SEBI fines CDSL Rs 1 crore over 2022 malware attack on depository
SEBI has penalised CDSL, India's largest depository, Rs 1 crore over the November 2022 malware attack, finding it breached the cybersecurity framework. Two former officials drew no penalty.
The Enforcement Action
The Securities and Exchange Board of India (SEBI) has imposed a penalty of Rs 1 crore on Central Depository Services (India) Limited (CDSL), the country's largest depository, over the malware attack that disrupted its systems on 18 November 2022. The order, dated 20 July 2026 and passed by adjudicating officer Jai Sebastian, is recorded under reference no. Order/JS/RJ/2026-27/32498-32500.
The penalty splits into Rs 90 lakh under section 15HB of the SEBI Act, 1992 and Rs 10 lakh under section 19G of the Depositories Act, 1996. Per the 88-page order, SEBI found that CDSL had failed to comply with the cybersecurity framework mandated for market infrastructure institutions, and that an inadequately secured, internet-facing server was the root cause of the incident. CDSL holds roughly 70% of India's demat accounts, a figure the order draws from the company's own FY23 annual report.
Two individuals were also named as noticees: Mr Rajesh Nadkarni, then chief information security officer, and Mr Amit Mahajan, then chief technology officer. The order disposes of the proceedings against both "without imposition of any monetary penalty". In its submissions recorded in the order, CDSL argued that the affected server was not a critical asset and did not hold sensitive data; SEBI rejected that characterisation. As of publication CDSL had not issued a separate public statement beyond the submissions recorded in the proceedings.
How the Scheme Worked
According to the order, CDSL's systems were originally designed to be accessed only from within its premises. When the COVID-19 lockdown began, the depository rolled out remote-access solutions so staff could work from home, including a web proxy and an Active Directory Federation Service (ADFS) server integrated with its internal directory for single sign-on. The order states that this internet-facing ADFS server was "the root cause of the incident".
The order records that the ADFS server was left out of CDSL's vulnerability assessment and penetration testing (VAPT) and was not connected to its security monitoring (SIEM) or privileged-access (PIM) systems, so intrusion attempts generated no alerts. SEBI notes that a circular dated 20 May 2022 required every internet-facing system to be classified as a critical asset, but that CDSL's critical-asset list approved by its technology committee on 12 September 2022 excluded the server. CDSL later admitted, by an email dated 8 January 2024, that it had not classified the server as critical.
The chronology in the order is stark. It states the attacker had accessed CDSL's servers as early as November 2021, while the attack itself was only discovered a year later. An administrator account created in 2021 was set with a password that would never expire, and a relaxed lock-out threshold went unaddressed until the attack. SEBI also records that it had drawn CDSL's attention to the VAPT deficiency by a letter dated 30 August 2022, but that the company "chose not to act".
The attack surfaced at 03:00 hours on 18 November 2022, after end-of-day operations, when servers and computers became inaccessible. The order states that 135 of 547 servers and 177 of 506 desktops and laptops were infected. CDSL isolated its network and rebuilt a clean environment, completing recovery on 19 November; settlements due on 18 November were processed on 20 November. Per the order, the settlement process faced disruption for about 46 hours and inter-depository transfers for about 54.5 hours.
The Law Invoked
The penalty rests on two residuary provisions. Section 15HB of the SEBI Act and section 19G of the Depositories Act each allow a penalty of between Rs 1 lakh and Rs 1 crore where a person fails to comply with any provision, rule, regulation or direction for which no separate penalty is prescribed. The order applied section 15HB to the breaches of SEBI's cybersecurity circulars and section 19G to the breach of the depository regulations.
The underlying obligations the order cites include clauses 1 and 5 of Part-D of the Third Schedule read with regulation 17 of the SEBI (Depositories and Participants) Regulations, 2018, and several SEBI cyber-security circulars: the circular dated 6 July 2015 as modified on 20 May 2022, the circular dated 7 December 2018, and the circular dated 22 March 2021. These set out how market infrastructure institutions must identify critical assets, assess cyber risk and deploy proportionate controls.
Notably, the order declined to penalise CDSL under both statutes for the same circular breaches, holding that a penalty for the circular violations should be imposed "either under the SEBI Act or under the Depositories Act" and not both. The charges against the two officials rested on clauses iii(e) and iii(f) of Part-C of the Third Schedule read with regulation 27(2), but drew no penalty.
What Happens Next
CDSL must pay the Rs 1 crore penalty within 45 days of receiving the order, through SEBI's online payment facility. An adjudication order of this kind is a regulator's finding, and it is appealable: an aggrieved party may challenge it before the Securities Appellate Tribunal (SAT) within the prescribed period, and from there, on a question of law, to the Supreme Court.
Because the proceedings against the former CISO and CTO were disposed without penalty, no liability attaches to those two individuals under this order. For CDSL itself, the order records that remedial measures taken after the incident, and an earlier Rs 10 lakh financial disincentive imposed under SEBI's 2019 standard operating procedure for cyber incidents, were weighed in fixing the amount.
This is a completed regulatory action rather than a criminal proceeding; there is no chargesheet or arrest involved. Were such an enforcement matter ever to reach that stage, a chargesheet contains allegations, not findings of guilt; the accused are presumed innocent until proven guilty, and due process continues. The finding here stands unless and until it is set aside on appeal. Investors' demat holdings are unaffected by the penalty itself, which is a sanction on the institution, not a restriction on account operations.
What It Means
For ordinary investors, the practical message is reassuring on one count and instructive on another. The order confirms that no investor losses and no wrongful gains were identified, and that demat accounts continued to function once systems were restored. The penalty concerns process failures at a systemically important institution, not missing securities.
The wider signal is that SEBI is holding market infrastructure institutions to the letter of its cybersecurity framework. The order stresses that CDSL, handling around 70% of the country's demat accounts, was "under an elevated obligation" to keep its defences robust, and that a single unpatched, internet-facing server was enough to halt settlement for the entire market for nearly two days. That interconnectedness is the real lesson: the resilience of the plumbing behind every demat account depends on controls investors never see.
For individuals, the takeaway is verification rather than alarm. You can confirm your depository participant and broker on the CDSL and SEBI websites, keep your own login credentials and two-factor settings current, and review the SMS and email alerts that depositories send for every debit to your account. Those alerts are the retail investor's own early-warning system.
FAQ
What exactly did SEBI order?
SEBI imposed a Rs 1 crore penalty on CDSL, comprising Rs 90 lakh under the SEBI Act and Rs 10 lakh under the Depositories Act, for failing to comply with its cybersecurity framework in connection with the 18 November 2022 malware attack. The order was passed by an adjudicating officer on 20 July 2026 and is payable within 45 days.
Does this mean the people named are guilty?
The order is a regulator's finding against CDSL, the company, and is appealable to the Securities Appellate Tribunal. The two individuals named, the former chief information security officer and chief technology officer, were not penalised at all; the proceedings against them were disposed without any monetary penalty. This is a regulatory adjudication, not a criminal case. Where an enforcement matter does involve an FIR or chargesheet, such a filing contains allegations, not findings of guilt, and the accused are presumed innocent until proven guilty while due process continues.
Were any investors' shares or money lost?
No. The order records that it found no disproportionate gain to CDSL and no quantified loss to investors. Settlement activity was delayed by roughly two days during recovery, but demat holdings were not lost and accounts resumed normal operation.
Can CDSL challenge the penalty?
Yes. A SEBI adjudication order can be appealed to the Securities Appellate Tribunal within the prescribed time, and onward to the Supreme Court on a question of law. Until then, the finding and the Rs 1 crore penalty stand, payable within 45 days of receipt of the order.
How can I check my own depository account is secure?
Confirm your depository participant is registered on the CDSL or SEBI website, enable two-factor authentication on your demat login, and never ignore the transaction alerts depositories send by SMS and email. Report anything unrecognised to your depository participant immediately.
Where can I read the official order?
The full 88-page adjudication order dated 20 July 2026 is published on SEBI's website under Enforcement, Orders, Orders of AO, and carries reference no. Order/JS/RJ/2026-27/32498-32500.
This report is based on the official SEBI adjudication order dated 20 July 2026, reference no. Order/JS/RJ/2026-27/32498-32500. It was surfaced via coverage in BW Businessworld.
This report describes enforcement actions and allegations on the public record, attributed to the officials cited. An order, FIR or chargesheet is not a conviction; parties are presumed innocent until proven guilty.
Named in this report, or spotted an error? Corrections and responses: editor@oquilia.com. We correct errors promptly and record responses from named parties.