SEBI Fines CDSL ₹1 Crore for 2022 Malware Attack Lapses
Article Content
- •SEBI imposed a ₹1 crore fine on CDSL for cybersecurity failures linked to a 2022 malware attack.
- •The malware attack exploited a misclassified ADFS server, disrupting key depository operations.
- •CDSL failed to conduct adequate vulnerability assessments and restore cybersecurity controls post-Covid.
The Securities and Exchange Board of India (SEBI) fined Central Depository Services (India) Ltd (CDSL) ₹1 crore for cybersecurity lapses that led to a malware attack in November 2022. The attack exploited a misclassified internet-facing Active Directory Federation Services (ADFS) server, which was not included in vulnerability assessments. This oversight caused significant disruptions in depository operations, delaying critical settlements scheduled for November 18, 2022, until November 20. SEBI's order highlighted failures in identifying critical IT assets, conducting vulnerability assessments, and implementing proper access controls. The regulator also noted that CDSL had relaxed password policies during the Covid-19 pandemic and failed to restore necessary cybersecurity measures afterward. SEBI held CDSL and two former executives accountable for these violations, but adjudication proceedings against the executives were disposed of.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Central Depository Services (India) Ltd in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…