Skip to content
SEBI Fines CDSL ₹1 Crore for 2022 Malware Attack Lapses

SEBI Fines CDSL ₹1 Crore for 2022 Malware Attack Lapses

First seen 20 Jul 2026, 17:39 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster July 21, 2026 at 16:29 UTC
  • SEBI imposed a ₹1 crore fine on CDSL for cybersecurity failures linked to a 2022 malware attack.
  • The malware attack exploited a misclassified ADFS server, disrupting key depository operations.
  • CDSL failed to conduct adequate vulnerability assessments and restore cybersecurity controls post-Covid.

The Securities and Exchange Board of India (SEBI) fined Central Depository Services (India) Ltd (CDSL) ₹1 crore for cybersecurity lapses that led to a malware attack in November 2022. The attack exploited a misclassified internet-facing Active Directory Federation Services (ADFS) server, which was not included in vulnerability assessments. This oversight caused significant disruptions in depository operations, delaying critical settlements scheduled for November 18, 2022, until November 20. SEBI's order highlighted failures in identifying critical IT assets, conducting vulnerability assessments, and implementing proper access controls. The regulator also noted that CDSL had relaxed password policies during the Covid-19 pandemic and failed to restore necessary cybersecurity measures afterward. SEBI held CDSL and two former executives accountable for these violations, but adjudication proceedings against the executives were disposed of.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 63d ago How this analysis works

Timeline

2022-11-18
Malware attack disrupts CDSL operations
A malware attack forced CDSL to delay settlements scheduled for November 18, 2022, until November 20.
Thehindubusinessline
2022-11-20
Settlements resumed after delay
CDSL resumed critical depository functions after isolating its systems due to the malware attack.
Thehindubusinessline
2026-07-20
SEBI fines CDSL ₹1 crore
SEBI imposed a fine on CDSL for multiple cybersecurity lapses that led to the 2022 malware attack.
Thehindubusinessline

More articles in this cluster (2)

Following this threat?

Track Central Depository Services (India) Ltd in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed