🧔♂️ A friendly human may check it before it goes live. More news here
Cyberattack hits Indian grocery delivery startup, data exposed
Indian grocery delivery startup KiranaPro has suffered a cyberattack that led to the deletion of its servers and sensitive customer data.
Co-founder and CEO Deepak Ravindran confirmed the incident on June 3, 2025.
The compromised data included app code, customer names, addresses, and payment details. Although the app is still online, it currently cannot process orders.
The attack happened between May 24 and May 25. Hackers gained access to KiranaPro’s AWS and GitHub root accounts, possibly using credentials from a former employee.
The startup, launched in December 2024, serves 55,000 customers in 50 cities and is backed by Blume Ventures, Unpopular Ventures, and Turbostart.
🔗 Source: TechCrunch
🧠 Food for thought
1️⃣ Indian food tech sector has history of security vulnerabilities
KiranaPro’s breach follows a pattern of security incidents in India’s food tech industry dating back several years.
In 2017, Zomato suffered a major breach affecting 17 million user records when hackers compromised an employee’s development account, exposing email addresses and hashed passwords 1.
That same year, McDonald’s India faced a similar crisis when a poorly configured server leaked approximately 2.2 million users’ personal data, including names, email addresses, home addresses, and phone numbers 2.
FreshMenu concealed a 2016 data breach affecting 110,000 users (exposing names, emails, phone numbers, and order histories) until it was revealed by security researchers in 2018, demonstrating the transparency challenges these incidents create 3.
These recurring breaches highlight persistent security vulnerabilities in India’s rapidly growing digital food services ecosystem, where user growth often outpaces security infrastructure development.
2️⃣ Former employee access management is a critical security blind spot
KiranaPro’s breach via a former employee’s account exemplifies a common yet dangerous security oversight in startups.
Research shows that properly implemented multi-factor authentication (MFA) can prevent up to 99.9% of account compromise attacks, yet many organizations fail to consistently enforce it across all accounts 4.
Stay updated on the go with our mobile app.
Get latest insights with smoother, more personalized experience through TIA mobile app.




