OquiliaOquiliaOquilia — India's Financial Intelligence Platform
Calculators
Compare
Tax
NRI
News
Investigations
Oquilia Advisor
HomeCalculatorsInvestigationsNews
View All CalculatorsSIP CalculatorEMI CalculatorIncome TaxFD CalculatorPPF CalculatorAll 150+ Calculators
View All CompareHome Loan RatesPersonal LoansCredit CardsHealth InsuranceTerm InsuranceMutual FundsFD RatesEducation Loan
View All TaxOld vs New RegimeTax Saving under 80CIncome Tax SlabsCapital Gains TaxSave Tax on SalaryITR Filing Guide
View All NRINRI Investment GuideNRI Tax FilingNRI Banking & NRE FDNRI Real EstateDTAA CalculatorNRE FD Calculator
View All NewsLatest NewsFraud & EnforcementInvestigationsBlog / GuidesReports
Investigations
View All ToolsAm I Underinsured?Policy AuditJargon DecoderMutual Fund Discovery
For Business
View All LearnFinancial GlossaryFAQAbout OquiliaContact
Oquilia Advisor
  1. Home
  2. News
  3. SEBI fines CDSL Rs 1 crore over 2022 malware attack on depository
Enforcement

SEBI fines CDSL Rs 1 crore over 2022 malware attack on depository

SEBI has penalised CDSL, India's largest depository, Rs 1 crore over the November 2022 malware attack, finding it breached the cybersecurity framework. Two former officials drew no penalty.

Oquilia Newsroom
Financial news desk covering SEBI, RBI, IRDAI, and Budget-related developments.
|Published 21 Jul 2026, 13:50 IST|7 min read · 1,554 words
Verified Sources|Last reviewed: 21 July 2026
SEBI fines CDSL Rs 1 crore over 2022 malware attack on depository — Fraud & Enforcement on Oquilia

The Enforcement Action

The Securities and Exchange Board of India (SEBI) has imposed a penalty of Rs 1 crore on Central Depository Services (India) Limited (CDSL), the country's largest depository, over the malware attack that disrupted its systems on 18 November 2022. The order, dated 20 July 2026 and passed by adjudicating officer Jai Sebastian, is recorded under reference no. Order/JS/RJ/2026-27/32498-32500.

The penalty splits into Rs 90 lakh under section 15HB of the SEBI Act, 1992 and Rs 10 lakh under section 19G of the Depositories Act, 1996. Per the 88-page order, SEBI found that CDSL had failed to comply with the cybersecurity framework mandated for market infrastructure institutions, and that an inadequately secured, internet-facing server was the root cause of the incident. CDSL holds roughly 70% of India's demat accounts, a figure the order draws from the company's own FY23 annual report.

Two individuals were also named as noticees: Mr Rajesh Nadkarni, then chief information security officer, and Mr Amit Mahajan, then chief technology officer. The order disposes of the proceedings against both "without imposition of any monetary penalty". In its submissions recorded in the order, CDSL argued that the affected server was not a critical asset and did not hold sensitive data; SEBI rejected that characterisation. As of publication CDSL had not issued a separate public statement beyond the submissions recorded in the proceedings.

How the Scheme Worked

According to the order, CDSL's systems were originally designed to be accessed only from within its premises. When the COVID-19 lockdown began, the depository rolled out remote-access solutions so staff could work from home, including a web proxy and an Active Directory Federation Service (ADFS) server integrated with its internal directory for single sign-on. The order states that this internet-facing ADFS server was "the root cause of the incident".

The order records that the ADFS server was left out of CDSL's vulnerability assessment and penetration testing (VAPT) and was not connected to its security monitoring (SIEM) or privileged-access (PIM) systems, so intrusion attempts generated no alerts. SEBI notes that a circular dated 20 May 2022 required every internet-facing system to be classified as a critical asset, but that CDSL's critical-asset list approved by its technology committee on 12 September 2022 excluded the server. CDSL later admitted, by an email dated 8 January 2024, that it had not classified the server as critical.

The chronology in the order is stark. It states the attacker had accessed CDSL's servers as early as November 2021, while the attack itself was only discovered a year later. An administrator account created in 2021 was set with a password that would never expire, and a relaxed lock-out threshold went unaddressed until the attack. SEBI also records that it had drawn CDSL's attention to the VAPT deficiency by a letter dated 30 August 2022, but that the company "chose not to act".

The attack surfaced at 03:00 hours on 18 November 2022, after end-of-day operations, when servers and computers became inaccessible. The order states that 135 of 547 servers and 177 of 506 desktops and laptops were infected. CDSL isolated its network and rebuilt a clean environment, completing recovery on 19 November; settlements due on 18 November were processed on 20 November. Per the order, the settlement process faced disruption for about 46 hours and inter-depository transfers for about 54.5 hours.

The Law Invoked

The penalty rests on two residuary provisions. Section 15HB of the SEBI Act and section 19G of the Depositories Act each allow a penalty of between Rs 1 lakh and Rs 1 crore where a person fails to comply with any provision, rule, regulation or direction for which no separate penalty is prescribed. The order applied section 15HB to the breaches of SEBI's cybersecurity circulars and section 19G to the breach of the depository regulations.

The underlying obligations the order cites include clauses 1 and 5 of Part-D of the Third Schedule read with regulation 17 of the SEBI (Depositories and Participants) Regulations, 2018, and several SEBI cyber-security circulars: the circular dated 6 July 2015 as modified on 20 May 2022, the circular dated 7 December 2018, and the circular dated 22 March 2021. These set out how market infrastructure institutions must identify critical assets, assess cyber risk and deploy proportionate controls.

Notably, the order declined to penalise CDSL under both statutes for the same circular breaches, holding that a penalty for the circular violations should be imposed "either under the SEBI Act or under the Depositories Act" and not both. The charges against the two officials rested on clauses iii(e) and iii(f) of Part-C of the Third Schedule read with regulation 27(2), but drew no penalty.

What Happens Next

CDSL must pay the Rs 1 crore penalty within 45 days of receiving the order, through SEBI's online payment facility. An adjudication order of this kind is a regulator's finding, and it is appealable: an aggrieved party may challenge it before the Securities Appellate Tribunal (SAT) within the prescribed period, and from there, on a question of law, to the Supreme Court.

Because the proceedings against the former CISO and CTO were disposed without penalty, no liability attaches to those two individuals under this order. For CDSL itself, the order records that remedial measures taken after the incident, and an earlier Rs 10 lakh financial disincentive imposed under SEBI's 2019 standard operating procedure for cyber incidents, were weighed in fixing the amount.

This is a completed regulatory action rather than a criminal proceeding; there is no chargesheet or arrest involved. Were such an enforcement matter ever to reach that stage, a chargesheet contains allegations, not findings of guilt; the accused are presumed innocent until proven guilty, and due process continues. The finding here stands unless and until it is set aside on appeal. Investors' demat holdings are unaffected by the penalty itself, which is a sanction on the institution, not a restriction on account operations.

What It Means

For ordinary investors, the practical message is reassuring on one count and instructive on another. The order confirms that no investor losses and no wrongful gains were identified, and that demat accounts continued to function once systems were restored. The penalty concerns process failures at a systemically important institution, not missing securities.

The wider signal is that SEBI is holding market infrastructure institutions to the letter of its cybersecurity framework. The order stresses that CDSL, handling around 70% of the country's demat accounts, was "under an elevated obligation" to keep its defences robust, and that a single unpatched, internet-facing server was enough to halt settlement for the entire market for nearly two days. That interconnectedness is the real lesson: the resilience of the plumbing behind every demat account depends on controls investors never see.

For individuals, the takeaway is verification rather than alarm. You can confirm your depository participant and broker on the CDSL and SEBI websites, keep your own login credentials and two-factor settings current, and review the SMS and email alerts that depositories send for every debit to your account. Those alerts are the retail investor's own early-warning system.

FAQ

What exactly did SEBI order?

SEBI imposed a Rs 1 crore penalty on CDSL, comprising Rs 90 lakh under the SEBI Act and Rs 10 lakh under the Depositories Act, for failing to comply with its cybersecurity framework in connection with the 18 November 2022 malware attack. The order was passed by an adjudicating officer on 20 July 2026 and is payable within 45 days.

Does this mean the people named are guilty?

The order is a regulator's finding against CDSL, the company, and is appealable to the Securities Appellate Tribunal. The two individuals named, the former chief information security officer and chief technology officer, were not penalised at all; the proceedings against them were disposed without any monetary penalty. This is a regulatory adjudication, not a criminal case. Where an enforcement matter does involve an FIR or chargesheet, such a filing contains allegations, not findings of guilt, and the accused are presumed innocent until proven guilty while due process continues.

Were any investors' shares or money lost?

No. The order records that it found no disproportionate gain to CDSL and no quantified loss to investors. Settlement activity was delayed by roughly two days during recovery, but demat holdings were not lost and accounts resumed normal operation.

Can CDSL challenge the penalty?

Yes. A SEBI adjudication order can be appealed to the Securities Appellate Tribunal within the prescribed time, and onward to the Supreme Court on a question of law. Until then, the finding and the Rs 1 crore penalty stand, payable within 45 days of receipt of the order.

How can I check my own depository account is secure?

Confirm your depository participant is registered on the CDSL or SEBI website, enable two-factor authentication on your demat login, and never ignore the transaction alerts depositories send by SMS and email. Report anything unrecognised to your depository participant immediately.

Where can I read the official order?

The full 88-page adjudication order dated 20 July 2026 is published on SEBI's website under Enforcement, Orders, Orders of AO, and carries reference no. Order/JS/RJ/2026-27/32498-32500.

This report is based on the official SEBI adjudication order dated 20 July 2026, reference no. Order/JS/RJ/2026-27/32498-32500. It was surfaced via coverage in BW Businessworld.

This report describes enforcement actions and allegations on the public record, attributed to the officials cited. An order, FIR or chargesheet is not a conviction; parties are presumed innocent until proven guilty.

Named in this report, or spotted an error? Corrections and responses: editor@oquilia.com. We correct errors promptly and record responses from named parties.

Sources & Citations

  1. Adjudication Order in the matter of Central Depository Services (India) Limited malware attack on November 18, 2022 (Ref. No. Order/JS/RJ/2026-27/32498-32500) — SEBI

This article was last reviewed on 21 July 2026by Oquilia's editorial team. Every claim is sourced from primary regulatory materials (CBDT, IRDAI, RBI, SEBI, Indian Kanoon). View our methodology.

Found an error? Report an issue.

CalculatorsInsuranceInvestTaxLoansNRIMBAHNIAI
Oquilia

150+ calculators · Zero commissions

Oquilia

Intelligent financial analysis. 150+ calculators & unbiased analysis.

Data: IRDAI · RBI · SEBI · AMFI

Calculators

  • SIP
  • EMI
  • Income Tax
  • FD
  • PPF
  • NPS
  • Gratuity
  • HRA
  • ELSS
  • All 150+

Insurance

  • Compare Plans
  • Companies
  • Claims Data
  • Hospitals
  • Health Premium
  • Term Premium
  • Section 80D

Tax & Loans

  • Old vs New
  • Capital Gains
  • TDS
  • Home Loan EMI
  • Car Loan EMI
  • Rent vs Buy
  • Prepayment

More Tools

  • Invest Hub
  • Tax Planning
  • Loan Tools
  • Loan Harassment Help
  • NRI Hub
  • MBA Finance
  • HNI Wealth
  • Glossary
  • News
  • Blog
  • Reports
  • Tools
  • Oquilia Advisor

Company

  • About
  • Contact
  • FAQ
  • Legal Hub
  • Privacy
  • Terms
  • Disclaimer
  • Cookie Policy
  • Grievance
  • Disclosure

Newsletter

Monthly digest

Policy moves, deadline reminders, and the most-used calculators each month.

Designed & developed by QX137, React & Next.js studio

Regulatory & data sources

RBISEBIIRDAIIncome Tax DeptAMFIPFRDAOECD TaxBISWorld Bank

Regulatory data last updated: July 2026. Figures are cross-checked against primary IRDAI, SEBI, RBI, CBDT and AMFI publications before they ship.

© 2026 Oquilia. Not a licensed financial advisor. All third-party logos and trademarks belong to their respective owners.

PrivacyTermsDisclaimerSitemap