OquiliaOquiliaOquilia — India's Financial Intelligence Platform
Calculators
Compare
Tax
NRI
News
Investigations
Oquilia Advisor
HomeCalculatorsInvestigationsNews
View All CalculatorsSIP CalculatorEMI CalculatorIncome TaxFD CalculatorPPF CalculatorAll 150+ Calculators
View All CompareHome Loan RatesPersonal LoansCredit CardsHealth InsuranceTerm InsuranceMutual FundsFD RatesEducation Loan
View All TaxOld vs New RegimeTax Saving under 80CIncome Tax SlabsCapital Gains TaxSave Tax on SalaryITR Filing Guide
View All NRINRI Investment GuideNRI Tax FilingNRI Banking & NRE FDNRI Real EstateDTAA CalculatorNRE FD Calculator
View All NewsLatest NewsFraud & EnforcementInvestigationsBlog / GuidesReports
Investigations
View All ToolsAm I Underinsured?Policy AuditJargon DecoderMutual Fund Discovery
For Business
View All LearnFinancial GlossaryFAQAbout OquiliaContact
Oquilia Advisor
  1. Home
  2. News
  3. SEBI penalises CDSL Rs 1 crore over 2022 malware attack lapses
Enforcement

SEBI penalises CDSL Rs 1 crore over 2022 malware attack lapses

SEBI's adjudicating officer has imposed a Rs 1 crore penalty on depository CDSL, finding cybersecurity lapses had built up before the November 2022 malware attack that halted settlements.

Oquilia Newsroom
Financial news desk covering SEBI, RBI, IRDAI, and Budget-related developments.
|Published 24 Jul 2026, 00:27 IST|7 min read · 1,646 words
Verified Sources|Last reviewed: 23 July 2026
SEBI penalises CDSL Rs 1 crore over 2022 malware attack lapses — Fraud & Enforcement on Oquilia

The Enforcement Action

The Securities and Exchange Board of India (SEBI) has imposed a penalty of Rs 1 crore on Central Depository Services (India) Limited (CDSL), one of the country's two securities depositories, for cybersecurity lapses that its adjudicating officer found had built up before a malware attack on the depository's systems on 18 November 2022. The order, dated 20 July 2026 and signed by adjudicating officer Jai Sebastian in Mumbai (Adjudication Order Ref. No. Order/JS/RJ/2026-27/32498-32500), splits the penalty into Rs 90,00,000 under section 15HB of the SEBI Act, 1992 and Rs 10,00,000 under section 19G of the Depositories Act, 1996.

The action follows a Show Cause Notice (Ref. No. SEBI/HO/EAD2/NH/RJ/2024/33455) dated 24 October 2024. Two individuals were also named as noticees - Mr Rajesh Nadkarni, the then Chief Information Security Officer, and Mr Amit Mahajan, the then Chief Technology Officer - but SEBI disposed of the proceedings against both without imposing any monetary penalty. The financial penalty rests solely with CDSL as an institution.

SEBI held that the attack was "the foreseeable outcome of lapses" that had accumulated over time, including policy deviations, unimplemented regulatory directions and an internet-facing server left out of the depository's critical-assets list. CDSL, for its part, submitted that there was "no failure" on its part, that its actions were bona fide and taken in good faith, and asked SEBI to take a lenient view and impose no penalty. The adjudicating officer rejected that plea and held the penalty "commensurate with the lapses/omissions".

How the Scheme Worked

This is a governance-failure matter rather than a market-manipulation one, and the order sets out a chronology. According to the order, at around 03:00 hours on Friday 18 November 2022, after end-of-day operations, CDSL observed that several servers and end-user computers had become inaccessible; verification traced the cause to a malware attack. CDSL isolated the affected machines and disconnected its network to stop the infection spreading, then rebuilt a clean environment on a separate virtual local area network. The recovery was completed on 19 November, and settlements scheduled for 18 November were carried out on Sunday 20 November.

Per the order, 135 of 547 servers and 177 of 506 desktops and laptops were infected across CDSL's primary data centre and disaster-recovery site. As a direct consequence, the order records, critical depository activities - including settlement pay-in and pay-out and margin pledge and unpledge - were not carried out on 18 November. SEBI notes the settlement process and inter-depository transfers faced disruption for 46 hours and 54.5 hours respectively, with a "major spillover impact" because settlement for the wider market depended on CDSL's systems functioning normally.

The order's central finding concerns what came before the attack. SEBI observed that the attacker had obtained access to CDSL's servers as early as November 2021, roughly a year before the intrusion was discovered. The order records that an administrator account created in 2021 was configured with a password set never to expire, and that a relaxation of the account lock-out threshold to three failed attempts went unaddressed until the attack. These deviations, SEBI found, continued even after the COVID-19 situation normalised, without CDSL considering the risks they carried.

SEBI also found that an ADFS server - an internet-facing system - had not been included in the list of critical assets approved by the depository's committee on 12 September 2022, and that a re-audit under the vulnerability assessment and penetration testing (VAPT) exercise, which it had been directed to conduct, was found deficient. The examination followed CDSL's own interim and final root-cause-analysis reports, submitted to SEBI after the incident and prepared with an external forensic agency.

The Law Invoked

The order cites the statutory framework governing depositories and market-infrastructure institutions. The penalty is imposed under section 15HB of the SEBI Act, 1992 - a residuary provision allowing a penalty of up to Rs 1 crore where a person fails to comply with a requirement and no separate penalty is specified - read with section 19G of the Depositories Act, 1996, its counterpart under that Act. The proceedings were conducted under section 15-I of the SEBI Act and section 19H of the Depositories Act, which empower an adjudicating officer to hold an inquiry and impose penalties.

On the underlying obligations, SEBI's examination alleged breaches of Clauses 1, 5 and 9 of Part-D of the Third Schedule read with regulation 17 of the SEBI (Depositories and Participants) Regulations, 2018, which set out a depository's code of conduct and systems obligations. The order also references SEBI's cybersecurity circulars dated 6 July 2015 (as modified on 20 May 2022) and 22 March 2021, and an advisory dated 18 May 2020 on remote access and telecommuting - the framework CDSL was found not to have fully adhered to.

In fixing the amount, the adjudicating officer recorded that the factors in section 15J of the SEBI Act - such as any disproportionate gain, loss caused to investors, and the repetitive nature of the default - had been given due regard, and noted a prior financial disincentive of Rs 10,00,000 that SEBI had earlier imposed on CDSL under its 2019 standard operating procedure for reporting cyber incidents.

What Happens Next

A SEBI adjudication order is not the final word. CDSL may appeal to the Securities Appellate Tribunal (SAT), and thereafter, on a question of law, to the Supreme Court. The order directs CDSL to remit the Rs 1 crore penalty within 45 days of receipt through SEBI's online payment facility. The proceedings against the two named officials were disposed of without penalty, so no further individual liability arises from this order.

For depositors, there is no direct financial consequence: the penalty is paid by CDSL to SEBI, and demat holdings are unaffected by it. The order is a regulatory sanction on the institution's cybersecurity governance, not a finding of loss to any individual account holder. Whether CDSL contests the findings before the SAT will determine if the order stands as issued.

It is worth stating plainly that this is a completed regulatory action by SEBI within its own adjudication process, not a criminal proceeding. The findings are those of the adjudicating officer and remain subject to the statutory appeal available to CDSL.

What It Means

For ordinary investors, the significance lies less in the rupee figure than in what the order signals about the plumbing of the market. CDSL and NSDL are the two depositories that hold virtually all Indian securities in dematerialised form; when one of them cannot settle trades for the better part of two days, the disruption reaches every investor whose transactions depend on it. SEBI's order reads as a message that market-infrastructure institutions will be held to their cybersecurity obligations, and that lapses allowed to accumulate over time - stale administrator credentials, an un-audited internet-facing server, unimplemented directions - can attract a penalty even where no investor is shown to have lost money.

The practical takeaway is reassurance rather than alarm. The system's built-in redundancy meant settlements were completed within two days, and no depositor's holdings were lost. Investors cannot audit a depository's servers, but they can note that the regulator does, and that SEBI publishes these orders in full on its website. Those wishing to verify the standing of any SEBI-registered intermediary - a broker, depository participant or adviser - can use the registration and intermediary-search tools on the official SEBI website, the same public record on which this action is documented.

None of this calls for any action on an investor's demat account. The episode is a governance and supervision story: a regulator examining an infrastructure institution's controls after an incident, finding them wanting, and imposing a proportionate penalty that the institution may still contest.

FAQ

What exactly did SEBI order?

SEBI's adjudicating officer imposed a total penalty of Rs 1 crore on CDSL - Rs 90 lakh under section 15HB of the SEBI Act and Rs 10 lakh under section 19G of the Depositories Act - for cybersecurity lapses connected to the malware attack on its systems on 18 November 2022. The order is dated 20 July 2026 and directs payment within 45 days.

Were any individuals penalised?

No. The order named CDSL's then Chief Information Security Officer and then Chief Technology Officer as noticees, but SEBI disposed of the proceedings against both without imposing any monetary penalty. The financial penalty applies only to CDSL as an institution.

Does this affect my demat account or holdings?

No. The penalty is paid by CDSL to SEBI and has no effect on individual demat holdings, which were not lost in the 2022 incident. According to the order, settlements delayed by the attack were completed within two days. The action concerns CDSL's cybersecurity governance, not any investor's account balance.

Can the order be appealed?

Yes. A SEBI adjudication order can be appealed to the Securities Appellate Tribunal (SAT), and on a question of law thereafter to the Supreme Court. The findings are those of SEBI's adjudicating officer and remain subject to that appeal. During the proceedings CDSL contended there was no failure on its part and sought a lenient view.

How can I check if my depository participant is registered?

Every depository, depository participant, broker and investment adviser dealing in securities must be registered with SEBI. You can verify registration status through the intermediary-search and registration tools on the official SEBI website, sebi.gov.in, which also hosts the full text of enforcement orders like this one.

Where can I read the official order?

The full adjudication order is published on SEBI's website under Enforcement > Orders > Orders of AO. It is dated 20 July 2026 and carries reference Order/JS/RJ/2026-27/32498-32500. The source link is provided at the end of this report.

This report is based on the official SEBI adjudication order dated 20 July 2026. It was surfaced via coverage aggregated by Google News.

This report describes enforcement actions and allegations on the public record, attributed to the officials cited. An order, FIR or chargesheet is not a conviction; parties are presumed innocent until proven guilty.

Named in this report, or spotted an error? Corrections and responses: editor@oquilia.com. We correct errors promptly and record responses from named parties.

Sources & Citations

  1. Adjudication Order in the matter of Central Depository Services (India) Limited malware attack on November 18, 2022 — SEBI

This article was last reviewed on 23 July 2026by Oquilia's editorial team. Every claim is sourced from primary regulatory materials (CBDT, IRDAI, RBI, SEBI, Indian Kanoon). View our methodology.

Found an error? Report an issue.

CalculatorsInsuranceInvestTaxLoansNRIMBAHNIAI
Oquilia

150+ calculators · Zero commissions

Oquilia

Intelligent financial analysis. 150+ calculators & unbiased analysis.

Data: IRDAI · RBI · SEBI · AMFI

Calculators

  • SIP
  • EMI
  • Income Tax
  • FD
  • PPF
  • NPS
  • Gratuity
  • HRA
  • ELSS
  • All 150+

Insurance

  • Compare Plans
  • Companies
  • Claims Data
  • Hospitals
  • Health Premium
  • Term Premium
  • Section 80D

Tax & Loans

  • Old vs New
  • Capital Gains
  • TDS
  • Home Loan EMI
  • Car Loan EMI
  • Rent vs Buy
  • Prepayment

More Tools

  • Invest Hub
  • Tax Planning
  • Loan Tools
  • Loan Harassment Help
  • NRI Hub
  • MBA Finance
  • HNI Wealth
  • Glossary
  • News
  • Blog
  • Reports
  • Tools
  • Oquilia Advisor

Company

  • About
  • Contact
  • FAQ
  • Legal Hub
  • Privacy
  • Terms
  • Disclaimer
  • Cookie Policy
  • Grievance
  • Disclosure

Newsletter

Monthly digest

Policy moves, deadline reminders, and the most-used calculators each month.

Designed & developed by QX137, React & Next.js studio

Regulatory & data sources

RBISEBIIRDAIIncome Tax DeptAMFIPFRDAOECD TaxBISWorld Bank

Regulatory data last updated: July 2026. Figures are cross-checked against primary IRDAI, SEBI, RBI, CBDT and AMFI publications before they ship.

© 2026 Oquilia. Not a licensed financial advisor. All third-party logos and trademarks belong to their respective owners.

PrivacyTermsDisclaimerSitemap