Tired of ads? Enjoy an ad-free experience by signing up.
👩‍🍳 How we use AI at Tech in Asia, thoughtfully and responsibly.
🧔‍♂️ A friendly human may check it before it goes live. More news here

Cyberattack hits Indian grocery delivery startup, data exposed

Indian grocery delivery startup KiranaPro has suffered a cyberattack that led to the deletion of its servers and sensitive customer data.

Co-founder and CEO Deepak Ravindran confirmed the incident on June 3, 2025.

The compromised data included app code, customer names, addresses, and payment details. Although the app is still online, it currently cannot process orders.

The attack happened between May 24 and May 25. Hackers gained access to KiranaPro’s AWS and GitHub root accounts, possibly using credentials from a former employee.

The startup, launched in December 2024, serves 55,000 customers in 50 cities and is backed by Blume Ventures, Unpopular Ventures, and Turbostart.

🔗 Source: TechCrunch


🧠 Food for thought

1️⃣ Indian food tech sector has history of security vulnerabilities

KiranaPro’s breach follows a pattern of security incidents in India’s food tech industry dating back several years.

In 2017, Zomato suffered a major breach affecting 17 million user records when hackers compromised an employee’s development account, exposing email addresses and hashed passwords 1.

That same year, McDonald’s India faced a similar crisis when a poorly configured server leaked approximately 2.2 million users’ personal data, including names, email addresses, home addresses, and phone numbers 2.

FreshMenu concealed a 2016 data breach affecting 110,000 users (exposing names, emails, phone numbers, and order histories) until it was revealed by security researchers in 2018, demonstrating the transparency challenges these incidents create 3.

These recurring breaches highlight persistent security vulnerabilities in India’s rapidly growing digital food services ecosystem, where user growth often outpaces security infrastructure development.

2️⃣ Former employee access management is a critical security blind spot

KiranaPro’s breach via a former employee’s account exemplifies a common yet dangerous security oversight in startups.

Research shows that properly implemented multi-factor authentication (MFA) can prevent up to 99.9% of account compromise attacks, yet many organizations fail to consistently enforce it across all accounts 4.

Stay ahead in Asia’s tech landscape

You've reached your 2 free content limit for the month. Sign up for free to read the full story.

🏄 For casual readers / 👶 Free

Basic

US$0

Free forever

Get instant access to this article and more every month

0 premium content

Unlimited news briefs

5

5 articles

Ad-free reading experience

Just US$0 per day

⌛Sign up in 20s. No payment details needed.

📖 For learners / 👍 Starter

Lite

US$4.92/month

Billed annually at US$59/year

Get instant access to this article and more every month

4

4 premium content

Unlimited news briefs & articles

Ad-free reading experience

Just US$0.17 per day

Cancel anytime

Our subscriber community includes professionals from these companies:

Stay updated on the go with our mobile app.

Get latest insights with smoother, more personalized experience through TIA mobile app.