Tired of ads? Enjoy an ad-free experience by signing up.
๐Ÿ‘ฉโ€๐Ÿณ How we use AI at Tech in Asia, thoughtfully and responsibly.
๐Ÿง”โ€โ™‚๏ธ A friendly human may check it before it goes live. More news here

Indian grocery app flags insider breach, canโ€™t rule out hack

KiranaPro has indicated that the breach resulted from internal actions rather than an external hack.

Initial claims were based on GitHub emails linking the incident to the former employeeโ€™s username, but further investigation is needed to confirm this and the company cannot rule out an external hack.

Last week, KiranaPro discovered its backend servers were inaccessible and its app code had been deleted from GitHub.

Co-founder and CEO Deepak Ravindran said they did not deactivate the employeeโ€™s account upon departure, allowing potential misuse.

A full forensic investigation is pending, and the team plans to brief its board, investors, and legal advisors.

Chief technology officer Saurav Kumar acknowledged that, due to the lack of a full-time HR department, the former employeeโ€™s access to GitHub and other accounts was never revoked.

The startup also temporarily lost access to its AWS account, which held customer data and transaction details.

๐Ÿ”— Source: TechCrunch


๐Ÿง  Food for thought

1๏ธโƒฃ Poor offboarding practices represent a critical but overlooked security vulnerability

KiranaProโ€™s failure to deactivate a former employeeโ€™s account highlights a common security blindspot among startups.

Their CTO explicitly acknowledged this failure, stating, โ€œEmployee offboarding was not being handled properly because there was no full-time HR,โ€ revealing how basic security protocols are often neglected.

This reflects a broader pattern where overlooked vulnerabilities, rather than sophisticated attacks, are responsible for major breaches in India, with compromised credentials accounting for 16% of all cyber incidents 1.

The case demonstrates why proper account termination procedures are crucial, as 67% of victim companies experience multiple attacks, with cybercriminals often exploiting existing access points rather than creating new ones 2.

Indian organizationsโ€™ cybersecurity investments are projected to reach $4.5 billion by 2027. Yet, this incident shows how even basic security hygiene is frequently overlooked despite growing awareness 2.

2๏ธโƒฃ Indian startups face unique cybersecurity challenges amid escalating threats

Stay ahead in Asiaโ€™s tech landscape

You've reached your 2 free content limit for the month. Sign up for free to read the full story.

๐Ÿ„ For casual readers / ๐Ÿ‘ถ Free

Basic

US$0

Free forever

Get instant access to this article and more every month

0 premium content

Unlimited news briefs

5

5 articles

Ad-free reading experience

Just US$0 per day

โŒ›Sign up in 20s. No payment details needed.

๐Ÿ“– For learners / ๐Ÿ‘ Starter

Lite

US$4.92/month

Billed annually at US$59/year

Get instant access to this article and more every month

4

4 premium content

Unlimited news briefs & articles

Ad-free reading experience

Just US$0.17 per day

Cancel anytime

Our subscriber community includes professionals from these companies:

Stay updated on the go with our mobile app.

Get latest insights with smoother, more personalized experience through TIA mobile app.