{"id":95549,"date":"2025-06-07T04:44:41","date_gmt":"2025-06-07T04:44:41","guid":{"rendered":"https:\/\/neclink.com\/index.php\/2025\/06\/07\/after-its-data-was-wiped-kiranapros-co-founder-cannot-rule-out-an-external-hack\/"},"modified":"2025-06-07T04:44:41","modified_gmt":"2025-06-07T04:44:41","slug":"after-its-data-was-wiped-kiranapros-co-founder-cannot-rule-out-an-external-hack","status":"publish","type":"post","link":"https:\/\/neclink.com\/index.php\/2025\/06\/07\/after-its-data-was-wiped-kiranapros-co-founder-cannot-rule-out-an-external-hack\/","title":{"rendered":"After its data was wiped, KiranaPro&#8217;s co-founder cannot rule out an external hack"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p id=\"speakable-summary\" class=\"wp-block-paragraph\">Indian grocery delivery startup KiranaPro\u2019s recent <a href=\"https:\/\/techcrunch.com\/2025\/06\/03\/indian-grocery-startup-kiranapro-was-hacked-and-its-servers-deleted-ceo-confirms\/\" target=\"_blank\" rel=\"noreferrer noopener\">data loss<\/a> story has more holes than Swiss cheese, as the startup remains unclear whether the incident was an internal breach or an external hack.<\/p>\n<p class=\"wp-block-paragraph\">Last week, the Bengaluru-based startup discovered that it could not access its back-end servers and that all its data, including its app code, had been deleted from GitHub. The startup on Friday blamed a former employee for the breach. However, in an interview, <a href=\"https:\/\/www.kirana.pro\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">KiranaPro<\/a> co-founder and CEO Deepak Ravindran conceded that the company had not deactivated the employee\u2019s account after they departed the company and cannot rule out the possibility of subsequent malicious misuse of their account.<\/p>\n<p class=\"wp-block-paragraph\">\u201cIf we go deeper, we have to do a real forensic investigation. We are going to talk [about] this with our board, the investors, and we are going to get a formal opinion on that also with our legal advisers,\u201d Ravindran told TechCrunch.<\/p>\n<p class=\"wp-block-paragraph\">Earlier on Friday, Ravindran claimed in a <a href=\"https:\/\/x.com\/deepakravindran\/status\/1930776943101894869\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">post on X<\/a> that the incident that affected its data was an internal breach.<\/p>\n<p class=\"wp-block-paragraph\">\u201cAfter careful investigation, we conclude that this was not a hack. No external party penetrated our ordering or payment systems, exploited vulnerabilities, or bypassed security protocols,\u201d he wrote.<\/p>\n<p class=\"wp-block-paragraph\">The co-founder also explicitly shared a screenshot of a LinkedIn profile of one of KiranaPro\u2019s former employees on X on Thursday, alleging that they had deleted the startup\u2019s code. (TechCrunch is not sharing the post\u2019s link, as the startup has yet to offer concrete proof supporting its position.)<\/p>\n<p class=\"wp-block-paragraph\">\u201c[T]his was an internal data breach. Specifically, it was the result of actions taken by a trusted internal employee who had legitimate access to our systems,\u201d the co-founder wrote in his post on Friday. \u201cThis individual intentionally deleted critical server logs while they were being tested and\/or edited, an action that goes directly against our policies, our principles, and the trust we place in our team.\u201d<\/p>\n<p class=\"wp-block-paragraph\">When TechCrunch asked if KiranaPro could rule out whether any third party had maliciously gained access to the former employee\u2019s account, Ravindran could not.<\/p>\n<p class=\"wp-block-paragraph\">\u201cWe have to do a complete forensic check on the company. We have to do the entire IP scan. We have to look at where the tracks happened. We have to check the computers, MacBooks, and whatever is used. Everything has to be done. Then we have to spend money\u00a0\u2026 so, that\u2019s why we decided not to,\u201d he told TechCrunch.<\/p>\n<p class=\"wp-block-paragraph\">Then what was the basis of Ravindran\u2019s allegation? It was a GitHub response, a copy of which he shared with TechCrunch.<\/p>\n<p class=\"wp-block-paragraph\">The response included a username, which Ravindran said was associated with the former employee.<\/p>\n<p class=\"wp-block-paragraph\">\u201cAll we have is the emails that we got from GitHub, stating that [the former employee\u2019s username] as an individual is the one who deleted the account. We haven\u2019t done the investigation further,\u201d Ravindran told TechCrunch. <\/p>\n<h2 class=\"wp-block-heading\" id=\"h-former-employee-s-account-was-never-offboarded\">Former employee\u2019s account was never offboarded<\/h2>\n<p class=\"wp-block-paragraph\">Launched in late 2024, KiranaPro operates as a buyer app on the Indian government\u2019s Open Network for Digital Commerce. The startup allows more than 55,000 customers in 50 cities to purchase groceries from their local shops and nearby supermarkets using its voice-based interface. The company also supports local language inputs, including English, Hindi, Malayalam, and Tamil.<\/p>\n<p class=\"wp-block-paragraph\">Ravindran stated that they decided to call out the former employee based on the company\u2019s \u201cbelief system,\u201d as they claim the former employee deleted the data after their sudden termination.<\/p>\n<p class=\"wp-block-paragraph\">However, the startup said it is not aware if there were enough protections on the former employee\u2019s devices, such as <a href=\"https:\/\/techcrunch.com\/2025\/04\/25\/techcrunch-reference-guide-to-security-terminology\/#multi-factor-authentication\">multi-factor authentication<\/a>, to restrict malicious third-party access, like malware. <\/p>\n<p class=\"wp-block-paragraph\">The company confirmed it did not remove the employee\u2019s access to its data and GitHub account following his departure.<\/p>\n<p class=\"wp-block-paragraph\">\u201cEmployee offboarding was not being handled properly because there was no full-time HR,\u201d KiranaPro\u2019s chief technology officer, Saurav Kumar, confirmed to TechCrunch.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-company-restores-aws-account-and-github-data\">Company restores AWS account and GitHub data<\/h2>\n<p class=\"wp-block-paragraph\">Alongside its code saved in GitHub, KiranaPro  also lost access to its Amazon Web Services (AWS) account, which included its customer data and their transaction details.<\/p>\n<p class=\"wp-block-paragraph\">Ravindran told TechCrunch that the GitHub data was restored after getting its backup from one of their employees. The startup also regained access to its AWS account along with its customer data.<\/p>\n<p class=\"wp-block-paragraph\">Both the co-founder and CTO said the AWS account was protected by multi-factor authentication, but neither could say how the account was accessed, as nobody else had physical access to Ravindran\u2019s phone, which generates the multi-factor code.<\/p>\n<p class=\"wp-block-paragraph\">Nonetheless, Ravindran claimed that the customer data stored in the AWS cloud remained intact and was not accessed by any third parties, nor was it downloaded by the former employee in question.<\/p>\n<p class=\"wp-block-paragraph\">\u201cBecause if that is the case, I will get its notification on email or anything [sic],\u201d he said.<\/p>\n<p class=\"wp-block-paragraph\">That said, Ravindran stated that the startup has enough evidence to file a formal complaint with the police, but said that its investigation is ongoing.<\/p>\n<p class=\"wp-block-paragraph\">The startup has also not fully paid its current employees, the company\u2019s co-founder confirmed, soon after the company raised a seed round of \u20b9100 million Indian rupees (about $1.2 million), which Ravindran said has yet to be fully wired.<\/p>\n<p class=\"wp-block-paragraph\">The startup counts Blume Ventures, Unpopular Ventures, and Turbostart among its institutional venture backers, as well as Olympic medalist PV Sindhu and Boston Consulting Group managing director Vikas Taneja among its angel investors. It has 15 employees located in Bengaluru and Kerala.<\/p>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/techcrunch.com\/2025\/06\/06\/after-its-data-was-wiped-kiranapros-co-founder-cannot-rule-out-an-external-hack\/\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Indian grocery delivery startup KiranaPro\u2019s recent data loss story has more holes than Swiss cheese, as the startup remains unclear whether the incident was an<\/p>\n","protected":false},"author":1,"featured_media":95550,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[178],"tags":[],"class_list":["post-95549","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-tech"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/neclink.com\/index.php\/wp-json\/wp\/v2\/posts\/95549","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/neclink.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/neclink.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/neclink.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/neclink.com\/index.php\/wp-json\/wp\/v2\/comments?post=95549"}],"version-history":[{"count":0,"href":"https:\/\/neclink.com\/index.php\/wp-json\/wp\/v2\/posts\/95549\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/neclink.com\/index.php\/wp-json\/wp\/v2\/media\/95550"}],"wp:attachment":[{"href":"https:\/\/neclink.com\/index.php\/wp-json\/wp\/v2\/media?parent=95549"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/neclink.com\/index.php\/wp-json\/wp\/v2\/categories?post=95549"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/neclink.com\/index.php\/wp-json\/wp\/v2\/tags?post=95549"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}