India’s markets regulator has fined Central Depository Services, better known as CDSL, Rs 1 crore over cybersecurity failures linked to a malware attack that hit its systems in November 2022. The Securities and Exchange Board of India issued the order on Monday, nearly four years after the breach first surfaced. SEBI said the incident disrupted settlement operations, corporate actions and inter-depository transfers for investors who rely on the depository to hold shares electronically. The penalty is one of the most detailed regulatory findings yet on how a systemically important market infrastructure institution handled a major cyber incident.
What SEBI Found in the CDSL Investigation
SEBI’s order found that CDSL failed to classify an internet-facing ADFS server as a critical asset, even though internal rules required such systems to receive stronger protection. That single oversight became the root cause of the malware attack, according to the regulator. Investigators also noted that the depository had excluded this server from vulnerability testing and ignored cybersecurity deficiencies that were flagged as early as August 2022, months before the breach was actually discovered.
The regulator’s findings go further back than the attack itself. SEBI noted that the attacker gained initial access to CDSL’s servers in November 2021, a full year before the intrusion was detected. During that window, the company had created an admin account with a password set never to expire, and it relaxed its lockout threshold to three failed login attempts, a setting that stayed unaddressed until the malware attack occurred.
Read more: Google Play Services
How the 2022 Malware Attack Disrupted Markets
When the malware attack was discovered on 18 November 2022, CDSL isolated affected machines and disconnected from other market infrastructure institutions to contain the damage. SEBI’s order shows the intrusion infected 135 servers and 177 desktops and laptops across the depository’s network. Settlement processes stayed down for 46 hours, while inter-depository transfers remained affected for nearly 55 hours, delays that rippled through brokerages, clearing corporations and investor accounts nationwide.

Timeline of the Malware Breach
SEBI’s order lays out a sequence of events stretching across roughly a year before the disruption became public:
- November 2021: Attackers first gained unauthorized access to a CDSL internet-facing server.
- August 2022: Internal reviews flagged cybersecurity deficiencies that went unresolved.
- 18 November 2022: The malware attack was discovered, forcing the depository to disconnect affected systems.
- 20–21 November 2022: Settlement and pledge-related operations were restored after nearly two days of disruption.
- July 2026: SEBI issued its final order imposing a Rs 1 crore penalty on CDSL.
Why SEBI Cleared CDSL’s Former Executives
The regulator had also opened proceedings against CDSL’s former Chief Information Security Officer, Rajesh Nadkarni, and former Chief Technology Officer, Amit Mahajan. SEBI ultimately dropped those proceedings, concluding that the lapses identified during its investigation could not be attributed to either individual specifically. The order instead placed responsibility on CDSL as an organization, pointing to systemic gaps in policy enforcement and unimplemented regulatory directions rather than the decisions of any single executive.
Read more: Codex Micro Keyboard
Why the Penalty Matters for Market Infrastructure
SEBI’s order emphasized that depositories like CDSL are deeply interconnected with the rest of the securities market, meaning a cyber incident at one institution can create broader systemic risk. The regulator described the malware attack as a foreseeable outcome of accumulated lapses rather than an isolated failure, a framing that raises the bar for how market infrastructure institutions are expected to manage cybersecurity going forward. It handles roughly 83 million investor accounts, close to 70 percent of India’s demat holdings, which makes its systems central to how millions of people buy, sell, and hold shares electronically.

What This Means for Investors Using CDSL
For everyday investors, the SEBI order does not change how demat accounts function day-to-day, but it highlights the infrastructure behind every trade. CDSL restored and validated its systems before markets reopened after the 2022 incident, and no investor holdings were reported lost as a result of the breach. Still, the size of the penalty signals that regulators now expect faster detection and stronger monitoring from institutions handling this volume of financial data.
Sebi’s investigation also flagged weaknesses beyond the ADFS server itself, including delayed real-time intrusion detection and gaps in analyzing security alerts as they came in. Those findings suggest the malware attack succeeded less because of a single failure and more because of layered gaps that built up over several years. Regulators are expected to reference this order as a benchmark case when reviewing cybersecurity practices at other depositories and clearing institutions.
What Happens Next
SEBI split the penalty into two parts, with Rs 90 lakh levied under the SEBI Act and Rs 10 lakh under the Depositories Act. CDSL has 45 days from the date of the order to pay the fine. The regulator’s findings are likely to shape how other depositories and market infrastructure institutions review their own server classification, vulnerability testing and incident response practices in the months ahead, with SEBI signaling closer scrutiny of critical financial infrastructure in the future.













