OquiliaOquiliaOquilia — India's Financial Intelligence Platform
Calculators
Compare
Tax
NRI
News
Investigations
Oquilia Advisor
HomeCalculatorsInvestigationsNews
View All CalculatorsSIP CalculatorEMI CalculatorIncome TaxFD CalculatorPPF CalculatorAll 150+ Calculators
View All CompareHome Loan RatesPersonal LoansCredit CardsHealth InsuranceTerm InsuranceMutual FundsFD RatesEducation Loan
View All TaxOld vs New RegimeTax Saving under 80CIncome Tax SlabsCapital Gains TaxSave Tax on SalaryITR Filing Guide
View All NRINRI Investment GuideNRI Tax FilingNRI Banking & NRE FDNRI Real EstateDTAA CalculatorNRE FD Calculator
View All NewsLatest NewsFraud & EnforcementInvestigationsBlog / GuidesReports
Investigations
View All ToolsAm I Underinsured?Policy AuditJargon DecoderMutual Fund Discovery
For Business
View All LearnFinancial GlossaryFAQAbout OquiliaContact
Oquilia Advisor
  1. Home
  2. News
  3. SEBI fines CDSL Rs 1 crore over 2022 depository malware attack
Enforcement

SEBI fines CDSL Rs 1 crore over 2022 depository malware attack

SEBI has penalised depository CDSL Rs 1 crore for cybersecurity lapses tied to a November 2022 malware attack that disrupted settlement for days. The 88-page order is appealable to the SAT.

Oquilia Newsroom
Financial news desk covering SEBI, RBI, IRDAI, and Budget-related developments.
|Published 20 Jul 2026, 21:09 IST|7 min read · 1,481 words
Verified Sources|Last reviewed: 20 July 2026
SEBI fines CDSL Rs 1 crore over 2022 depository malware attack — Fraud & Enforcement on Oquilia

The Enforcement Action

The Securities and Exchange Board of India (SEBI) has imposed a penalty of Rs 1 crore on Central Depository Services (India) Limited (CDSL), one of the country's two securities depositories, for cybersecurity lapses connected to a malware attack that disrupted its systems on 18 November 2022. The adjudication order, dated 20 July 2026 and running to 88 pages, splits the penalty into Rs 90 lakh under the SEBI Act and Rs 10 lakh under the Depositories Act, and directs CDSL to pay within 45 days.

CDSL holds the demat accounts of a very large share of India's retail investors, so an outage in its core systems reaches directly into the securities-holding infrastructure that ordinary shareholders rely on. SEBI found that a malware infection spread across a large part of CDSL's server and end-user estate and interrupted settlement and related depository functions for a period measured in days rather than hours.

The order also examined the conduct of two former CDSL officials named in the proceedings, the then Chief Information Security Officer Rajesh Nadkarni and the then Chief Technology Officer Amit Mahajan. According to the order, the adjudicating officer did not impose a monetary penalty on either of the two former officials; the penalty falls on CDSL as the regulated entity. CDSL has not, on the public record so far, issued a detailed response to the specific findings, and the order remains appealable before the Securities Appellate Tribunal.

How the Scheme Worked

This matter is not an investor-facing scam but an operational-security failure, and the order describes the incident in sequence. According to the order, attackers are said to have gained a foothold in CDSL's environment as early as November 2021, close to a year before the malware was detected on 18 November 2022. That dwell time, per SEBI's findings, meant the intrusion went unnoticed while the depository's routine operations continued.

When the malware activated, it spread widely. Per the order, 135 of CDSL's 547 servers were infected, along with 177 of its 506 desktops and laptops. The practical effect was a halt to core depository processing: the settlement process was disrupted for about 46 hours, and inter-depository transfers for roughly 54.5 hours, according to the figures recorded in the order. The activities affected included settlement, pay-in and pay-out, and pledge operations, the machinery through which shares move between accounts when investors buy, sell or pledge securities.

SEBI's findings, as set out in the order, trace the breach to specific gaps. The order records that CDSL did not classify its internet-facing Active Directory Federation Services (ADFS) server as a critical asset, and consequently excluded it from vulnerability assessment and penetration testing (VAPT), the periodic security testing meant to surface exactly this kind of exposure. The order also notes weaknesses in basic controls, including a password policy under which administrator accounts were set never to expire.

Crucially, the order states that SEBI had flagged cybersecurity deficiencies to CDSL as early as August 2022, months before the attack, and that these were not adequately addressed. In an earlier procedural step, CDSL had also faced a Rs 10 lakh disincentive under a standard operating procedure relating to cybersecurity-incident reporting. The present adjudication proceeding followed a show-cause notice, with CDSL given the opportunity to respond before the order was passed.

The Law Invoked

The penalty is imposed under two statutes named in the order. The SEBI Act, 1992 is the principal law governing the securities market and empowers the regulator to penalise regulated entities for failures to comply with its requirements; the Rs 90 lakh component sits here. The Depositories Act, 1996, which specifically governs depositories such as CDSL and NSDL, supplies the Rs 10 lakh component.

Underlying the charge is SEBI's cyber-security and cyber-resilience framework for depositories, the body of circular-based requirements that obliges market-infrastructure institutions to classify critical systems, conduct regular VAPT, enforce access controls and report incidents within prescribed timelines. The order assesses CDSL's conduct against that framework and concludes, on the facts recorded, that the depository fell short of several of its obligations.

Because the 88-page order sets out the precise provisions and circular clauses it relies on, readers who need the exact section references should consult the order itself rather than any secondary summary. What is clear from the record is the nature of the proceeding: a regulatory adjudication that results in a monetary penalty, not a criminal prosecution, and one that CDSL can contest on appeal.

What Happens Next

A SEBI adjudication order is not the final word. Under the SEBI Act, CDSL may appeal to the Securities Appellate Tribunal (SAT) within the prescribed period, and a further appeal on a question of law lies to the Supreme Court. Until any such challenge is decided, the order stands and the Rs 1 crore penalty is payable within the 45-day window the order sets.

For the two former officials named in the proceedings, the order's disposal without a monetary penalty closes that part of the matter at the adjudication stage. CDSL, as the penalised entity, must both pay and be able to demonstrate that the identified control gaps have been remediated, a supervisory expectation that typically continues well beyond the payment itself.

This remains a regulatory finding rather than a court verdict, and CDSL retains its appeal rights. Nothing in the order, on the record available, suggests investor holdings were lost, and the penalty addresses the adequacy of CDSL's controls rather than any loss of securities.

What It Means

For ordinary investors, the reassuring part of this order is what it does not say: there is no finding that demat holdings were stolen or that securities were permanently lost. The harm SEBI penalised was operational, a failure of preventive controls that left a depository at the centre of the market exposed to being knocked offline. The order's value is as a signal that the regulator will hold market-infrastructure institutions to their cybersecurity obligations even where no investor money goes missing.

The practical takeaway is about resilience, not alarm. Investors can and should keep their own records of holdings, download and retain the periodic Consolidated Account Statement (CAS) issued by the depositories, and reconcile it against broker statements, so that any discrepancy after an outage is easy to spot. It is also worth remembering that both CDSL and NSDL are SEBI-regulated, and their registration, and the registration of your broker, can be verified on the SEBI website, a habit that protects against the very different risk of dealing with an unregistered intermediary.

More broadly, the order is a reminder that the plumbing of the market, the depositories, clearing corporations and exchanges, carries systemic importance. Firm, documented enforcement of cyber-resilience standards is how that plumbing is kept trustworthy.

FAQ

What exactly did SEBI order?

Per the order dated 20 July 2026, SEBI imposed a total penalty of Rs 1 crore on CDSL, Rs 90 lakh under the SEBI Act and Rs 10 lakh under the Depositories Act, for cybersecurity lapses connected to the 18 November 2022 malware attack that disrupted its systems. The penalty is payable within 45 days.

Is this SEBI order a criminal conviction?

No. This is a regulatory adjudication, not a criminal case. SEBI's order is a civil finding of non-compliance that CDSL can appeal to the Securities Appellate Tribunal; it is not a criminal conviction. The two former officials named in the proceedings were not penalised. Any characterisation of wrongdoing here is SEBI's finding, and it is subject to appeal.

Were my shares or demat holdings affected?

According to the record, the incident disrupted settlement and inter-depository transfer operations for a matter of days, but the order does not find that investor securities were stolen or permanently lost. It penalises the adequacy of CDSL's cybersecurity controls rather than any loss of holdings.

Can the order be appealed?

Yes. A SEBI adjudication order can be challenged before the Securities Appellate Tribunal (SAT), with a further appeal on a question of law to the Supreme Court. Until then, the order stands and the penalty is payable within the timeline set in the order.

How can I keep my own holdings safe?

Retain the Consolidated Account Statement (CAS) sent by the depository, reconcile it against your broker statements, and verify that your broker and depository are SEBI-registered via the SEBI website. Good personal record-keeping is the simplest safeguard against confusion after any outage.

Where can I read the official order?

The full 88-page adjudication order is published on SEBI's website in its enforcement orders section, in the matter of the CDSL malware attack of 18 November 2022.

This report is based on the official SEBI adjudication order in the matter of the CDSL malware attack of 18 November 2022, dated 20 July 2026, published on the SEBI website. The action was also reported in the business press, including The Economic Times.

This report describes enforcement actions and allegations on the public record, attributed to the officials cited. An order, FIR or chargesheet is not a conviction; parties are presumed innocent until proven guilty.

Named in this report, or spotted an error? Corrections and responses: editor@oquilia.com. We correct errors promptly and record responses from named parties.

Sources & Citations

  1. Adjudication Order in the matter of Central Depository Services India Limited malware attack on November 18, 2022 — SEBI
  2. Sebi imposes Rs 1 crore penalty on CDSL over 2022 malware attack — The Economic Times

This article was last reviewed on 20 July 2026by Oquilia's editorial team. Every claim is sourced from primary regulatory materials (CBDT, IRDAI, RBI, SEBI, Indian Kanoon). View our methodology.

Found an error? Report an issue.

CalculatorsInsuranceInvestTaxLoansNRIMBAHNIAI
Oquilia

150+ calculators · Zero commissions

Oquilia

Intelligent financial analysis. 150+ calculators & unbiased analysis.

Data: IRDAI · RBI · SEBI · AMFI

Calculators

  • SIP
  • EMI
  • Income Tax
  • FD
  • PPF
  • NPS
  • Gratuity
  • HRA
  • ELSS
  • All 150+

Insurance

  • Compare Plans
  • Companies
  • Claims Data
  • Hospitals
  • Health Premium
  • Term Premium
  • Section 80D

Tax & Loans

  • Old vs New
  • Capital Gains
  • TDS
  • Home Loan EMI
  • Car Loan EMI
  • Rent vs Buy
  • Prepayment

More Tools

  • Invest Hub
  • Tax Planning
  • Loan Tools
  • Loan Harassment Help
  • NRI Hub
  • MBA Finance
  • HNI Wealth
  • Glossary
  • News
  • Blog
  • Reports
  • Tools
  • Oquilia Advisor

Company

  • About
  • Contact
  • FAQ
  • Legal Hub
  • Privacy
  • Terms
  • Disclaimer
  • Cookie Policy
  • Grievance
  • Disclosure

Newsletter

Monthly digest

Policy moves, deadline reminders, and the most-used calculators each month.

Designed & developed by QX137, React & Next.js studio

Regulatory & data sources

RBISEBIIRDAIIncome Tax DeptAMFIPFRDAOECD TaxBISWorld Bank

Regulatory data last updated: July 2026. Figures are cross-checked against primary IRDAI, SEBI, RBI, CBDT and AMFI publications before they ship.

© 2026 Oquilia. Not a licensed financial advisor. All third-party logos and trademarks belong to their respective owners.

PrivacyTermsDisclaimerSitemap