Bee Cheng Hiang Marketing Pte Ltd
bd_7ec338a866e4b3ac · schema v1 · pii pii-v2
Full breach record for Bee Cheng Hiang Marketing Pte Ltd →Regulator's decision — not a breach notification
This record is a regulator's decision, not the organisation's own breach notice. Breach-notification fields (discovery date, notification clock) are structurally absent — what this source establishes is the outcome and the provisions the decision cites.
Background Bee Cheng Hiang Marketing Pte. Ltd. (the “Organisation”) notified the Personal Data Protection Commission (the “Commission”) on 27 April 2026 of a personal data breach involving its bulk marketing email distribution process (the “Incident”). The Incident involved a marketing email sent to the Organisation’s members on 25 April 2026. All email addresses within each batch were displayed in the “To” field, visible to every recipient within that batch, disclosed without the consent of the other recipients. The Organisation established that the Incident was caused by a configuration error in an email distribution Python script developed by one of the Organisation’s employees through the personal use of a generative artificial intelligence (“AI”) tool. The generated script contained a code-level configuration missing a bracket that caused all recipient email addresses within each batch to be grouped together as a single object in the “To” field, rather than as individual, isolated recipient entries. This was not a malfunction in the AI tool but resulted from the prompt given to the AI tool to write a programme to send “mass email using a local list” in batches, without specific instructions to block the visibility of other recipients’ email addresses to each individual recipient. The employee did not realise the error before deploying the script, as testing was done by checking activity logs without reviewing the contents of the actual test email. The erroneous code was: "personalizations": [{"to": [{"email": str(e)} for e in chunk]}] The corrected code is: "personalizations": [{"to": [{"email": str(e)}] } for e in chunk] Code Comparison Table "personalizations": [{"to": [{"email": str(e)} for e in chunk]}] "personalizations": [{"to": [{"email": str(e)}] } for e in chunk] What it means: You are creating one single personalization object that contains an array of
P pin to compareR raw source
Incident timeline — partial
? — ?
Breach window unknown
Sep 21, 2026
Filed
—
No linked breach filing · watching
Compliance clocks stay unassessable until a breach filing is linked. This record is the regulator's action, not a breach notice. Dashed segments fill in automatically when corroboration arrives.
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.
Source ceiling
- outcome + obligations
- fine (SGD) and affected count where a grounds document states them
- discovery date
- notification clock
See the underlying breach notice, if any.