KiranaPro Faces Data Breach After Internal Security Lapse

KiranaPro Faces Data Breach After Internal Security Lapse

KiranaPro, a Bengaluru-based startup, is grappling with a significant security incident that has left it unable to access its back-end servers and resulted in the deletion of all its data, including app code, from GitHub.

Incident Overview

  • Co-founder and CEO Statement: Deepak Ravindran claimed the incident was an internal breach in a post on X.
  • TechCrunch Inquiry: When questioned about the nature of the breach, Ravindran acknowledged he could not rule out the possibility of a third party maliciously accessing a former employee’s account.

Security Concerns

  • Evidence Cited: Ravindran referenced a LinkedIn profile of one of KiranaPro’s former employees to support his claims.
  • Device Protections: He expressed uncertainty regarding whether adequate protections were in place on the former employee’s devices to prevent malware-related access.

Offboarding Process Issues

  • Employee Access: The company admitted it did not revoke the former employee’s access to its data and GitHub account after their departure.
  • HR Challenges: This oversight was attributed to poor handling of offboarding processes, exacerbated by the absence of full-time HR personnel. This situation highlights the security risks faced by companies lacking proper HR support.

Recovery Efforts

KiranaPro has since managed to restore both its AWS account and GitHub data by regaining control through backups from some employees.

FacebooktwitterlinkedinrssyoutubeFacebooktwitterlinkedinrssyoutube
FacebooktwitterredditpinterestlinkedinmailFacebooktwitterredditpinterestlinkedinmail

Leave a Comment

Your email address will not be published. Required fields are marked *