LOGO

Kiranapro Hacked: Indian Grocery Startup Loses Servers

June 3, 2025
Kiranapro Hacked: Indian Grocery Startup Loses Servers

KiranaPro Data Breach: Startup Suffers Complete Data Wipe

KiranaPro, an Indian grocery delivery service, has confirmed a significant security incident resulting in a complete loss of data. The company’s founder disclosed this information to TechCrunch.

Data Compromised

The compromised data encompassed the entirety of the company’s application code and the servers housing sensitive customer details. This included customer names, postal addresses, and payment information, as stated by KiranaPro co-founder and CEO, Deepak Ravindran.

Currently, the application remains accessible online, however, order processing capabilities are suspended.

Company Overview

Established in December 2024, KiranaPro functions as a buyer application integrated with the Indian government’s Open Network for Digital Commerce. This allows consumers to procure groceries from local retailers and supermarkets.

The platform serves 55,000 customers, with an active user base of 30,000 to 35,000 spread across 50 cities. Collectively, these users generate approximately 2,000 orders each day.

Unique Features and Expansion Plans

Distinguishing itself from conventional grocery delivery applications, KiranaPro provides a voice-activated interface. This feature enables users to place orders via voice commands in multiple languages, including Hindi, Tamil, Malayalam, and English.

Prior to the breach, the startup had ambitious plans to extend its operations to 100 cities within the following 100 days, according to Ravindran.

Discovery of the Incident

Executives at KiranaPro first detected the security breach on May 26th while attempting to access their Amazon Web Services account.

The attackers successfully obtained access to KiranaPro’s root accounts on both AWS and GitHub, as Ravindran explained to TechCrunch.

Potential Entry Point

Screenshots of GitHub security logs and activity logs shared by Ravindran suggest the intrusion may have occurred through the compromised account of a former employee.

Saurav Kumar, KiranaPro’s chief technology officer, indicated the hacking took place around May 24th and 25th.

Security Measures and Failures

The startup had implemented Google Authenticator for multi-factor authentication on its AWS account. However, Kumar reported that the multi-factor code had been altered when they attempted to log in last week.

Consequently, all of their Electric Compute Cloud (EC2) services – which provide access to virtual computing resources – were deleted.

“Access is currently limited to the IAM (Identity and Access Management) account, allowing us to confirm the EC2 instances are no longer present. Unfortunately, we are unable to retrieve logs or further information due to the loss of root account access,” Kumar stated.

Ongoing Investigations

KiranaPro has contacted GitHub’s support team to assist in identifying the attacker’s IP addresses and other relevant details pertaining to the incident, as stated by Ravindran.

Furthermore, the startup is initiating legal action against former employees who allegedly failed to submit their credentials for GitHub account log review.

Possible Causes and Industry Trends

The precise cause of the attack remains undetermined. However, recent large-scale cyberattacks, including those targeting LastPass, Change Healthcare, and Snowflake, have frequently been attributed to credential theft – often through malware installed on employee devices or insufficient multi-factor authentication.

Ultimately, organizations bear the responsibility for securing their systems, including enforcing multi-factor authentication and promptly deactivating accounts of former employees.

Investors and Team

KiranaPro’s investors include venture capital firms Blume Ventures, Unpopular Ventures, and Turbostart. Angel investors include Olympic medalist PV Sindhu and BCG MD Vikas Taneja.

The company employs a team of 15 individuals based in Bengaluru and Kerala.

#Kiranapro#hack#data breach#indian grocery#startup#cybersecurity