OquiliaOquiliaOquilia — India's Financial Intelligence Platform
Calculators
Compare
Tax
NRI
News
Investigations
Oquilia Advisor
HomeCalculatorsInvestigationsNews
View All CalculatorsSIP CalculatorEMI CalculatorIncome TaxFD CalculatorPPF CalculatorAll 150+ Calculators
View All CompareHome Loan RatesPersonal LoansCredit CardsHealth InsuranceTerm InsuranceMutual FundsFD RatesEducation Loan
View All TaxOld vs New RegimeTax Saving under 80CIncome Tax SlabsCapital Gains TaxSave Tax on SalaryITR Filing Guide
View All NRINRI Investment GuideNRI Tax FilingNRI Banking & NRE FDNRI Real EstateDTAA CalculatorNRE FD Calculator
View All NewsLatest NewsFraud & EnforcementInvestigationsBlog / GuidesReports
Investigations
View All ToolsAm I Underinsured?Policy AuditJargon DecoderMutual Fund Discovery
For Business
View All LearnFinancial GlossaryFAQAbout OquiliaContact
Oquilia Advisor
  1. Home
  2. News
  3. SEBI fines CDSL Rs 1 crore over 2022 depository malware attack
Enforcement

SEBI fines CDSL Rs 1 crore over 2022 depository malware attack

SEBI's adjudicating officer imposed a Rs 1 crore penalty on Central Depository Services (India) Ltd, finding cybersecurity lapses tied to a November 2022 malware attack that halted settlement operations for two days.

Oquilia Newsroom
Financial news desk covering SEBI, RBI, IRDAI, and Budget-related developments.
|Published 21 Jul 2026, 18:49 IST|7 min read · 1,602 words
Verified Sources|Last reviewed: 21 July 2026
SEBI fines CDSL Rs 1 crore over 2022 depository malware attack — Fraud & Enforcement on Oquilia

SEBI has imposed a monetary penalty of Rs 1 crore on Central Depository Services (India) Limited (CDSL) over cybersecurity lapses connected with a malware attack that struck the depository's systems on 18 November 2022. The action, taken by an adjudicating officer, is one of the larger cyber-related penalties SEBI has levied on a market infrastructure institution and lands on an entity that safeguards the demat holdings of crores of Indian investors.

The Enforcement Action

By an order dated 20 July 2026 (Ref. No. Order/JS/RJ/2026-27/32498-32500), SEBI adjudicating officer Jai Sebastian imposed a penalty totalling Rs 1,00,00,000 (Rupees one crore) on CDSL. The penalty is split into Rs 90,00,000 charged under Section 15HB of the SEBI Act, 1992 and Rs 10,00,000 under Section 19G of the Depositories Act, 1996. CDSL has been directed to remit the amount within 45 days through SEBI's online payment facility.

The order arises from an examination SEBI conducted into the failure of CDSL's systems and the discontinuation of its services after a malware attack on 18 November 2022, and what SEBI's examination described as CDSL's non-adherence to the cybersecurity framework mandated by the regulator. CDSL is registered with SEBI as a depository and is one of the two depositories in India that hold investors' securities in electronic form.

The order names three noticees: CDSL itself, Mr Rajesh Nadkarni, the then Chief Information Security Officer, and Mr Amit Mahajan, the then Chief Technology Officer. Importantly, the adjudication proceedings against the two individuals were disposed of without the imposition of any penalty. Only CDSL, as the registered depository, was penalised.

CDSL contested the case during the proceedings. Per its submissions recorded in the order, there was no loss to investors, no compromise of sensitive data, and no attempt to conceal the incident, and it argued that the matter did not warrant a further penalty given the remedial steps it had taken.

How the Scheme Worked

The order sets out a detailed, chronological account of the incident as SEBI's examination and the forensic Root Cause Analysis (RCA) describe it. On 18 November 2022 at around 03:00 hours, after the end-of-day operations, CDSL observed that several servers and end-user computers had become inaccessible. On investigation, this was found to be a malware attack. CDSL isolated the affected servers, disconnected its network to stop the malware spreading, and rebuilt a clean environment by creating a separate virtual local area network with scanned, clean desktops and servers. Recovery work was completed on 19 November 2022, and settlements scheduled for 18 November were carried out on 20 November.

The order records that the disruption was significant. According to the findings, the settlement process for on-market transactions and inter-depository transfers faced disruption for about 46 hours and 54.5 hours respectively, with a spillover effect because settlement activity across the wider securities market depended on CDSL functioning normally.

As to how the intrusion is said to have occurred, the RCA cited in the order points to several control gaps. The internet-facing ADFS server, per the order, was not included in the vulnerability assessment and penetration testing (VAPT), was not integrated with the Security Information and Event Management (SIEM) system, and was not brought under the Privileged Identity Management (PIM) tool. A network vulnerability scan had not been conducted, so a Remote Desktop Protocol port accessible from the internet was, per the RCA, not identified.

The order further records that a domain administrator account on the ADFS server used a weak password that, per the RCA, could be brute-forced through common dictionary attacks, and that the password was set to "Never Expire". The examination alleged this may have allowed persistent access, that privileged-account controls permitted lateral movement, and that the threat actor was able to stop the endpoint detection and response tool, disabling basic cybersecurity controls. CDSL, in response, explained the account arose from measures taken during the COVID-19 period and that its Remote Desktop Protocol access did not support two-factor authentication at the time. The proceedings ran through show-cause, replies and hearings held in September 2025, with further submissions filed up to March 2026.

The Law Invoked

The order was passed under Section 15-I of the SEBI Act, 1992 read with Rule 5 of the SEBI Adjudication Rules, 1995, and under Section 19H of the Depositories Act, 1996 read with Rule 5 of the corresponding Depositories Rules, 2005. These are the provisions that empower a SEBI adjudicating officer to hold an inquiry and impose penalties.

On the substantive charges, the examination alleged that CDSL violated Clauses 1, 5 and 9 of Part-D of the Third Schedule read with Regulation 17 of the SEBI (Depositories and Participants) Regulations, 2018, which set out the code of conduct and system requirements for depositories. It also alleged non-compliance with SEBI's cybersecurity and cyber-resilience circular dated 6 July 2015 (as modified on 20 May 2022) and an advisory dated 18 May 2020 on remote access and telecommuting.

The penalty itself was charged under two residuary provisions: Section 15HB of the SEBI Act and Section 19G of the Depositories Act. Both allow a penalty where a person fails to comply with a requirement and no specific penalty is otherwise provided. The order also notes that CDSL had earlier faced a financial disincentive of Rs 10 lakh under SEBI's standard operating procedure, dated 28 August 2019, for reporting cybersecurity incidents.

What Happens Next

An order of a SEBI adjudicating officer is appealable. The standard route is an appeal to the Securities Appellate Tribunal (SAT), and a SAT decision can, in turn, be taken to the Supreme Court on a question of law. The order records that CDSL relied on earlier SAT rulings during the proceedings, which indicates the depository is aware of, and may pursue, that appellate route.

Unless and until the order is stayed or set aside on appeal, CDSL must pay the Rs 1 crore penalty within 45 days through SEBI's online facility. The proceedings against the two named officials stand disposed of without penalty, so no monetary liability attaches to them under this order. Because this is a completed regulatory adjudication rather than a criminal proceeding, there is no trial to follow; what remains open is the appeal window.

What It Means

For ordinary investors, the immediate reassurance is that, per the record, the 2022 incident did not result in any loss of securities or money, and CDSL restored critical services within about two days. The penalty is a regulatory signal about process and controls at a systemically important institution, not evidence that anyone's holdings were taken.

The wider message is about how much rides on the cyber-resilience of market infrastructure. The order notes that CDSL safeguards digital assets belonging to roughly 8.3 crore beneficial owners, valued at around Rs 40 lakh crore, alongside securities of tens of thousands of issuers. SEBI's decision underlines that depositories are expected to keep every internet-facing system inside their testing, monitoring and access-control regimes, and that lapses such as untested servers, weak passwords or missing multi-factor authentication carry consequences even where no investor loses money.

The practical takeaway for investors is straightforward. Your demat account sits with a SEBI-registered depository, CDSL or NSDL, through a registered depository participant. You can verify a participant's registration on the SEBI and depository websites, enable the alerts the depositories offer, and review your consolidated account statements periodically so that any discrepancy is spotted early. Regulatory penalties of this kind are part of the oversight that keeps that system accountable.

FAQ

Is this SEBI penalty the same as a criminal conviction?

No. This is a civil regulatory penalty imposed by a SEBI adjudicating officer under the SEBI Act and the Depositories Act, not a criminal conviction. It records a finding of compliance lapses, is appealable before the Securities Appellate Tribunal, and the two named officials faced proceedings that were closed without any penalty.

What exactly did SEBI order?

By an order dated 20 July 2026, the adjudicating officer imposed a penalty totalling Rs 1 crore on CDSL: Rs 90 lakh under Section 15HB of the SEBI Act and Rs 10 lakh under Section 19G of the Depositories Act, payable within 45 days. Proceedings against the two officials were disposed without penalty.

Can the order be appealed?

Yes. An order of a SEBI adjudicating officer can be challenged before the Securities Appellate Tribunal, and a SAT ruling can be taken further to the Supreme Court on a question of law. The order notes CDSL cited earlier SAT rulings during the proceedings.

Were investors' securities or money lost in the 2022 attack?

Per CDSL's submissions recorded in the order, there was no loss to investors, no compromise of sensitive data and no attempt to conceal the incident. SEBI's finding concerns cybersecurity control lapses and the resulting service disruption, not any theft of investor holdings. Services were restored within about two days.

How can I check that my demat account and depository are properly regulated?

CDSL and NSDL are the two SEBI-registered depositories in India, and your demat account is opened through a depository participant registered with one of them. You can verify a participant's registration on the SEBI and depository websites and review your holdings through periodic statements.

Where can I read the official order?

The full 88-page adjudication order is published on SEBI's website under Enforcement, Orders, Orders of Adjudicating Officer. It carries the reference number Order/JS/RJ/2026-27/32498-32500 and sets out the findings, CDSL's responses, the provisions invoked and the penalty imposed.

This report is based on the official SEBI adjudication order dated 20 July 2026. It was surfaced via coverage aggregated on Google News.

This report describes enforcement actions and allegations on the public record, attributed to the officials cited. An order, FIR or chargesheet is not a conviction; parties are presumed innocent until proven guilty.

Named in this report, or spotted an error? Corrections and responses: editor@oquilia.com. We correct errors promptly and record responses from named parties.

Sources & Citations

  1. Adjudication Order in the matter of Central Depository Services (India) Limited malware attack on November 18, 2022 — Securities and Exchange Board of India

This article was last reviewed on 21 July 2026by Oquilia's editorial team. Every claim is sourced from primary regulatory materials (CBDT, IRDAI, RBI, SEBI, Indian Kanoon). View our methodology.

Found an error? Report an issue.

CalculatorsInsuranceInvestTaxLoansNRIMBAHNIAI
Oquilia

150+ calculators · Zero commissions

Oquilia

Intelligent financial analysis. 150+ calculators & unbiased analysis.

Data: IRDAI · RBI · SEBI · AMFI

Calculators

  • SIP
  • EMI
  • Income Tax
  • FD
  • PPF
  • NPS
  • Gratuity
  • HRA
  • ELSS
  • All 150+

Insurance

  • Compare Plans
  • Companies
  • Claims Data
  • Hospitals
  • Health Premium
  • Term Premium
  • Section 80D

Tax & Loans

  • Old vs New
  • Capital Gains
  • TDS
  • Home Loan EMI
  • Car Loan EMI
  • Rent vs Buy
  • Prepayment

More Tools

  • Invest Hub
  • Tax Planning
  • Loan Tools
  • Loan Harassment Help
  • NRI Hub
  • MBA Finance
  • HNI Wealth
  • Glossary
  • News
  • Blog
  • Reports
  • Tools
  • Oquilia Advisor

Company

  • About
  • Contact
  • FAQ
  • Legal Hub
  • Privacy
  • Terms
  • Disclaimer
  • Cookie Policy
  • Grievance
  • Disclosure

Newsletter

Monthly digest

Policy moves, deadline reminders, and the most-used calculators each month.

Designed & developed by QX137, React & Next.js studio

Regulatory & data sources

RBISEBIIRDAIIncome Tax DeptAMFIPFRDAOECD TaxBISWorld Bank

Regulatory data last updated: July 2026. Figures are cross-checked against primary IRDAI, SEBI, RBI, CBDT and AMFI publications before they ship.

© 2026 Oquilia. Not a licensed financial advisor. All third-party logos and trademarks belong to their respective owners.

PrivacyTermsDisclaimerSitemap