- July 20, 2026
Sebi Slaps Rs 1 Crore Penalty On CDSL Over 2022 Malware Attack, Cybersecurity Failures
Last Updated:
The market regulator said CDSL failed to fix key cybersecurity gaps despite prior warnings, with the November 2022 malware attack disrupting settlement, critical depository ops.

Sebi imposed a Rs 1 crore penalty on CDSL over cybersecurity lapses linked to the 2022 malware attack, while dropping proceedings against its former CISO and CTO. (IMAGE: PTI)
The Securities and Exchange Board of India (Sebi) on Monday imposed a Rs 1 crore penalty on Central Depository Services (India) Ltd (CDSL) for cybersecurity lapses linked to the malware attack that crippled several of its systems in November 2022.
However, the market regulator dropped proceedings against CDSL’s former Chief Information Security Officer Rajesh Nadkarni and former Chief Technology Officer Amit Mahajan, saying the alleged lapses could not be held against them individually.
In its 88-page order, Sebi said CDSL failed to identify an internet-facing server as a critical asset, excluded it from mandatory security testing and did not implement basic cybersecurity safeguards despite repeated regulatory requirements.
The regulator said it had flagged these shortcomings to CDSL in August 2022, months before the malware attack, but the depository failed to fix them and instead relied on an earlier security assessment that Sebi found to be inadequate.
Sebi also said hackers had gained access to CDSL’s systems as early as November 2021, nearly a year before the attack was detected. It flagged several policy lapses, including an administrator account whose password was set to never expire even after Covid-era relaxations had ended.
The November 18, 2022 attack infected 135 of CDSL’s 547 servers and 177 of its 506 desktops and laptops, disrupting critical operations such as securities settlement, pay-in/pay-out and pledge-related services.
According to Sebi, key settlement systems remained disrupted for nearly 47 hours, while inter-depository transfer services were affected for more than 54 hours, impacting the smooth functioning of India’s securities market.
“The disruption… had a major spillover impact as the settlement activities for the entire securities market were also dependent upon the normal functioning of CDSL systems,” the regulator said.
Explaining why the former CISO and CTO were not penalised, Sebi said decisions relating to identifying critical assets, approving password policy deviations and conducting vulnerability assessments were institutional in nature and involved oversight from CDSL’s Systems and Technology Committee (SCOT) and its board.
While imposing the penalty, Sebi said it had taken into account the critical role played by depositories in maintaining market integrity and investor confidence. It also noted that CDSL had undertaken remedial measures after the incident and had already paid a separate Rs 10 lakh financial disincentive under the regulator’s cyber incident reporting framework.
The regulator imposed a Rs 90 lakh penalty under the Sebi Act and an additional Rs 10 lakh under the Depositories Act, directing CDSL to pay the amount within 45 days.
A single successful cyberattack on a major exchange or depository can disrupt markets nationally, erase wealth, and shake public confidence.
About the Author

Shankhyaneel Sarkar is a senior subeditor at News18. He covers international affairs, where he focuses on breaking news to in-depth analyses. He has over five years of experience during which he has c…Read More
Read More