Over 95,000 customer emails were exposed in Singapore’s first AI-related data breach after a worker gave a bad instruction to a computer tool.
Singapore has recorded its very first official privacy breach linked to artificial intelligence after a popular local food company accidentally exposed the email addresses of over 95,000 customers.
Reports published by privacy regulators on September 30, 2026, revealed that traditional food maker Bee Cheng Hiang leaked the personal contact details during a promotional campaign in April.
The accidental leak happened when a company worker used a smart computer assistant to automatically generate software code for sending out bulk marketing messages, but forgot to tell the program to hide recipient addresses from each other.
The privacy breakdown represents a milestone case for Singapore’s Personal Data Protection Commission, marking the first time a business in the country reported a data spill caused by AI tools.
The employee asked the smart tool to write a computer script to send out thousands of sales emails in batches of 1,000.
Because the worker wrote an incomplete instruction, the computer program generated code that put all recipient addresses into the open email line instead of keeping them hidden, allowing every customer who opened the message to see the email addresses of hundreds of strangers.
Government privacy officers confirmed that customer email addresses were the only personal details leaked during the incident, with no password records, home locations, or banking details exposed.
The Personal Data Protection Commission reassured the public after investigating the incident, stating that “these customer e-mail addresses were the only personal data affected, and they were not managed, processed or generated by any AI-powered operation or process”.
Officials added that there is no evidence suggesting the exposed email lists were stolen or misused by criminal hackers.
In response to the mistake, the local food company immediately changed its internal workplace rules to prevent similar accidents.
See Also: Meta’s New AI Agent Gives Away User’s Home Address to Strangers
Company management reported that it has introduced a mandatory requirement that at least two human staff members must double-check all bulk email blasts before clicking send.
Furthermore, the business is setting up automated security controls that automatically block outgoing messages if multiple customer email addresses appear together in an open recipient field.
Technology safety experts say the Singapore incident serves as an important warning lesson for businesses rushing to adopt automated tools without proper staff training.
While AI can write computer scripts and handle office tasks very quickly, human workers must carefully review every piece of code before deploying it in live operations.
As companies around the world continue integrating smart software into daily work, tech safety regulators emphasize that human supervision remains essential to keep private consumer information safe from simple coding errors.

