Initializing portfolio

000

Aravind.
All articles
Cybersecurity3 min read

Singapore's First AI-Related Data Breach Came From an AI-Written Email Script

Singapore's PDPC recorded its first AI-related data breach: an AI-written mailing script exposed 95,364 customer email addresses. The regulator blamed missing checks, not the tool.

AravindChief Technology Officer & Advisor · AI, Cloud & Cybersecurity
Singapore's First AI-Related Data Breach Came From an AI-Written Email Script

Singapore's Personal Data Protection Commission (PDPC) has recorded its first AI-related data breach. There was no sophisticated attack behind it. It was a marketing email.

What happened

  • On April 25, an employee at Singapore food retailer Bee Cheng Hiang used a generative AI tool to write a Python script for sending marketing emails.
  • The prompt asked for a program to send a mass email from a local list in batches. It didn't say recipients' addresses should be hidden from each other.
  • The script sent emails in batches of about 1,000 with every address visible to the rest of the batch. In total, 95,364 customers' email addresses were exposed, each potentially seen by up to 999 others.
  • The PDPC said the AI tool didn't malfunction. The error came from the instructions given to it and from inadequate checks before the code went live.
  • Only email addresses were exposed, and there was no evidence they were misused.

The PDPC found the company hadn't tested the AI-generated code properly and had no supervisory checks or policies on staff use of generative AI. During testing, the employee looked at activity logs but never opened an actual test email.

Bee Cheng Hiang stopped the campaign, fixed the code and told affected customers. Two employees now have to verify any bulk email before it goes out. The PDPC accepted a voluntary undertaking from the company on September 2. Breaches of Singapore's PDPA can bring fines of up to S$1 million or 10% of annual turnover in Singapore.

Why this matters for every enterprise

This is about as ordinary as an AI incident gets, and that's why it's worth paying attention to. No jailbreak, no prompt injection, no rogue agent. Someone who wasn't a developer asked a tool for working code, got working code, and shipped it without anyone reviewing it.

Look at how the regulator reasoned. It didn't blame the tool. It blamed the missing policy, testing and supervision. That's the standard organisations will be held to as more staff write scripts, macros and automations with AI.

A few questions I'd put to my own teams this week. Do we have a policy for AI-generated code written outside engineering? Does anything that touches customer data get a second pair of eyes before it runs? And when we test, do we check the real output, or just the logs?

Source: VnExpress International: Emails of 95,000 customers exposed in Singapore's first AI-related data breach

#AI Governance#AI Security#Data Breach#PDPC

Comments

Checking you're human…

Keep reading

Get the next essay first

Checking you're human…

By subscribing you agree to our Privacy Policy. Unsubscribe anytime.