SEBI fines CDSL Rs 1 crore for 2022 malware attack
Analysis based on 13 articles · First reported Jul 20, 2026 · Last updated Jul 21, 2026
The penalty underscores regulatory scrutiny on cybersecurity at market infrastructure institutions, potentially increasing compliance costs for CDSL and similar entities. However, the relatively modest fine and disposal of proceedings against individuals may limit negative market reaction.
India's markets regulator, the India — Securities and Exchange Board of India (SEBI), imposed a total penalty of Rs 1 crore on Central Depository Services (India) Ltd (CDSL) for cybersecurity lapses that led to a malware attack in November 2022. The attack disrupted critical depository operations, including settlement processes and inter-depository transfers, for up to 54.5 hours, causing spillover effects on the entire securities market. SEBI found that CDSL failed to classify an internet-facing Active Directory Federation Services (ADFS) server as a critical asset, excluded it from vulnerability assessments, and had weak password policies. The regulator noted that attackers had gained access as early as November 2021. Proceedings against former CISO Ashish Nadkarni and former CTO Amit Mahajan were disposed of without monetary penalties.
Set up alerts, explore entity relationships, search across thousands of events, and build custom intelligence feeds.
Open Dashboard