{
  "type": "article",
  "title": "SEBI Slaps ₹1 Crore Fine On CDSL Over Massive 2022 Malware Breach",
  "summary": "Market regulator SEBI has imposed a massive penalty of ₹1 crore on CDSL due to critical failures in its cybersecurity framework. The punitive action comes after a detailed investigation into a severe malware attack that compromised the depository's servers and computers in November 2022.",
  "content": "Central Depository Services Limited (CDSL), one of the primary institutions responsible for safeguarding the demat accounts of millions of stock market investors in India, has been slapped with a hefty financial penalty due to severe technological negligence. The capital markets regulator, the Securities and Exchange Board of India (SEBI), has imposed a fine of ₹1 crore on the depository after uncovering glaring flaws in its cybersecurity infrastructure. This strict regulatory action follows a detailed investigation into a massive malware attack that compromised the depository's network in November 2022. According to the regulator, the institution completely failed to adhere to fundamental digital security protocols which directly allowed unknown attackers to breach their highly sensitive internal systems.\n\nExtensive Infiltration and Market Disruption\nThe incident in question took place on November 18, 2022 when a dangerous cyberattack struck the core digital infrastructure of the depository. The infiltration had a profound and widespread impact across the company's entire network footprint. Official data reveals that out of the 547 servers operating at the time, 135 were severely affected by the malicious software. Furthermore, out of the 506 desktops and laptops used by the staff, 177 systems were found to be infected. This technological crisis did not merely remain confined to the institution's internal offices; it directly disrupted the daily operations of the broader stock market. Crucial market services including the settlement of shares, share pledging, and regular pay in and pay out processes were completely halted for a period causing significant inconvenience to retail investors and brokerage firms alike.\n\nAn Unprotected Gateway Server\nFollowing the massive breach, the market regulator conducted an exhaustive probe culminating in an 88 page detailed investigation report. This document brings to light several shocking and severe lapses on the part of the depository management. According to the findings, the most glaring technical blunder was that the institution completely failed to classify a highly sensitive internet facing server as a critical asset. This specific server functioned as a vital gateway between the external public internet and the company's highly secure internal database network. Despite serving such a delicate and crucial role, the institution did not provide it with any enhanced security perimeters. As a direct result of this oversight, the server never underwent a Vulnerability Assessment and Penetration Testing audit. This specialized and mandatory security evaluation is designed to expose hidden technical weaknesses in computer systems before they can be exploited. The regulator firmly believes that had this mandatory testing been completed on schedule, the attackers would likely never have managed to penetrate the main system through this vulnerable route.\n\nIgnoring Prior Red Flags\nPerhaps the most alarming aspect revealed during the probe was that the regulator had already alerted the company about its fragile security posture long before the actual incident occurred. SEBI had explicitly warned the depository in August 2022 about several major vulnerabilities existing within its cybersecurity framework. Despite receiving such clear and direct warnings, the company management failed to implement the necessary corrective measures in a timely manner. Instead of fixing the known loopholes, the institution continued to rely heavily on an outdated security audit report. This complacent attitude and the failure to patch old vulnerabilities eventually became the primary catalyst for the devastating cyberattack just a few months later.\n\nPenalty Breakdown and Strict Directives\nViewing this entire episode as a severe threat to the integrity of the Indian financial framework, the regulator has taken a remarkably tough stance by levying a total monetary penalty of ₹1 crore. This aggregate fine has been distributed under two distinct regulatory frameworks. A sum of ₹90 lakh has been penalized under the strict provisions of the SEBI Act of 1992 while the remaining ₹10 lakh fine has been imposed under the Depositories Act of 1996. In its final regulatory order, the authority made it abundantly clear that a depository ranks among the most critical pillars of the nation's entire financial architecture. These institutions are entrusted with the highly secure custody of valuable shares and private data belonging to millions of ordinary and institutional investors across the country. In such a high stakes environment, any form of negligence pertaining to digital security and data protection simply cannot be tolerated. The regulator has issued a stern directive mandating the depository to deposit the entire penalty amount within exactly 45 days from the date of the issued order.\n\nWhat this means for you\n• Across India: This stringent action forces major financial institutions and depositories to significantly upgrade their cybersecurity measures ensuring safer digital infrastructure.\n• For Investors: The penalty reassures retail investors that the market regulator is actively monitoring the safety of their demat accounts and will punish any institutional negligence.\n\nQuestions & Answers\n\n1. How much fine has SEBI imposed on CDSL?\nSEBI has imposed a total penalty of ₹1 crore on CDSL for severe negligence in maintaining cybersecurity standards.\n\n2. Why was CDSL fined by the market regulator?\nThe fine relates to a massive malware attack in November 2022 which occurred because CDSL failed to secure and audit a critical internet facing server.\n\n3. How many systems were compromised in the cyber attack?\nThe attack infected 135 out of CDSL's 547 servers along with 177 out of 506 employee desktops and laptops.\n\n4. How much time does CDSL have to pay the penalty?\nAs per the regulatory order CDSL has been directed to pay the full penalty amount within 45 days.",
  "url": "https://trendkia.com/en/business/cdsl-ki-bari-laparavahi-haikinga-se-jure-mamale-men-sebi-ne-thoka-1-karora-rupaye-ka-jurmana-9820",
  "category": "Business",
  "publishedAt": "2026-07-22",
  "tags": [
    "CDSL",
    "SEBI",
    "Cyber Attack",
    "Stock Market",
    "Demat Account",
    "Penalty",
    "Cybersecurity"
  ],
  "language": "en",
  "site": "TrendKia"
}