OquiliaOquiliaOquilia — India's Financial Intelligence Platform
Calculators
Compare
Tax
NRI
News
Investigations
Oquilia Advisor
HomeCalculatorsInvestigationsNews
View All CalculatorsSIP CalculatorEMI CalculatorIncome TaxFD CalculatorPPF CalculatorAll 150+ Calculators
View All CompareHome Loan RatesPersonal LoansCredit CardsHealth InsuranceTerm InsuranceMutual FundsFD RatesEducation Loan
View All TaxOld vs New RegimeTax Saving under 80CIncome Tax SlabsCapital Gains TaxSave Tax on SalaryITR Filing Guide
View All NRINRI Investment GuideNRI Tax FilingNRI Banking & NRE FDNRI Real EstateDTAA CalculatorNRE FD Calculator
View All NewsLatest NewsFraud & EnforcementInvestigationsBlog / GuidesReports
Investigations
View All ToolsAm I Underinsured?Policy AuditJargon DecoderMutual Fund Discovery
For Business
View All LearnFinancial GlossaryFAQAbout OquiliaContact
Oquilia Advisor
  1. Home
  2. News
  3. SEBI fines CDSL Rs 1 crore over 2022 depository malware attack
Enforcement

SEBI fines CDSL Rs 1 crore over 2022 depository malware attack

SEBI has imposed a Rs 1 crore penalty on depository CDSL over the November 2022 malware attack, finding cyber-security lapses that disrupted market settlement. The order is appealable to the SAT.

Oquilia Newsroom
Financial news desk covering SEBI, RBI, IRDAI, and Budget-related developments.
|Published 21 Jul 2026, 00:54 IST|7 min read · 1,520 words
Verified Sources|Last reviewed: 20 July 2026
SEBI fines CDSL Rs 1 crore over 2022 depository malware attack — Fraud & Enforcement on Oquilia

The Enforcement Action

The Securities and Exchange Board of India (SEBI), through Adjudicating Officer Jai Sebastian, has imposed a penalty of Rs 1 crore on Central Depository Services (India) Limited (CDSL) by an adjudication order dated 20 July 2026, bearing reference Order/JS/RJ/2026-27/32498-32500. The order, passed at Mumbai under section 15-I of the SEBI Act, 1992 read with section 19H of the Depositories Act, 1996, splits the penalty into Rs 90 lakh under section 15HB of the SEBI Act and Rs 10 lakh under section 19G of the Depositories Act. CDSL has been directed to pay within 45 days.

The order arises from a malware attack that struck CDSL, one of India's two securities depositories, in the early hours of 18 November 2022. SEBI held that the disruption to a systemically important market institution flowed from cybersecurity lapses that had built up over time, rather than from an unforeseeable or random event.

The proceedings also named two CDSL officials, Mr Rajesh Nadkarni, the then Chief Information Security Officer, and Mr Amit Mahajan, the then Chief Technology Officer, as Noticees 2 and 3. The adjudication proceedings against both were disposed of without any monetary penalty.

CDSL, in submissions recorded in the order, denied the allegations and argued that any violations were "merely technical and venial" and that no penalty ought to be imposed. The finding is a regulatory determination and is appealable to the Securities Appellate Tribunal.

How the Scheme Worked

Per the order, at around 03:00 hours on 18 November 2022, after end-of-day operations, several CDSL servers and end-user computers became inaccessible. On investigation, the cause was found to be a malware attack. SEBI records that CDSL isolated the affected servers, disconnected its network to contain the spread, and built a separate clean virtual local area network before restoring services on 19 November, with the settlements scheduled for 18 November completed on 20 November.

The order sets out the scale of the intrusion. Drawing on CDSL's own final Root Cause Analysis and the minutes of a SEBI committee meeting on 13 March 2023, it records that 135 of 547 servers and 177 of 506 desktops and laptops were infected across the primary data centre and the disaster recovery site, findings the order states CDSL did not dispute. Settlement of on-market transactions, corporate actions, inter-depository transfers, margin pledges, e-services transactions and off-market transfers were all disrupted between 18 and 20 November 2022. The settlement process was down for about 46 hours and inter-depository transfers for about 54.5 hours.

Crucially, SEBI found that the attacker had gained access to CDSL's servers as far back as November 2021, a full year before the attack was discovered. The order observes that an internet-facing Active Directory Federation Service (ADFS) server had been excluded from the scope of CDSL's vulnerability assessment and penetration testing, and that SEBI had drawn attention to this deficiency by a letter dated 30 August 2022, but that CDSL "chose not to act". It further records that an administrator account created in 2021 had its password set never to expire, and that an account lock-out policy relaxed during the COVID-19 period was not later restored.

Procedurally, the matter began with a show-cause notice dated 24 October 2024. After the original adjudicating officer superannuated, Mr Sebastian was appointed to the matter by a communique dated 4 April 2025, heard the noticees, and passed the final order on 20 July 2026.

The Law Invoked

The order was passed under section 15-I of the SEBI Act and section 19H of the Depositories Act, the provisions that empower an adjudicating officer to hold an inquiry and impose penalties. The penalty on CDSL was levied under section 15HB of the SEBI Act and section 19G of the Depositories Act. Both are residuary penalty provisions: they apply where a regulated entity contravenes a rule, regulation or direction for which no separate penalty is prescribed, and each allows a penalty of not less than one lakh rupees and up to one crore rupees.

On the substance, SEBI alleged that CDSL had violated Clauses 1, 5 and 9 of Part-D of the Third Schedule read with regulation 17 of the SEBI (Depositories and Participants) Regulations, 2018, together with an advisory dated 18 May 2020 on remote access and telecommuting and several SEBI cybersecurity circulars, including the circular dated 6 July 2015 as modified on 20 May 2022, the circular dated 22 March 2021 and the circular dated 7 December 2018. These provisions set the cyber-security and cyber-resilience framework that market infrastructure institutions are required to maintain.

The allegations against the two officials rested on Clauses iii(e) and iii(f) of Part-C of the Third Schedule read with regulation 27(2) of the same regulations, which concern the code of conduct applicable to key personnel.

What Happens Next

CDSL has 45 days from receipt of the order to pay the Rs 1 crore penalty through SEBI's online facility. An adjudication order of this kind is not the final word: under the SEBI Act and the Depositories Act, CDSL may appeal to the Securities Appellate Tribunal (SAT), and from there, on a question of law, to the Supreme Court. Until any such appeal is decided, the order stands as SEBI's finding.

For the two named officials, the order closes the matter without penalty, so no further action follows against them from this proceeding.

Because this is a regulatory adjudication rather than a criminal case, the register is a finding by the regulator, appealable before a tribunal, rather than a charge to be tested at trial. Even so, it remains subject to that appellate process, and CDSL's recorded position is that the lapses were technical. Readers should treat the conclusions as SEBI's, open to challenge before the SAT.

What It Means

The action is a reminder that the plumbing of India's markets carries operational risk, not just the shares and funds that ride on it. A depository holds securities in dematerialised form for crores of investors, and SEBI noted that the disruption had a "major spillover impact" because settlement for the entire securities market depended on CDSL functioning normally. The regulator's message is that market infrastructure institutions are expected to meet the cyber-security framework in full, and that known, flagged weaknesses left unaddressed can attract a penalty even where the institution later spends heavily on remediation. The order records that CDSL spent about Rs 3.70 crore on forensic investigation and remedial measures.

For an ordinary investor, the practical takeaway is modest but real. Your demat holdings were not erased by this incident; depository records are backed up and were restored within days. The episode is about a service outage and the standards behind it, not about lost securities. If you want to satisfy yourself about where your holdings sit, you can check your CDSL or NSDL statement and confirm your depository participant's registration on the SEBI website. It is also a useful prompt to keep your contact details updated with your participant so that you receive an alert for every debit and credit to your demat account.

FAQ

What exactly did SEBI order?

SEBI's adjudicating officer imposed a penalty of Rs 1 crore on CDSL, being Rs 90 lakh under section 15HB of the SEBI Act and Rs 10 lakh under section 19G of the Depositories Act, by an order dated 20 July 2026. CDSL has 45 days to pay. Proceedings against two named officials were closed without any penalty.

What has SEBI found, and is this a criminal conviction?

The order is a finding by SEBI's adjudicating officer, not a criminal conviction. CDSL denied the allegations, describing any violations as technical, and can appeal to the Securities Appellate Tribunal. Until an appeal is decided, the order stands as the regulator's determination and remains subject to that appellate process.

Were investors' demat holdings lost in the attack?

No. Per the order, the November 2022 malware attack disrupted depository operations and settlement for a period, but services were restored within days. The matter concerns cyber-security standards and an operational outage, not the loss of investors' securities held in dematerialised form.

Can the order be appealed?

Yes. An adjudication order under the SEBI Act and the Depositories Act can be challenged before the Securities Appellate Tribunal, and thereafter, on a question of law, before the Supreme Court. The penalty is payable within 45 days unless a tribunal directs otherwise.

How can I check my depository and broker are registered?

You can verify a depository participant, broker or other intermediary through the registered-intermediary search on the SEBI website, and check your holdings via the statement your depository, CDSL or NSDL, sends you. Keeping your mobile number and email updated with your participant ensures you receive alerts for every debit and credit.

Where can I read the official order?

The full 88-page order is published on SEBI's website under Enforcement, Orders, Orders of AO, dated 20 July 2026, in the matter of Central Depository Services (India) Limited.

This report is based on the official SEBI adjudication order dated 20 July 2026. It was surfaced via coverage in The Economic Times.

This report describes enforcement actions and allegations on the public record, attributed to the officials cited. An order, FIR or chargesheet is not a conviction; parties are presumed innocent until proven guilty.

Named in this report, or spotted an error? Corrections and responses: editor@oquilia.com. We correct errors promptly and record responses from named parties.

Sources & Citations

  1. Adjudication Order in the matter of Central Depository Services (India) Limited malware attack on November 18, 2022 — SEBI

This article was last reviewed on 20 July 2026by Oquilia's editorial team. Every claim is sourced from primary regulatory materials (CBDT, IRDAI, RBI, SEBI, Indian Kanoon). View our methodology.

Found an error? Report an issue.

CalculatorsInsuranceInvestTaxLoansNRIMBAHNIAI
Oquilia

150+ calculators · Zero commissions

Oquilia

Intelligent financial analysis. 150+ calculators & unbiased analysis.

Data: IRDAI · RBI · SEBI · AMFI

Calculators

  • SIP
  • EMI
  • Income Tax
  • FD
  • PPF
  • NPS
  • Gratuity
  • HRA
  • ELSS
  • All 150+

Insurance

  • Compare Plans
  • Companies
  • Claims Data
  • Hospitals
  • Health Premium
  • Term Premium
  • Section 80D

Tax & Loans

  • Old vs New
  • Capital Gains
  • TDS
  • Home Loan EMI
  • Car Loan EMI
  • Rent vs Buy
  • Prepayment

More Tools

  • Invest Hub
  • Tax Planning
  • Loan Tools
  • Loan Harassment Help
  • NRI Hub
  • MBA Finance
  • HNI Wealth
  • Glossary
  • News
  • Blog
  • Reports
  • Tools
  • Oquilia Advisor

Company

  • About
  • Contact
  • FAQ
  • Legal Hub
  • Privacy
  • Terms
  • Disclaimer
  • Cookie Policy
  • Grievance
  • Disclosure

Newsletter

Monthly digest

Policy moves, deadline reminders, and the most-used calculators each month.

Designed & developed by QX137, React & Next.js studio

Regulatory & data sources

RBISEBIIRDAIIncome Tax DeptAMFIPFRDAOECD TaxBISWorld Bank

Regulatory data last updated: July 2026. Figures are cross-checked against primary IRDAI, SEBI, RBI, CBDT and AMFI publications before they ship.

© 2026 Oquilia. Not a licensed financial advisor. All third-party logos and trademarks belong to their respective owners.

PrivacyTermsDisclaimerSitemap