AI-Generated Code Causes Major Data Breach at Bee Cheng Hiang in Singapore

Thumbnail Image

The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.

In April, a Bee Cheng Hiang employee used a generative AI tool to write code for marketing emails, but a poorly crafted prompt led to the exposure of over 95,000 customer email addresses. This marks Singapore's first AI-related data breach, attributed to human error in AI use rather than tool malfunction.[AI generated]

Why's our monitor labelling this an incident or hazard?

The event involves the use of an AI tool in the development or use phase, where a programming error caused a significant data breach exposing personal information of many customers. This constitutes a violation of privacy rights and data protection laws, which falls under harm category (c) - violations of human rights or breach of obligations under applicable law. The AI system's malfunction or misuse directly led to the harm, qualifying this as an AI Incident.[AI generated]
AI principles
Privacy & data governanceAccountability

Industries
Food and beverages

Affected stakeholders
Consumers

Harm types
Human or fundamental rights

Business function:
Marketing and advertisement

AI system task:
Content generation


Articles about this incident or hazard