Singapore · Tuesday, October 6, 2026
asianomistAsia’s economy, daily.
Tech & Semiconductors

Singapore's Bee Cheng Hiang hit by AI data breach, 95,000 emails exposed

Singapore's Personal Data Protection Commission found an employee used an AI tool to generate marketing code, exposing over 95,000 customer email addresses.

By Daniel SimPublished 4 October 20261 min read
Photo: TheDigitalArtist / Pixabay

Singapore Firm's Data Exposure

On 1 October 2026, Singaporean firm Bee Cheng Hiang experienced a data breach, exposing more than 95,000 customer email addresses. The incident marks Singapore's first reported data breach linked to artificial intelligence (AI) tools. An employee at the company used an AI programme to generate code for a marketing email campaign, which subsequently handled a local mailing list. The Personal Data Protection Commission (PDPC) investigated the matter.

PDPC Investigation Details

The Personal Data Protection Commission's inquiry revealed that the AI-assisted code was deployed without sufficient testing or review. This oversight allowed the vulnerability that led to the exposure of customer data. The PDPC's findings show the risks associated with integrating new technologies without robust internal validation processes.

SME AI Adoption Challenges

This incident reveals a dilemma for small and medium-sized enterprises (SMEs) adopting AI. As AI capabilities advance, it becomes less realistic to expect non-technical staff to identify complex technical risks within these systems.

The PDPC's report implicitly points to the need for clearer guidelines or enhanced training for employees using AI tools in business operations, particularly where sensitive customer data is involved.

Future Compliance Requirements

Businesses in Singapore, especially SMEs, now face increased scrutiny regarding their AI governance frameworks. The PDPC may issue updated advisories or compliance requirements for companies integrating AI into data-handling processes, particularly concerning code generation and data list management.

Companies should review their internal protocols for AI tool deployment and ensure adequate technical oversight is in place before 1 January 2027, to avoid similar incidents.

This article is journalism, not investment advice; consult a licensed professional before making financial decisions. Market data is indicative, may be delayed, and should be verified with your broker or exchange before use.

Comments.

Comments are moderated. We remove what is unlawful, abusive or off-topic, and and you remain responsible for what you post.

Reader comments open soon. Until then, corrections and responses go to our newsroom, and we publish what we get wrong on Corrections.