Singapore food retailer Bee Cheng Hiang used a generative AI tool to write a script for sending bulk marketing emails to its mailing list. The script omitted code to isolate each recipient’s address in the “To” field, so when the batch emails went out, each customer’s address was visible to up to 999 other recipients in the same send. The error, which occurred in April 2026 and was reported to Singapore’s Personal Data Protection Commission two days after discovery, exposed the email addresses of more than 95,000 customers and was described as the country’s first AI-related data breach notification.