In late May 2025, Indian grocery delivery startup KiranaPro suffered a catastrophic cyberattack that wiped out its servers, application code, and sensitive customer data. The breach, which has been described as one of the most severe in India’s quick-commerce sector, has halted the company’s operations and raised significant concerns about cybersecurity practices in startups. ChatGPT What Happened? KiranaPro, launched in December 2024, operated as a voice-enabled grocery ordering platform on the Indian government's Open Network for Digital Commerce (ONDC). What happened? On May 26, company executives discovered that their Amazon Web Services (AWS) and GitHub accounts had been compromised. Hackers had gained root access, deleted all Elastic Compute Cloud (EC2) instances, and wiped the application code repositories. The attackers also bypassed multi-factor authentication (MFA), possibly by exploiting unrevoked credentials from a former employee. The business has likely fallen out.
Download the medial app to read full posts, comements and news.