Nearly 100,000 affected as Bee Cheng Hiang suffers Singapore's first AI-related data breach
Nearly 100,000 Bee Cheng Hiang customers had their email addresses exposed after an employee used an AI tool to generate code for a mass marketing email. The incident is reportedly Singapore's first AI-related data breach notified to the Personal Data Protection Commission (PDPC).The incident took place on April 25. Bee Cheng Hiang notified the PDPC two days later.PDPC Commission accepted a voluntary undertaking by Bee Cheng Hiang in September, to improve its compliance with the Personal Data Protection Act 2012.The email was sent out in batches of about 1,000 customers, so recipients were able to see the email addresses of other people in the same batch.Insufficient AI promptBee Cheng Hiang said the employee had used a generative AI tool to help create a programme for sending marketing emails from a local mailing list.However, the instructions given to the AI did not specify that recipients' email addresses should be hidden from one another.The resulting code therefore caused multiple customers' addresses to appear in the same email.
Read full article β