OquiliaOquiliaOquilia — India's Financial Intelligence Platform
Calculators
Compare
Tax
NRI
News
Investigations
Oquilia Advisor
HomeCalculatorsInvestigationsNews
View All CalculatorsSIP CalculatorEMI CalculatorIncome TaxFD CalculatorPPF CalculatorAll 150+ Calculators
View All CompareHome Loan RatesPersonal LoansCredit CardsHealth InsuranceTerm InsuranceMutual FundsFD RatesEducation Loan
View All TaxOld vs New RegimeTax Saving under 80CIncome Tax SlabsCapital Gains TaxSave Tax on SalaryITR Filing Guide
View All NRINRI Investment GuideNRI Tax FilingNRI Banking & NRE FDNRI Real EstateDTAA CalculatorNRE FD Calculator
View All NewsLatest NewsFraud & EnforcementInvestigationsBlog / GuidesReports
Investigations
View All ToolsAm I Underinsured?Policy AuditJargon DecoderMutual Fund Discovery
For Business
View All LearnFinancial GlossaryFAQAbout OquiliaContact
Oquilia Advisor
  1. Home
  2. News
  3. SEBI fines CDSL Rs 1 crore over 2022 malware attack lapses
Enforcement

SEBI fines CDSL Rs 1 crore over 2022 malware attack lapses

SEBI has imposed a Rs 1 crore penalty on depository CDSL, holding that cyber-security lapses preceded a November 2022 malware attack that infected 135 servers and disrupted settlements.

Oquilia Newsroom
Financial news desk covering SEBI, RBI, IRDAI, and Budget-related developments.
|Published 21 Jul 2026, 16:27 IST|7 min read · 1,471 words
Verified Sources|Last reviewed: 21 July 2026
SEBI fines CDSL Rs 1 crore over 2022 malware attack lapses — Fraud & Enforcement on Oquilia

The Enforcement Action

The Securities and Exchange Board of India (SEBI) has imposed a penalty of Rs 1 crore on Central Depository Services (India) Limited (CDSL), one of the country's two securities depositories, over cyber-security lapses that SEBI found preceded a malware attack on CDSL's systems on 18 November 2022. The penalty was set out in an adjudication order dated 20 July 2026, passed by SEBI's adjudicating officer.

The order splits the penalty into two parts: Rs 90 lakh imposed under Section 15HB of the SEBI Act, 1992, and Rs 10 lakh under Section 19G of the Depositories Act, 1996, per the order. Both are residuary penalty provisions that SEBI invokes where a contravention has no separately specified penalty. CDSL holds the demat accounts of a large share of India's retail investors, which is why a settlement-day disruption at the depository is treated as a systemic concern rather than a routine IT incident.

SEBI's action followed a show-cause process in which the regulator examined how the November 2022 malware reached CDSL's network and why its defences did not contain it sooner. The order records that the attack disrupted CDSL's operations for a period the regulator assessed at between roughly 46 and 54.5 hours, during which pay-in and pay-out settlement functions and other critical services were affected. The order is a regulatory finding and is appealable to the Securities Appellate Tribunal (SAT). CDSL, a listed company, has not publicly disputed the order at the time of writing and retains its right of appeal.

How the Scheme Worked

The order sets out, in the regulator's account, how the intrusion unfolded and where CDSL's controls fell short. According to SEBI, the attacker reached CDSL's environment through an exposed Remote Desktop Protocol (RDP) port, a common remote-access channel that, left open to the internet, can be probed and exploited.

Central to SEBI's findings is a server running Active Directory Federation Services (ADFS), which manages authentication across systems. The order records that CDSL had not classified this ADFS server as a critical asset, per SEBI's account. That classification matters because SEBI's cyber-security and cyber-resilience framework for depositories requires the most sensitive systems to receive the strictest protection, including mandatory vulnerability assessment and penetration testing (VAPT) and integration with real-time security monitoring. Because the server was not treated as critical, the order states, it did not receive those mandatory checks.

SEBI further found access-control weaknesses. The order notes there was no account lock-out policy to freeze a login after three failed attempts, a basic control that blunts password-guessing, according to the regulator's findings. Once inside, per the order, the malware spread widely: SEBI's account records that it infected 135 servers and 177 computers across CDSL's estate.

The regulator's timeline runs from the intrusion on 18 November 2022, through the disruption to settlement services, to CDSL's restoration of operations. On the basis of this sequence, SEBI concluded that the depository's cyber-security posture did not meet the standard its framework requires, and moved from the show-cause stage to the final adjudication order dated 20 July 2026.

The Law Invoked

The penalties rest on two residuary provisions. Section 15HB of the SEBI Act, 1992, allows SEBI to levy a penalty of up to Rs 1 crore where a person fails to comply with a requirement of the Act, its rules or regulations and no specific penalty is otherwise provided. The order imposes Rs 90 lakh under this section.

Section 19G of the Depositories Act, 1996, is the parallel residuary penalty provision under the statute that governs depositories such as CDSL, and the order imposes Rs 10 lakh under it. Because CDSL operates as a depository, both statutes apply to its conduct, which is why SEBI split the penalty across the two Acts.

The substantive obligations SEBI found unmet flow from its cyber-security and cyber-resilience framework for depositories, which prescribes how market infrastructure institutions must classify assets, test systems and monitor for intrusions. The order treats a breach of that framework as the contravention that attracts the residuary penalties above. SEBI's findings, being an adjudication, are appealable and have not been tested on appeal at the time of writing.

What Happens Next

An adjudication order of this kind is a completed regulatory action, but not the final word. CDSL may appeal to the Securities Appellate Tribunal within the prescribed period, and the SAT can uphold, reduce or set aside the penalty; a further appeal on a question of law lies to the Supreme Court. Unless stayed, the penalty is payable as directed in the order.

For the depository itself, the more consequential effect is usually remedial rather than monetary. SEBI's findings put on record specific control gaps - asset classification, VAPT, monitoring and access controls - that a market infrastructure institution is expected to close and to demonstrate it has closed, typically through follow-up audits and reporting to the regulator.

For investors, the order changes nothing about the ownership of their holdings. Demat balances are records maintained by the depository and were not reported to have been altered; the 2022 incident affected the availability of settlement services for a period, not the title to securities. These points remain as stated in the order and are subject to any revision on appeal.

What It Means

The order is a reminder that India's market plumbing is regulated for resilience, not just for conduct. Depositories, exchanges and clearing corporations are classified as market infrastructure institutions precisely because an outage at any one of them can freeze settlement for the whole market. SEBI's willingness to penalise a systemically important institution over how it configured a single authentication server signals that the regulator treats cyber-hygiene failures as compliance failures.

For ordinary investors, the practical takeaways are modest but real. Your securities are held in demat form across two depositories, CDSL and NSDL, and both are regulated entities; you can verify your holdings independently through the consolidated account statement (CAS) you receive and through your depository participant. If a settlement delay ever affects a trade, the audit trail sits with the depository and your broker, not with you.

The broader lesson is about operational risk. The gaps SEBI described - an unclassified critical server, a missing lock-out policy, an exposed remote-access port - are the same failures that recur across cyber incidents. That the regulator has spelled them out in a public order gives every other regulated intermediary a plain checklist of what reasonable cyber-security is expected to look like.

FAQ

What exactly did SEBI order?

SEBI imposed a total penalty of Rs 1 crore on CDSL - Rs 90 lakh under Section 15HB of the SEBI Act, 1992, and Rs 10 lakh under Section 19G of the Depositories Act, 1996 - through an adjudication order dated 20 July 2026. SEBI found cyber-security lapses connected to a malware attack on CDSL's systems on 18 November 2022.

Does this mean investors' shares are at risk?

No. The order concerns the availability of settlement services during the 2022 incident, not the ownership of securities. Demat holdings are records maintained by the depository and were not reported to have been altered. Investors can independently verify their holdings through their consolidated account statement and depository participant.

Can CDSL appeal the penalty?

Yes. A SEBI adjudication order can be challenged before the Securities Appellate Tribunal (SAT) within the prescribed time, and the SAT may uphold, reduce or set aside the penalty. A further appeal on a question of law lies to the Supreme Court. Until any stay, the penalty stands as ordered.

What were the specific lapses SEBI identified?

According to the order, CDSL did not classify an Active Directory Federation Services server as a critical asset, so it did not receive mandatory vulnerability assessment and penetration testing or real-time monitoring; an exposed Remote Desktop Protocol port was used in the intrusion; and there was no policy to lock an account after three failed login attempts. SEBI recorded that malware infected 135 servers and 177 computers.

How can I check that my depository and broker are registered?

Every depository, depository participant and broker in India is registered with SEBI. You can confirm registration through the intermediary lists on SEBI's website and cross-check your account against the consolidated account statement issued by CDSL or NSDL. Registration details and grievance routes are also displayed on your broker's official pages.

Where can I read the official order?

The full adjudication order dated 20 July 2026 is published on SEBI's website in its enforcement orders section for July 2026, in the matter of the CDSL malware attack of 18 November 2022.

This report is based on the official SEBI adjudication order dated 20 July 2026 in the matter of the CDSL malware attack of 18 November 2022. It was surfaced via coverage carried on Google News.

This report describes enforcement actions and allegations on the public record, attributed to the officials cited. An order, FIR or chargesheet is not a conviction; parties are presumed innocent until proven guilty.

Named in this report, or spotted an error? Corrections and responses: editor@oquilia.com. We correct errors promptly and record responses from named parties.

Sources & Citations

  1. Adjudication Order in the matter of Central Depository Services India Limited malware attack on November 18, 2022 — SEBI

This article was last reviewed on 21 July 2026by Oquilia's editorial team. Every claim is sourced from primary regulatory materials (CBDT, IRDAI, RBI, SEBI, Indian Kanoon). View our methodology.

Found an error? Report an issue.

CalculatorsInsuranceInvestTaxLoansNRIMBAHNIAI
Oquilia

150+ calculators · Zero commissions

Oquilia

Intelligent financial analysis. 150+ calculators & unbiased analysis.

Data: IRDAI · RBI · SEBI · AMFI

Calculators

  • SIP
  • EMI
  • Income Tax
  • FD
  • PPF
  • NPS
  • Gratuity
  • HRA
  • ELSS
  • All 150+

Insurance

  • Compare Plans
  • Companies
  • Claims Data
  • Hospitals
  • Health Premium
  • Term Premium
  • Section 80D

Tax & Loans

  • Old vs New
  • Capital Gains
  • TDS
  • Home Loan EMI
  • Car Loan EMI
  • Rent vs Buy
  • Prepayment

More Tools

  • Invest Hub
  • Tax Planning
  • Loan Tools
  • Loan Harassment Help
  • NRI Hub
  • MBA Finance
  • HNI Wealth
  • Glossary
  • News
  • Blog
  • Reports
  • Tools
  • Oquilia Advisor

Company

  • About
  • Contact
  • FAQ
  • Legal Hub
  • Privacy
  • Terms
  • Disclaimer
  • Cookie Policy
  • Grievance
  • Disclosure

Newsletter

Monthly digest

Policy moves, deadline reminders, and the most-used calculators each month.

Designed & developed by QX137, React & Next.js studio

Regulatory & data sources

RBISEBIIRDAIIncome Tax DeptAMFIPFRDAOECD TaxBISWorld Bank

Regulatory data last updated: July 2026. Figures are cross-checked against primary IRDAI, SEBI, RBI, CBDT and AMFI publications before they ship.

© 2026 Oquilia. Not a licensed financial advisor. All third-party logos and trademarks belong to their respective owners.

PrivacyTermsDisclaimerSitemap