新加坡:根据个人数据保护委员会(PDPC)周三(9月30日)发布的声明,近10万名Bee Cheng Hiang公司的客户的电子邮件地址在未经他们同意的情况下被泄露。这是新加坡首次发生的与人工智能(AI)相关的数据泄露事件。
SINGAPORE: The email addresses of nearly 100,000 Bee Cheng Hiang customers were disclosed without consent in what the Personal Data Protection Commission said on Wednesday (Sep 30) was the first AI-related data breach in Singapore that it has been notified of.
该数据泄露事件发生在4月份,当时一名Bee Cheng Hiang公司的员工使用AI工具生成了一个Python脚本,用于发送营销邮件。由于该脚本存在缺陷,收件人的电子邮件地址被公开显示给了所有人,共计95,364名客户受到了影响。PDPC在回应CNA的询问时表示:“此次事件是由于员工在利用AI工具开发邮件分发脚本时出现了人为错误。”
The breach occurred in April after a Bee Cheng Hiang employee used an AI tool to generate a Python script to distribute a marketing email. The resulting code caused the recipients' email addresses to be visible to everyone, affecting a total of 95,364 customers "The incident was caused by a human error in developing the email distribution code with an AI tool," the PDPC said in response to queries from CNA.
根据PDPC于9月21日在其网站上发布的声明,此次事件“并非AI工具本身的故障”,而是由于员工给AI工具提供了错误的指令所致。员工要求AI工具编写程序,以便分批发送批量邮件,但并未明确指示该工具隐藏其他收件人的电子邮件地址。
According to a statement posted on its website on Sep 21, PDPC said the incident was "not a malfunction in the AI tool", but a result of the prompt given to it by the employee. PDPC said the employee had prompted the AI tool to write a programme to send a "mass email using a local list" in batches, without specifically telling it to hide the email addresses of the other recipients.
PDPC进一步说明:该员工在部署脚本之前并未意识到这一错误,因为测试过程仅通过查看活动日志来完成,而并未实际查看测试邮件的内容。委员会还表示,受影响的数据“并未通过任何基于AI的技术或流程进行管理、处理或生成”,且“没有证据表明这些数据被进一步滥用”。
"The employee did not realise the error before deploying the script, as testing was done by checking activity logs without reviewing the contents of the actual test email," said PDPC. It added that the affected data "was not managed, processed, or generated by any AI-powered operation or process", and that there was "no evidence of further misuse" of the data.
PDPC指出,Bee Cheng Hiang公司迅速采取了补救措施,包括立即停止批量邮件发送、修正错误的脚本,并通知所有受影响的客户。该公司还规定,今后所有批量邮件发送活动都必须由至少两名员工共同审核。
The PDPC noted that Bee Cheng Hiang took prompt remedial actions, including immediately stopping the bulk marketing email distribution process, correcting the erroneous script and informing affected customers. The company also introduced a requirement for at least two staff members to verify all bulk email communications.
此外,这也是Bee Cheng Hiang公司首次尝试将AI工具应用于其业务运营中。
The PDPC noted that this is Bee Cheng Hiang's first attempt at incorporating AI tools into its business operations.
在采用人工智能工具以提升业务运营效率之前,组织应开展适当的数据保护影响评估;制定政策和流程;并实施测试和审查机制,以确保其员工负责任地使用人工智能工具并保护个人数据。考虑到案件情况,个人数据保护委员会(PDPC)接受了美珍香作出的自愿承诺,以改善其对《个人数据保护法》的合规情况。
"Prior to adopting AI tools to enhance the efficiency of their business operations, organisations should carry out appropriate data protection impact assessments; develop policies and processes; and implement testing and review mechanisms, to ensure that their employees use AI tools responsibly and safeguard personal data." Taking into account the circumstances of the case, t he PDPC accepted a voluntary undertaking from Bee Cheng Hiang to improve its compliance with the Personal Data Protection Act.