Bad AI Prompt Causes First AI-Related Data Leak in Singapore

Singapore Sees First Data Breach Linked to AI Use, ST Reports

Over 95,000 customer emails were exposed in Singapore’s first AI-related data breach after a worker gave a bad instruction to a computer tool.

Singapore has recorded its very first official privacy breach linked to artificial intelligence after a popular local food company accidentally exposed the email addresses of over 95,000 customers.

Reports published by privacy regulators on September 30, 2026, revealed that traditional food maker Bee Cheng Hiang leaked the personal contact details during a promotional campaign in April.

The accidental leak happened when a company worker used a smart computer assistant to automatically generate software code for sending out bulk marketing messages, but forgot to tell the program to hide recipient addresses from each other.

The privacy breakdown represents a milestone case for Singapore’s Personal Data Protection Commission, marking the first time a business in the country reported a data spill caused by AI tools.

The employee asked the smart tool to write a computer script to send out thousands of sales emails in batches of 1,000.

Because the worker wrote an incomplete instruction, the computer program generated code that put all recipient addresses into the open email line instead of keeping them hidden, allowing every customer who opened the message to see the email addresses of hundreds of strangers.

Government privacy officers confirmed that customer email addresses were the only personal details leaked during the incident, with no password records, home locations, or banking details exposed.

The Personal Data Protection Commission reassured the public after investigating the incident, stating that “these customer e-mail addresses were the only personal data affected, and they were not managed, processed or generated by any AI-powered operation or process”.

Officials added that there is no evidence suggesting the exposed email lists were stolen or misused by criminal hackers.

In response to the mistake, the local food company immediately changed its internal workplace rules to prevent similar accidents.

See Also: Meta’s New AI Agent Gives Away User’s Home Address to Strangers

Company management reported that it has introduced a mandatory requirement that at least two human staff members must double-check all bulk email blasts before clicking send.

Furthermore, the business is setting up automated security controls that automatically block outgoing messages if multiple customer email addresses appear together in an open recipient field.

Technology safety experts say the Singapore incident serves as an important warning lesson for businesses rushing to adopt automated tools without proper staff training.

While AI can write computer scripts and handle office tasks very quickly, human workers must carefully review every piece of code before deploying it in live operations.

As companies around the world continue integrating smart software into daily work, tech safety regulators emphasize that human supervision remains essential to keep private consumer information safe from simple coding errors.

About the Author

Jennifer Sakmufuwo Baba

Jennifer Sakmufuwo Baba is a tech analyst, senior staff, and writer covering artificial intelligence, cybersecurity , and emerging technologies at TechRegard. Based in Nigeria, she's passionate about translating complex tech developments into compelling, accessible stories for diverse audiences. Her work focuses on how technology shapes innovation across Africa and globally.