计划。
《海峡时报》已联系碧清香征求意见。
人工智能
个人数据保护法
人工智能