OquiliaOquiliaOquilia — India's Financial Intelligence Platform
Calculators
Compare
Tax
NRI
News
Investigations
Oquilia Advisor
HomeCalculatorsInvestigationsNews
View All CalculatorsSIP CalculatorEMI CalculatorIncome TaxFD CalculatorPPF CalculatorAll 150+ Calculators
View All CompareHome Loan RatesPersonal LoansCredit CardsHealth InsuranceTerm InsuranceMutual FundsFD RatesEducation Loan
View All TaxOld vs New RegimeTax Saving under 80CIncome Tax SlabsCapital Gains TaxSave Tax on SalaryITR Filing Guide
View All NRINRI Investment GuideNRI Tax FilingNRI Banking & NRE FDNRI Real EstateDTAA CalculatorNRE FD Calculator
View All NewsLatest NewsFraud & EnforcementInvestigationsBlog / GuidesReports
Investigations
View All ToolsAm I Underinsured?Policy AuditJargon DecoderMutual Fund Discovery
For Business
View All LearnFinancial GlossaryFAQAbout OquiliaContact
Oquilia Advisor
  1. Home
  2. News
  3. SEBI fines CDSL Rs 1 crore over 2022 malware attack lapses
Enforcement

SEBI fines CDSL Rs 1 crore over 2022 malware attack lapses

SEBI's adjudicating officer imposed a Rs 1 crore penalty on Central Depository Services over cybersecurity lapses tied to the November 2022 malware attack that disrupted settlements.

Oquilia Newsroom
Financial news desk covering SEBI, RBI, IRDAI, and Budget-related developments.
|Published 21 Jul 2026, 10:28 IST|7 min read · 1,605 words
Verified Sources|Last reviewed: 21 July 2026
SEBI fines CDSL Rs 1 crore over 2022 malware attack lapses — Fraud & Enforcement on Oquilia

The Enforcement Action

The Securities and Exchange Board of India has imposed a penalty of Rs 1,00,00,000 (Rupees One Crore) on Central Depository Services (India) Limited (CDSL), India's largest depository, over cybersecurity lapses linked to the malware attack that disrupted its systems on 18 November 2022. The penalty was ordered by adjudicating officer Jai Sebastian in an order dated 20 July 2026, carrying reference number Order/JS/RJ/2026-27/32498-32500 and passed at Mumbai.

The penalty is split across two statutes. Per the order, SEBI imposed Rs 90,00,000 on CDSL under Section 15HB of the SEBI Act, 1992, and a further Rs 10,00,000 under Section 19G of the Depositories Act, 1996. CDSL has been directed to pay the amount within 45 days through SEBI's online payment facility. The order records that CDSL is registered with SEBI as a depository and, per its FY23 annual report cited by the adjudicating officer, manages roughly 70 per cent of the country's demat accounts.

The order also named two individuals as noticees: Mr Rajesh Nadkarni, the then Chief Information Security Officer, and Mr Amit Mahajan, the then Chief Technology Officer. The adjudicating officer disposed of the proceedings against both without imposing any monetary penalty. A SEBI adjudication is a regulatory finding that is appealable to the Securities Appellate Tribunal, not a criminal conviction.

How the Scheme Worked

According to the order, at 03:00 hours on Friday, 18 November 2022, after end-of-day operations, a few CDSL servers and end-user computers were found to be inaccessible, and the cause was traced to a malware attack. CDSL isolated its servers and end-user computers and disconnected its network to stop the infection spreading, then rebuilt operations on a separate virtual local area network with clean, scanned machines. The order notes that the recovery exercise was completed on 19 November 2022 and that settlements scheduled for 18 November were carried out on Sunday, 20 November 2022.

The disruption was substantial. The order records that 135 of 547 servers and 177 of 506 desktops and laptops were infected across CDSL's primary and disaster-recovery sites. As a direct consequence, the order states, critical depository activities including settlement pay-in and pay-out and margin-related pledge and unpledge activities were not carried out on 18 November 2022. The settlement process faced disruption for about 46 hours and inter-depository transfers for about 54.5 hours, per the order, which observed that the outage had a "major spillover impact" on settlement activity for the wider securities market.

The adjudicating officer traced the incident to failures that, in his words, "had built up over time". The order records that the attacker had obtained access to CDSL's servers in November 2021, roughly a year before the attack was discovered in November 2022. It notes that CDSL created an administrator account in 2021 whose password was set never to expire, and that a relaxation of the account lock-out threshold to three failed attempts was not addressed until the malware attack. These deviations, the order says, continued even after the COVID-19 situation normalised.

Central to the finding is an Active Directory Federation Service (ADFS) server. Per the order, this internet-facing asset was excluded from CDSL's vulnerability assessment and penetration testing (VAPT) exercise and was not classified as a critical asset, despite a SEBI circular dated 20 May 2022 requiring every internet-facing system to be so classified. The order records that SEBI, by a letter dated 30 August 2022, had drawn CDSL's attention to this deficiency, but that CDSL "chose not to act" and relied on an earlier VAPT exercise found to be deficient. The ADFS server was also absent from the critical-assets list approved by CDSL's standing committee on technology on 12 September 2022, the order states.

The matter followed the standard adjudication route. A show-cause notice, reference SEBI/HO/EAD2/NH/RJ/2024/33455 dated 24 October 2024, was issued to the noticees. After the earlier adjudicating officer superannuated, the present officer was appointed by a communique dated 4 April 2025 to complete the proceedings.

The Law Invoked

The order sets out the specific provisions the show-cause notice alleged CDSL had breached. These include Clauses 1, 5 and 9 of Part-D of the Third Schedule read with Regulation 17 of the SEBI (Depositories and Participants) Regulations, 2018, which frame a depository's obligations for internal controls and systems. The notice also cited the SEBI Advisory dated 18 May 2020 on remote access and telecommuting, and numbered paragraphs of Annexure A of the SEBI cybersecurity circular dated 6 July 2015 as modified by the circular dated 20 May 2022, along with SEBI circulars dated 22 March 2021 and 7 December 2018 on cyber security and cyber resilience.

For the two individual noticees, the order records an alleged breach of Clauses iii(e) and iii(f) of Part-C of the Third Schedule read with Regulation 27(2) of the same Regulations, provisions dealing with the code of conduct for a depository's officers.

The penalty itself was charged under two heads. Section 15HB of the SEBI Act is a residuary provision under which a party that fails to comply with any provision, rule, regulation or direction "for which no separate penalty has been provided" is liable to a penalty of not less than one lakh rupees. Section 19G of the Depositories Act is its counterpart under that statute. The adjudicating powers were exercised under Section 15-I of the SEBI Act and Section 19H of the Depositories Act.

What Happens Next

A SEBI adjudication order is subject to appeal. CDSL may challenge the order before the Securities Appellate Tribunal within the period the statute allows, and thereafter, on a question of law, before the Supreme Court. Until then, the order stands as a regulatory finding and the Rs 1 crore penalty is payable within 45 days of receipt.

In reaching the penalty, the adjudicating officer recorded that he had given "due consideration" to the remedial measures CDSL took after the incident, and had taken note of a financial disincentive of Rs 10,00,000 that SEBI had already imposed under its standard operating procedure for reporting cyber security incidents dated 28 August 2019. The order states the penalty is "commensurate with the lapses/omissions" on CDSL's part. The proceedings against the former CISO and former CTO were disposed of without any monetary penalty, and nothing further is directed against them.

What It Means

The action is a reminder that depositories sit at the centre of India's market plumbing, and that SEBI treats their cyber resilience as a systemic, not merely operational, matter. The order stresses that a depository holding the majority of the country's demat accounts was "under an elevated obligation" to keep its cybersecurity infrastructure robust, and it frames the 2022 outage as a foreseeable result of unaddressed controls rather than an unavoidable event.

For ordinary investors, the practical takeaway is reassurance about process rather than cause for alarm. The order records that settlements were completed within two days and does not allege loss of investor holdings. Investors can verify that their broker or depository participant is registered using SEBI's public "Intermediaries" search on sebi.gov.in, and can independently track holdings through the consolidated account statement and the depository's own investor login rather than relying on any single interface.

More broadly, the matter illustrates the pattern SEBI's cyber circulars are designed to catch: internet-facing assets left out of critical-asset inventories, testing that skips a live entry point, and known deficiencies flagged by the regulator but not remediated. The enduring signal for investors is that market infrastructure is held to a documented standard, with penalties attached when it is not met.

FAQ

What exactly did SEBI order against CDSL?

Per the order dated 20 July 2026, SEBI's adjudicating officer imposed a total penalty of Rs 1 crore on CDSL, comprising Rs 90 lakh under Section 15HB of the SEBI Act and Rs 10 lakh under Section 19G of the Depositories Act, over cybersecurity lapses linked to the 18 November 2022 malware attack. CDSL must pay within 45 days.

What does the order mean for the two individuals it names?

Per the order, the two former CDSL officers were named as noticees, but the adjudicating officer disposed of the proceedings against them without imposing any monetary penalty. A SEBI adjudication records regulatory findings that are appealable to the Securities Appellate Tribunal; it is not a criminal case or conviction.

Were investors' demat holdings lost in the attack?

The order does not allege any loss of investor securities. It records that CDSL isolated its systems, rebuilt them on a clean network, and completed the delayed settlements by 20 November 2022. The finding concerns cybersecurity control failures and the resulting disruption to depository processes, not loss of holdings.

Can CDSL appeal the penalty?

Yes. A SEBI adjudication order can be challenged before the Securities Appellate Tribunal, and thereafter, on a question of law, before the Supreme Court. Until any such appeal succeeds, the order stands and the penalty is payable within the time SEBI has stipulated.

How can I check that my broker or depository is SEBI-registered?

Use the "Intermediaries" search on SEBI's official website, sebi.gov.in, which lets you verify registered depositories, depository participants and brokers by name or registration number. You can also cross-check your holdings through your consolidated account statement rather than relying on a single app or portal.

Where can I read the official order?

The full adjudication order, reference Order/JS/RJ/2026-27/32498-32500 dated 20 July 2026, is published on SEBI's website under Enforcement, Orders, Orders of Adjudicating Officer.

This report is based on the official SEBI adjudication order dated 20 July 2026 in the matter of the CDSL malware attack. It was surfaced via coverage in The Economic Times.

This report describes enforcement actions and allegations on the public record, attributed to the officials cited. An order, FIR or chargesheet is not a conviction; parties are presumed innocent until proven guilty.

Named in this report, or spotted an error? Corrections and responses: editor@oquilia.com. We correct errors promptly and record responses from named parties.

Sources & Citations

  1. Adjudication Order in the matter of Central Depository Services (India) Limited malware attack on November 18, 2022 (Ref. Order/JS/RJ/2026-27/32498-32500) — SEBI

This article was last reviewed on 21 July 2026by Oquilia's editorial team. Every claim is sourced from primary regulatory materials (CBDT, IRDAI, RBI, SEBI, Indian Kanoon). View our methodology.

Found an error? Report an issue.

CalculatorsInsuranceInvestTaxLoansNRIMBAHNIAI
Oquilia

150+ calculators · Zero commissions

Oquilia

Intelligent financial analysis. 150+ calculators & unbiased analysis.

Data: IRDAI · RBI · SEBI · AMFI

Calculators

  • SIP
  • EMI
  • Income Tax
  • FD
  • PPF
  • NPS
  • Gratuity
  • HRA
  • ELSS
  • All 150+

Insurance

  • Compare Plans
  • Companies
  • Claims Data
  • Hospitals
  • Health Premium
  • Term Premium
  • Section 80D

Tax & Loans

  • Old vs New
  • Capital Gains
  • TDS
  • Home Loan EMI
  • Car Loan EMI
  • Rent vs Buy
  • Prepayment

More Tools

  • Invest Hub
  • Tax Planning
  • Loan Tools
  • Loan Harassment Help
  • NRI Hub
  • MBA Finance
  • HNI Wealth
  • Glossary
  • News
  • Blog
  • Reports
  • Tools
  • Oquilia Advisor

Company

  • About
  • Contact
  • FAQ
  • Legal Hub
  • Privacy
  • Terms
  • Disclaimer
  • Cookie Policy
  • Grievance
  • Disclosure

Newsletter

Monthly digest

Policy moves, deadline reminders, and the most-used calculators each month.

Designed & developed by QX137, React & Next.js studio

Regulatory & data sources

RBISEBIIRDAIIncome Tax DeptAMFIPFRDAOECD TaxBISWorld Bank

Regulatory data last updated: July 2026. Figures are cross-checked against primary IRDAI, SEBI, RBI, CBDT and AMFI publications before they ship.

© 2026 Oquilia. Not a licensed financial advisor. All third-party logos and trademarks belong to their respective owners.

PrivacyTermsDisclaimerSitemap