{"id":172287,"date":"2025-06-03T15:46:06","date_gmt":"2025-06-03T15:46:06","guid":{"rendered":"https:\/\/entertainment.runfyers.com\/index.php\/2025\/06\/03\/indian-grocery-startup-kiranapro-was-hacked-and-its-servers-deleted-ceo-confirms\/"},"modified":"2025-06-03T15:46:06","modified_gmt":"2025-06-03T15:46:06","slug":"indian-grocery-startup-kiranapro-was-hacked-and-its-servers-deleted-ceo-confirms","status":"publish","type":"post","link":"https:\/\/entertainment.runfyers.com\/index.php\/2025\/06\/03\/indian-grocery-startup-kiranapro-was-hacked-and-its-servers-deleted-ceo-confirms\/","title":{"rendered":"Indian grocery startup KiranaPro was hacked and its servers deleted, CEO confirms"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p id=\"speakable-summary\" class=\"wp-block-paragraph\">Indian grocery delivery startup <a href=\"https:\/\/www.kirana.pro\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">KiranaPro<\/a> has been hacked and all its data has been wiped, the company\u2019s founder confirmed to TechCrunch.<\/p>\n<p class=\"wp-block-paragraph\">The destroyed data included the company\u2019s app code and its servers containing banks of sensitive customer information, including their names, mailing addresses, and payment details, KiranaPro co-founder and CEO Deepak Ravindran told TechCrunch.<\/p>\n<p class=\"wp-block-paragraph\">The company\u2019s app is online but cannot process orders, TechCrunch has found.<\/p>\n<p class=\"wp-block-paragraph\">Launched in December 2024, KiranaPro operates as a buyer app on the <a href=\"https:\/\/techcrunch.com\/2024\/08\/22\/indias-open-commerce-network-expands-into-digital-lending\/\" target=\"_blank\" rel=\"noreferrer noopener\">Indian government\u2019s Open Network for Digital Commerce<\/a>, allowing customers to purchase groceries from their local shops and nearby supermarkets.<\/p>\n<p class=\"wp-block-paragraph\">KiranaPro has 55,000 customers, with 30,000-35,000 active buyers across 50 cities, who collectively place 2,000 orders daily, according to the company. Unlike a typical grocery delivery app, KiranaPro offers a voice-based interface that allows users to place orders from local shops using voice commands in languages such as Hindi, Tamil, Malayalam, and English.<\/p>\n<p class=\"wp-block-paragraph\">The startup planned to expand to 100 cities in the next 100 days before the incident happened, Ravindran said.<\/p>\n<p class=\"wp-block-paragraph\">On May 26, KiranaPro executives became aware of the incident while logging into their Amazon Web Services account. Hackers had gained access to KiranaPro\u2019s root accounts on AWS and GitHub, Ravindran told TechCrunch.<\/p>\n<p class=\"wp-block-paragraph\">Ravindran shared a couple of screenshots of the GitHub security logs and a file containing a sample of activity logs around the time of the incident, suggesting that the hacking happened after someone gained access to their systems via a former employee\u2019s account.<\/p>\n<p class=\"wp-block-paragraph\">KiranaPro\u2019s chief technology officer Saurav Kumar told TechCrunch that the hack happened around May 24-25.<\/p>\n<p class=\"wp-block-paragraph\">The startup said it used Google Authenticator for multi-factor authentication on its AWS account. Kumar told TechCrunch that the multi-factor code had changed when they tried to log into their AWS account last week, and all their Electric Compute Cloud (EC2) services, which let clients access virtual computers to run their applications, were deleted.<\/p>\n<p class=\"wp-block-paragraph\">\u201cWe can only log in through the IAM [Identity and Access Management] account, through which we can see that the EC2 instances don\u2019t exist anymore, but we are not able to get any logs or anything because we don\u2019t have the root account,\u201d he said.<\/p>\n<p class=\"wp-block-paragraph\">KiranaPro has reached out to GitHub\u2019s support team to help identify the hacker\u2019s IP addresses and other traces of the incident, said Ravindran.<\/p>\n<p class=\"wp-block-paragraph\">Similarly, Ravindran told TechCrunch that the startup is filing cases against its former employees, who he said had not submitted their credentials for accessing their GitHub accounts to check their logs.<\/p>\n<p class=\"wp-block-paragraph\">It is unclear how the attack happened. Some of the biggest cyberattacks in recent years, such as <a href=\"https:\/\/techcrunch.com\/2022\/12\/22\/lastpass-customer-password-vaults-stolen\/\" target=\"_blank\" rel=\"noreferrer noopener\">LastPass<\/a>, <a href=\"https:\/\/techcrunch.com\/2024\/06\/21\/change-healthcare-confirms-ransomware-hackers-stole-medical-records-on-a-substantial-proportion-of-americans\/\" target=\"_blank\" rel=\"noreferrer noopener\">Change Healthcare<\/a>, and <a href=\"https:\/\/techcrunch.com\/2024\/06\/07\/snowflake-ticketmaster-lendingtree-customer-data-breach\/\" target=\"_blank\" rel=\"noreferrer noopener\">Snowflake<\/a>, were caused by credential theft, such as through <a href=\"https:\/\/techcrunch.com\/2025\/01\/31\/techcrunch-reference-guide-to-security-terminology\/#infostealers\" target=\"_blank\" rel=\"noopener\">password-stealing malware<\/a> installed on an employee\u2019s laptop, and missing or unenforced multi-factor authentication. <\/p>\n<p class=\"wp-block-paragraph\">The companies were ultimately responsible for enforcing the security of their own systems, including whether their employees must use multi-factor authentication, and terminating accounts of former employees who no longer work at their company.<\/p>\n<p class=\"wp-block-paragraph\">KiranaPro counts Blume Ventures, Unpopular Ventures, and Turbostart among its institutional venture backers, as well as Olympic medalist PV Sindhu and BCG MD Vikas Taneja among its angel investors. The company has a team of 15 employees located in Bengaluru and Kerala.<\/p>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/techcrunch.com\/2025\/06\/03\/indian-grocery-startup-kiranapro-was-hacked-and-its-servers-deleted-ceo-confirms\/\" target=\"_blank\" rel=\"noopener\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Indian grocery delivery startup KiranaPro has been hacked and all its data has been wiped, the company\u2019s founder confirmed to TechCrunch. The destroyed data included the company\u2019s app code and its servers containing banks of sensitive customer information, including their names, mailing addresses, and payment details, KiranaPro co-founder and CEO Deepak Ravindran told TechCrunch. The [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":172288,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[14],"tags":[],"class_list":{"0":"post-172287","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-tech"},"_links":{"self":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts\/172287","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/comments?post=172287"}],"version-history":[{"count":0,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts\/172287\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/media\/172288"}],"wp:attachment":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/media?parent=172287"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/categories?post=172287"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/tags?post=172287"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}