# SEBI Slaps ₹1 Crore Fine on CDSL Over Severe Cyber Security Lapses That Led to 2022 Outage

> Market regulator SEBI has slapped a ₹1 crore penalty on CDSL for severe cyber security lapses that disrupted essential market operations. Investigations revealed that hackers had breached the depository's network a full year before the massive 2022 malware attack surfaced.

**Type:** article · **Category:** Market · **Published:** 2026-07-22 · **Source:** TrendKia
**Canonical:** https://trendkia.com/en/market/sebi-ne-cdsl-para-thoka-1-karora-ka-jurmana-haikarsa-ne-2021-men-hi-sistama-men-kara-li-thi-sendhamari-9819 · **Language:** English
**Tags:** SEBI, CDSL, Stock Market, Cyber Security, Malware Attack, Penalty, Investors

In a stringent disciplinary move, India's capital markets regulator SEBI has imposed a hefty penalty of ₹1 crore on the Central Depository Services (India) Limited (CDSL). The severe financial sanction comes in response to glaring vulnerabilities and extensive negligence in the depository's cyber security infrastructure, which directly culminated in a devastating malware attack in late 2022. The digital breach not only compromised the internal network of the financial institution but also severely paralyzed critical stock market operations for an extended period, creating panic and operational hurdles across the financial sector.

## Failure to Classify and Protect Critical Assets

A comprehensive investigation conducted by the market regulator revealed a series of alarming procedural and technical failures on the part of the depository. According to the regulatory findings, the organization completely failed to classify a highly sensitive, internet-facing server as a critical asset. Because this essential piece of digital infrastructure was improperly categorized, the company neglected to conduct routine Vulnerability Assessment and Penetration Testing (VAPT) within the mandated timeframes. This meant that glaring security loopholes were left completely unchecked and unpatched.

Adding to the severity of the negligence, the regulator had explicitly highlighted these exact technical shortcomings in August 2022, officially alerting the management. However, the institution failed to take prompt corrective measures to seal the vulnerabilities. The most shocking revelation from the inquiry was the timeline of the actual breach: cyber attackers had successfully infiltrated the organization's secure network as early as November 2021. The hackers lurked undetected within the digital ecosystem for an entire year before the massive malware attack finally surfaced and wreaked havoc in November 2022.

## Massive Disruption of Financial Services

When the malware payload was finally executed, the consequences for the broader financial ecosystem were catastrophic. The scale of the digital infection was massive, crippling the institution's day-to-day operations. Official technical reports indicate that out of a total of 547 servers operating within the network, 135 were heavily infected by the virus. Furthermore, the malware spread to end-user devices, compromising 177 out of the 506 computers and laptops used by the staff.

This widespread system failure brought the entire stock market transaction cycle to a grinding halt. Extremely sensitive and essential market services, including the transfer of shares, pledging of securities, complex settlement processes, and routine pay-in and pay-out mechanisms, were completely paralyzed. The regulator's order specifically notes that the crucial settlement system remained disrupted for a staggering 46 hours. Given that this depository acts as the fundamental backbone of the Indian financial market, holding the demat accounts of millions of investors, this massive technical failure caused severe ripple effects across the entire security market.

## Ex-Officials Cleared While Company Faces Deadline

The regulatory probe also scrutinized the roles played by the top technical leadership at the time of the breach. The actions of the former Chief Technology Officer (CTO), Amit Mahajan, and the former Chief Information Security Officer (CISO), Rajesh Nadkarni, were thoroughly examined to determine personal liability. However, the investigation concluded that the decisions regarding the system architecture and security protocols were not taken by these executives in isolation. Instead, the policies had been formally approved by the board of directors and various internal committees. Recognizing this collective decision-making process, the regulator opted not to impose any personal financial penalties on the two former officials.

While the individuals were spared, the institution itself has been held strictly accountable for the systemic failures. The market regulator has issued a firm directive, giving the company a strict 45-day deadline to remit the entire ₹1 crore fine. The total penalty amount has been levied under two separate regulatory frameworks: ₹90 lakh has been charged under the provisions of the SEBI Act, while the remaining ₹10 lakh penalty falls under the Depositories Act.

In its concluding remarks, the regulatory body delivered a stern warning to all financial market participants. The order emphasized that cyber security lapses at critical institutions like depositories cannot be viewed merely as internal corporate issues. Such severe technical negligence directly jeopardizes investor trust, compromises the integrity of financial data, and puts the reliability of the entire stock market at immense risk.

## What this means for you
- **For Investors:** This strict regulatory penalty ensures that major financial institutions will be forced to upgrade their cybersecurity measures, ultimately providing better protection for your data and market investments.

## Questions & Answers

### 1. How much fine has SEBI imposed on CDSL?
SEBI has imposed a total penalty of ₹1 crore on CDSL for severe negligence in maintaining cyber security.

### 2. Why was CDSL penalized by the regulator?
The fine was levied due to a massive malware attack in 2022 and the company's failure to conduct timely security audits of its critical servers.

### 3. Which stock market services were affected by the malware attack?
Crucial services like share transfers, settlements, pledging, and pay-in/pay-out processes were completely disrupted for nearly 46 hours.

### 4. Were former company officials penalized in this case?
No, following the probe, SEBI did not impose any personal financial penalties on former CTO Amit Mahajan and former CISO Rajesh Nadkarni.

---
_TrendKia — Har trend, sabse pehle.. Machine-readable view; canonical HTML at the URL above._