SEBI penalises CDSL Rs 1 crore over 2022 malware attack lapses
SEBI's adjudicating officer has imposed a Rs 1 crore penalty on depository CDSL, finding cybersecurity lapses had built up before the November 2022 malware attack that halted settlements.
The Enforcement Action
The Securities and Exchange Board of India (SEBI) has imposed a penalty of Rs 1 crore on Central Depository Services (India) Limited (CDSL), one of the country's two securities depositories, for cybersecurity lapses that its adjudicating officer found had built up before a malware attack on the depository's systems on 18 November 2022. The order, dated 20 July 2026 and signed by adjudicating officer Jai Sebastian in Mumbai (Adjudication Order Ref. No. Order/JS/RJ/2026-27/32498-32500), splits the penalty into Rs 90,00,000 under section 15HB of the SEBI Act, 1992 and Rs 10,00,000 under section 19G of the Depositories Act, 1996.
The action follows a Show Cause Notice (Ref. No. SEBI/HO/EAD2/NH/RJ/2024/33455) dated 24 October 2024. Two individuals were also named as noticees - Mr Rajesh Nadkarni, the then Chief Information Security Officer, and Mr Amit Mahajan, the then Chief Technology Officer - but SEBI disposed of the proceedings against both without imposing any monetary penalty. The financial penalty rests solely with CDSL as an institution.
SEBI held that the attack was "the foreseeable outcome of lapses" that had accumulated over time, including policy deviations, unimplemented regulatory directions and an internet-facing server left out of the depository's critical-assets list. CDSL, for its part, submitted that there was "no failure" on its part, that its actions were bona fide and taken in good faith, and asked SEBI to take a lenient view and impose no penalty. The adjudicating officer rejected that plea and held the penalty "commensurate with the lapses/omissions".
How the Scheme Worked
This is a governance-failure matter rather than a market-manipulation one, and the order sets out a chronology. According to the order, at around 03:00 hours on Friday 18 November 2022, after end-of-day operations, CDSL observed that several servers and end-user computers had become inaccessible; verification traced the cause to a malware attack. CDSL isolated the affected machines and disconnected its network to stop the infection spreading, then rebuilt a clean environment on a separate virtual local area network. The recovery was completed on 19 November, and settlements scheduled for 18 November were carried out on Sunday 20 November.
Per the order, 135 of 547 servers and 177 of 506 desktops and laptops were infected across CDSL's primary data centre and disaster-recovery site. As a direct consequence, the order records, critical depository activities - including settlement pay-in and pay-out and margin pledge and unpledge - were not carried out on 18 November. SEBI notes the settlement process and inter-depository transfers faced disruption for 46 hours and 54.5 hours respectively, with a "major spillover impact" because settlement for the wider market depended on CDSL's systems functioning normally.
The order's central finding concerns what came before the attack. SEBI observed that the attacker had obtained access to CDSL's servers as early as November 2021, roughly a year before the intrusion was discovered. The order records that an administrator account created in 2021 was configured with a password set never to expire, and that a relaxation of the account lock-out threshold to three failed attempts went unaddressed until the attack. These deviations, SEBI found, continued even after the COVID-19 situation normalised, without CDSL considering the risks they carried.
SEBI also found that an ADFS server - an internet-facing system - had not been included in the list of critical assets approved by the depository's committee on 12 September 2022, and that a re-audit under the vulnerability assessment and penetration testing (VAPT) exercise, which it had been directed to conduct, was found deficient. The examination followed CDSL's own interim and final root-cause-analysis reports, submitted to SEBI after the incident and prepared with an external forensic agency.
The Law Invoked
The order cites the statutory framework governing depositories and market-infrastructure institutions. The penalty is imposed under section 15HB of the SEBI Act, 1992 - a residuary provision allowing a penalty of up to Rs 1 crore where a person fails to comply with a requirement and no separate penalty is specified - read with section 19G of the Depositories Act, 1996, its counterpart under that Act. The proceedings were conducted under section 15-I of the SEBI Act and section 19H of the Depositories Act, which empower an adjudicating officer to hold an inquiry and impose penalties.
On the underlying obligations, SEBI's examination alleged breaches of Clauses 1, 5 and 9 of Part-D of the Third Schedule read with regulation 17 of the SEBI (Depositories and Participants) Regulations, 2018, which set out a depository's code of conduct and systems obligations. The order also references SEBI's cybersecurity circulars dated 6 July 2015 (as modified on 20 May 2022) and 22 March 2021, and an advisory dated 18 May 2020 on remote access and telecommuting - the framework CDSL was found not to have fully adhered to.
In fixing the amount, the adjudicating officer recorded that the factors in section 15J of the SEBI Act - such as any disproportionate gain, loss caused to investors, and the repetitive nature of the default - had been given due regard, and noted a prior financial disincentive of Rs 10,00,000 that SEBI had earlier imposed on CDSL under its 2019 standard operating procedure for reporting cyber incidents.
What Happens Next
A SEBI adjudication order is not the final word. CDSL may appeal to the Securities Appellate Tribunal (SAT), and thereafter, on a question of law, to the Supreme Court. The order directs CDSL to remit the Rs 1 crore penalty within 45 days of receipt through SEBI's online payment facility. The proceedings against the two named officials were disposed of without penalty, so no further individual liability arises from this order.
For depositors, there is no direct financial consequence: the penalty is paid by CDSL to SEBI, and demat holdings are unaffected by it. The order is a regulatory sanction on the institution's cybersecurity governance, not a finding of loss to any individual account holder. Whether CDSL contests the findings before the SAT will determine if the order stands as issued.
It is worth stating plainly that this is a completed regulatory action by SEBI within its own adjudication process, not a criminal proceeding. The findings are those of the adjudicating officer and remain subject to the statutory appeal available to CDSL.
What It Means
For ordinary investors, the significance lies less in the rupee figure than in what the order signals about the plumbing of the market. CDSL and NSDL are the two depositories that hold virtually all Indian securities in dematerialised form; when one of them cannot settle trades for the better part of two days, the disruption reaches every investor whose transactions depend on it. SEBI's order reads as a message that market-infrastructure institutions will be held to their cybersecurity obligations, and that lapses allowed to accumulate over time - stale administrator credentials, an un-audited internet-facing server, unimplemented directions - can attract a penalty even where no investor is shown to have lost money.
The practical takeaway is reassurance rather than alarm. The system's built-in redundancy meant settlements were completed within two days, and no depositor's holdings were lost. Investors cannot audit a depository's servers, but they can note that the regulator does, and that SEBI publishes these orders in full on its website. Those wishing to verify the standing of any SEBI-registered intermediary - a broker, depository participant or adviser - can use the registration and intermediary-search tools on the official SEBI website, the same public record on which this action is documented.
None of this calls for any action on an investor's demat account. The episode is a governance and supervision story: a regulator examining an infrastructure institution's controls after an incident, finding them wanting, and imposing a proportionate penalty that the institution may still contest.
FAQ
What exactly did SEBI order?
SEBI's adjudicating officer imposed a total penalty of Rs 1 crore on CDSL - Rs 90 lakh under section 15HB of the SEBI Act and Rs 10 lakh under section 19G of the Depositories Act - for cybersecurity lapses connected to the malware attack on its systems on 18 November 2022. The order is dated 20 July 2026 and directs payment within 45 days.
Were any individuals penalised?
No. The order named CDSL's then Chief Information Security Officer and then Chief Technology Officer as noticees, but SEBI disposed of the proceedings against both without imposing any monetary penalty. The financial penalty applies only to CDSL as an institution.
Does this affect my demat account or holdings?
No. The penalty is paid by CDSL to SEBI and has no effect on individual demat holdings, which were not lost in the 2022 incident. According to the order, settlements delayed by the attack were completed within two days. The action concerns CDSL's cybersecurity governance, not any investor's account balance.
Can the order be appealed?
Yes. A SEBI adjudication order can be appealed to the Securities Appellate Tribunal (SAT), and on a question of law thereafter to the Supreme Court. The findings are those of SEBI's adjudicating officer and remain subject to that appeal. During the proceedings CDSL contended there was no failure on its part and sought a lenient view.
How can I check if my depository participant is registered?
Every depository, depository participant, broker and investment adviser dealing in securities must be registered with SEBI. You can verify registration status through the intermediary-search and registration tools on the official SEBI website, sebi.gov.in, which also hosts the full text of enforcement orders like this one.
Where can I read the official order?
The full adjudication order is published on SEBI's website under Enforcement > Orders > Orders of AO. It is dated 20 July 2026 and carries reference Order/JS/RJ/2026-27/32498-32500. The source link is provided at the end of this report.
This report is based on the official SEBI adjudication order dated 20 July 2026. It was surfaced via coverage aggregated by Google News.
This report describes enforcement actions and allegations on the public record, attributed to the officials cited. An order, FIR or chargesheet is not a conviction; parties are presumed innocent until proven guilty.
Named in this report, or spotted an error? Corrections and responses: editor@oquilia.com. We correct errors promptly and record responses from named parties.