Resilience
One AI-written mail script exposed 95,364 customer emails
A generated Python script put Bee Cheng Hiang customers in each other's To field. How it happened and how to stop bulk mail code leaking addresses.
On April 25, 2026, Singapore food retailer Bee Cheng Hiang sent a marketing email that showed 95,364 members' email addresses to other members. An employee in the marketing team had asked a generative AI tool to write a Python script for the campaign. The script sent in batches of about 1,000, and every address in a batch landed in the visible "To" field, so each customer could see up to 999 others.
The case became public on September 30, after the Personal Data Protection Commission (PDPC), Singapore's privacy regulator, accepted a voluntary undertaking from the company on September 2. Local media describe it as the first AI-related breach notified to the PDPC. Only email addresses were exposed. Any organisation whose staff use AI tools to write code that touches customer data has the same exposure.
How it works
An email has two separate recipient lists. The envelope recipients are the addresses the sending program hands to the mail server in the SMTP RCPT TO commands, and they decide who receives a copy. The To and Cc headers are part of the message itself, and every recipient sees them. Blind copy works because those addresses go only into the envelope, never into a visible header. A script that wants 1,000 people to receive a mail without seeing each other must either send 1,000 separate messages or keep the list out of the headers.
According to the PDPC findings reported by local media, the employee's prompt asked for a mass email from a local list, in batches of 1,000, and said nothing about hiding recipients from one another. The generated code grouped every address in a batch into a single entry in the To field instead of treating each as its own recipient. Reports put the difference between the faulty and correct code down to the placement of brackets. To a mail server, a message with 1,000 addresses in To is valid, so nothing downstream would have stopped it.
The PDPC was explicit that the AI tool did not malfunction. It treated this as human error in building the distribution code with an AI tool, and pointed at how the code was checked. The employee tested the script by reading its activity logs, which showed sends succeeding, and did not open a test email to see what a recipient would see. A log line saying "sent to 1,000 addresses" looks the same whether those addresses were hidden or not.
What went wrong in the process
Reporting on the undertaking lists the gaps the regulator found. Bee Cheng Hiang had no framework for staff using generative AI tools, and this script was its first attempt at using one. Testing was not thorough enough to catch the problem, and no second person reviewed the code or the campaign before it went out.
A developer could make the same mistake by hand. The difference here is who wrote the code: sources describe no supervisory review of the script, and testing relied on activity logs without anyone opening the actual test email.
The company stopped the bulk send once the problem was found, corrected the script and told the affected members. It notified the PDPC on April 27, two days after the send.
What to do
Start with a quick inventory. Ask marketing, sales, HR and customer service whether anyone sends bulk email from a script, a spreadsheet macro or a desktop mail client instead of your email service provider (ESP), the platform built for campaigns. Scripts that run from a staff laptop rather than a managed server will not show up in any application inventory.
Then put controls at the mail layer, where they catch mistakes whoever wrote the code:
- Route marketing and other bulk mail through an ESP that sends one message per recipient. Block direct sending from scripts to your SMTP relay for anyone who does not need it.
- Lower per-message recipient limits on mailboxes that should never send to large groups. In Exchange Online the default is 500 recipients per message, adjustable from 1 to 1,000, for example
Set-Mailbox marketing@yourdomain -RecipientLimits 50. A script that packs a whole batch into one message then fails loudly instead of leaking. - Add a pre-send check in any script you keep: refuse to send if the
ToorCcheader holds more than one external address, and log the header values, not just a success count. The company's own fix included an automated block of this kind.
Change how generated code gets accepted. Any AI-written code that reads or sends personal data should be reviewed by someone who can read it, separate from the person who prompted it. The undertaking commits Bee Cheng Hiang to exactly that, plus a two-person check on every bulk communication and a usage framework for AI in coding.
For testing, send every campaign first to two or three seed mailboxes you control, open the received copy, and read its headers. If you can see any address other than your own in To or Cc, stop. The PDPC also recommends a data protection impact assessment, a structured review of what personal data a process touches and what could go wrong, before introducing AI tools into work that handles personal data.
To check whether this has already happened to you, look in your mail logs for single outbound messages with many external recipients. On Postfix, the queue manager logs a nrcpt= value for each message, so any bulk sender with a high count from a non-ESP host deserves a look. In Microsoft 365, run a message trace for the sending mailbox over the campaign dates and group the results by message ID. If you find a leak, stop the job, notify the affected people and your regulator as your law requires, and warn customers to expect phishing that uses the exposed list.
The wider lesson
Most organisations already have rules for production code: review, testing, change approval. Generative AI lets people who were never covered by those rules write and run code that touches customer data. The useful policy question is which kinds of data and systems require a technical review before AI-written code runs against them, and who does that review.
We review AI-written scripts and internal tools as part of our code review service, and help teams set up mail and data controls through safeguarding and hardening. If you want a second pair of eyes on how your teams send bulk email, open the chat and Yaali, our AI agent, will pass your question to an engineer.
Sources: https://mothership.sg/2026/10/bee-cheng-hiang-members-data-breach-ai/, https://www.asiaone.com/singapore/bee-cheng-hiang-customers-email-addresses-exposed-ai-generated-code-breach, https://www.stomp.sg/trending-now/bee-cheng-hiang-customers-e-mail-addresses-exposed-first-case-ai-related-data-breach-spore, https://goodyfeed.com/95364-bee-cheng-hiang-members-email-addresses-exposed-after-employee-uses-ai-to-write-mass-mail-code/, https://oecd.ai/en/incidents/2026-09-30-1509, https://techcommunity.microsoft.com/blog/exchange/customizable-recipient-limits-in-office-365/1183228, https://office365itpros.com/2020/01/17/custom-recipient-limits-exo/