Nearly 100,000 affected as Bee Cheng Hiang suffers Singapore's first AI-related data breach美珍香遭遇新加坡首例人工智能相关数据泄露事件,近10万人受到影响
Nearly 100,000 Bee Cheng Hiang customers had their email addresses exposed after an employee used an AI tool to generate code for a mass marketing email. The incident is reportedly Singapore's first AI-related data breach notified to the Personal Data Protection Commission (PDPC).The incident took place on April 25. Bee Cheng Hiang notified the PDPC two days later.PDPC Commission accepted...

Nearly 100,000 Bee Cheng Hiang customers had their email addresses exposed after an employee used an AI tool to generate code for a mass marketing email.
The incident is reportedly Singapore's first AI-related data breach notified to the Personal Data Protection Commission (PDPC).
The incident took place on April 25. Bee Cheng Hiang notified the PDPC two days later.
PDPC Commission accepted a voluntary undertaking by Bee Cheng Hiang in September, to improve its compliance with the Personal Data Protection Act 2012.
The email was sent out in batches of about 1,000 customers, so recipients were able to see the email addresses of other people in the same batch.
Insufficient AI prompt
Bee Cheng Hiang said the employee had used a generative AI tool to help create a programme for sending marketing emails from a local mailing list.
However, the instructions given to the AI did not specify that recipients' email addresses should be hidden from one another.
The resulting code therefore caused multiple customers' addresses to appear in the same email.
The PDPC said the incident was not caused by a malfunction in the AI tool, but by human error in developing the email distribution code.
The affected email addresses were the only personal data involved, and the PDPC said there was no evidence that they were subsequently misused.
The employee had tested the programme before it was deployed, but only checked activity logs instead of examining the content of an actual test email.
This meant the problem was not detected before the marketing emails were sent.
Company introduces additional checks
Bee Cheng Hiang, which is known for their bak kwa, stopped the bulk email distribution after discovering the issue, corrected the code and informed affected customers.
The company has since introduced a requirement for at least two employees to check all bulk email communications before they are sent, according to the PDPC.
The PDPC also noted that this was Bee Cheng Hiang's first attempt at incorporating AI tools into its business operations.
Following the incident, the company gave a voluntary undertaking to improve its compliance with the Personal Data Protection Act. The PDPC accepted the undertaking on Sept 2.
As part of the undertaking, Bee Cheng Hiang will establish a framework governing employees' use of AI for coding.
This includes requiring independent technical reviews of AI-generated code that involves personal data.
The company will also strengthen its software testing procedures, including testing emails using dummy accounts before deployment.
It plans to formalise its response to the incident into a data breach procedure, as well as introduce automated measures to prevent emails containing multiple addresses from being sent in a single email field.
PDPC urges businesses to assess risks before using AI
The PDPC reportedly said organisations should conduct appropriate data protection impact assessments before adopting AI tools to improve business processes.
It also recommended that companies establish clear policies and processes, alongside testing and review mechanisms, to ensure employees use AI responsibly and protect personal data.
The case highlights that while AI may be used to assist with coding and other business functions, organisations remain responsible for checking how AI-generated outputs handle personal data before putting them into use.
asyiqin.nadzri@asiaone.com
美珍香餐厅一名员工使用人工智能工具生成群发营销邮件的代码后,近 10 万名顾客的电子邮件地址遭到泄露。
据报道,这是新加坡首例向个人数据保护委员会 (PDPC) 通报的与人工智能相关的数据泄露事件。
事件发生在4月25日。两天后,Bee Cheng Hiang向警方报案。
9 月,PDPC 委员会接受了 Bee Cheng Hiang 的自愿承诺,以改善其对 2012 年《个人资料保护法》的遵守情况。
该邮件分批发送,每批约有 1000 位客户,因此收件人可以看到同一批次中其他人的电子邮件地址。
人工智能提示不足
Bee Cheng Hiang表示,该员工使用了一款生成式人工智能工具,帮助创建了一个程序,用于从本地邮件列表中发送营销电子邮件。
然而,给人工智能的指令并没有明确规定收件人的电子邮件地址应该彼此隐藏。
因此,生成的代码导致多个客户的地址出现在同一封电子邮件中。
菲律宾个人数据保护委员会表示,该事件并非由人工智能工具故障引起,而是由编写电子邮件分发代码时的人为错误造成的。
受影响的电子邮件地址是唯一涉及的个人数据,个人数据保护委员会表示没有证据表明这些地址随后被滥用。
该员工在程序部署前对其进行了测试,但只查看了活动日志,而没有检查实际测试电子邮件的内容。
这意味着在营销邮件发送之前没有发现这个问题。
公司引入额外检查
以肉干闻名的美珍香在发现问题后停止了批量电子邮件发送,修正了代码并通知了受影响的客户。
据菲律宾个人数据保护委员会 (PDPC) 称,该公司此后出台了一项规定,要求至少两名员工在发送所有批量电子邮件通信之前进行检查。
菲律宾药品定价委员会还指出,这是美珍香首次尝试将人工智能工具融入其业务运营中。
事件发生后,该公司自愿承诺改进其对《个人数据保护法》的遵守情况。个人数据保护委员会于9月2日接受了该承诺。
作为该计划的一部分,碧成香将建立一个框架来管理员工使用人工智能进行编码。
这包括要求对涉及个人数据的 AI 生成代码进行独立的技术审查。
该公司还将加强软件测试流程,包括在部署前使用虚拟帐户测试电子邮件。
该公司计划将此次事件的应对措施正式纳入数据泄露处理程序,并引入自动化措施,以防止在单个电子邮件字段中发送包含多个地址的电子邮件。
菲律宾个人数据保护委员会(PDPC)敦促企业在使用人工智能之前进行风险评估。
据报道,菲律宾个人数据保护委员会 (PDPC) 表示,各组织在采用人工智能工具改进业务流程之前,应进行适当的数据保护影响评估。
报告还建议各公司制定明确的政策和流程,以及测试和审查机制,以确保员工负责任地使用人工智能并保护个人数据。
该案例表明,虽然人工智能可以用于辅助编码和其他业务功能,但组织仍有责任在使用人工智能生成的输出结果之前检查其如何处理个人数据。
asyiqin.nadzri@asiaone.com