Bee Cheng Hiang's 100,000-address leak is Singapore's first AI-linked breach
Source: CNA Tech
A coding slip while building Bee Cheng Hiang's email tool exposed around 100,000 customer addresses, giving Singapore its first data leak traced to AI.

Bee Cheng Hiang has picked up an unwanted first. Roughly 100,000 shoppers' email addresses were left exposed in what Singapore's privacy watchdog has identified as the country's earliest personal data leak connected to an AI tool.
The Personal Data Protection Commission, the body that polices how organisations here handle people's information, examined the episode and pinned it on a person's mistake while writing the code that drives email distribution. No cunning intruder, no exotic software failure — just a slip during development.
So the machinery built to fire off the brand's mailers instead spilled customer contact details. The regulator's finding puts responsibility squarely at the build stage, not at any breach from outside.
That is the part the rest of the industry should squirm over. Firms are rushing to fold AI into marketing, service desks and back-office chores, frequently waving through machine-generated code with only a light check. One overlooked line can turn a mundane mailout into a headline. The lesson is not that AI is dangerous; it is that adoption is outrunning the habits meant to catch exactly this kind of error.
Why it matters for Singapore: The Republic has staked plenty on being a trusted place to build and deploy AI, and that reputation only holds if basic data hygiene holds with it. A familiar local brand leaking customer contacts through careless AI-assisted coding is precisely the sort of tale that chips away at confidence. Let guardrails lag adoption, and the country's AI pitch keeps colliding with avoidable embarrassment.


