AI‑Generated Bulk‑Email Script Leaks 95,364 Bee Cheng Hiang Customer Addresses
A generative‑AI‑crafted Python script used by Bee Cheng Hiang in April 2026 unintentionally placed thousands of customer email addresses in the visible recipient field, exposing 95,364 addresses to other recipients.

In April 2026, a staff member at Singapore‑based meat‑snack maker Bee Cheng Hiang turned to a generative‑AI assistant to draft a Python script intended to launch a marketing blast through the SendGrid service. The prompt supplied to the AI explicitly asked for a solution that would pull customer addresses from an internal database and send them in bulk, but it omitted any instruction that the recipients should be concealed from one another.
The code produced by the AI consequently placed each group of email addresses into the conventional "To" header instead of employing the blind carbon copy (BCC) field. This oversight meant that every address in a given batch was openly displayed to all other recipients in that same batch.
Scope of the breach
When the script was finally executed, it dispatched the promotional message to a total of 95,364 distinct customer email accounts. The only data that became visible was the email addresses themselves; no passwords, payment information, or the actual marketing content were leaked.
During the testing phase, the employee reviewed the system’s activity logs but never opened a test email to inspect the actual recipient list. As a result, the visibility flaw went undetected until the bulk send was already underway.
Regulatory response
Singapore's Personal Data Protection Commission (PDPC) classified the incident as the nation’s first AI‑related data breach reported to the authority. The regulator stressed that the breach originated from human error in the development and deployment of the script, not from any malfunction of the generative‑AI tool itself.
The PDPC also clarified that the exposed data was not processed or generated by an AI system, reinforcing the view that the breach was a consequence of how the AI‑assisted code was applied rather than an inherent risk of the technology.
Bee Cheng Hiang’s remedial actions
- Immediately halted the bulk email distribution
- Corrected the script to enforce BCC for all recipient batches
- Notified all affected customers via a dedicated email and public statement
- Implemented a dual‑verification policy requiring at least two staff members to approve any bulk communication before sending
The PDPC found no evidence that the leaked addresses had been repurposed for phishing attacks or spam campaigns. Instead of levying a monetary fine, the commission accepted a voluntary undertaking from Bee Cheng Hiang to upgrade its data‑protection safeguards.
In its ruling, the regulator urged organisations to carry out data‑protection impact assessments whenever AI‑assisted tools are deployed, to draft clear internal policies governing AI use, and to conduct testing that examines real‑world outputs—not merely log files—before any code is put into production.
For English‑speaking companies, the incident highlights the necessity of concrete verification steps when AI generates operational code. Relying solely on log reviews can miss functional defects that only surface in actual email headers.
Implementing peer‑review processes, automating tests that validate email header fields, and mandating the use of BCC for any bulk mailing are practical measures that can avert similar exposures of personal data.
Broader implications for AI governance
The breach illustrates how generative AI can amplify existing human oversights, turning a simple omission into a large‑scale data exposure. It underscores the importance of integrating AI governance frameworks that address both the technology and the human processes surrounding its use.
Experts note that as organisations increasingly rely on AI to automate routine tasks, the line between tool error and user error becomes blurred, making it essential to assign clear responsibility for code validation.
Industry best practices
Security professionals recommend a layered approach: start with clear prompts that include privacy safeguards, follow up with code reviews by multiple engineers, and employ automated scanning tools that detect insecure email handling patterns before deployment.
Training programmes that educate staff on the limits of AI‑generated code and the necessity of functional testing are also vital to prevent similar incidents in the future.
Finally, maintaining an incident‑response playbook that outlines steps for rapid containment, customer notification, and regulator engagement can reduce the impact of any inadvertent data leak.
This episode, rooted in Singapore, serves as a cautionary tale for businesses worldwide, reminding them that AI‑driven automation must be paired with rigorous human oversight to protect personal information.
Sources
- 新加坡首起生成式AI相關個資外洩事故,肉乾業者Bee Cheng Hiang誤曝逾9.5萬名會員信箱iThome · October 4, 2026
- Nearly 100,000 Bee Cheng Hiang customers' email addresses exposed in first AI-related data breach in SingaporeCNA · September 30, 2026



