SEBI Fine of Rs.1 crore on CSDL for Cyber Security Failures & Lapses in 2022 Malware Attack
The attacker had got access to the servers in November 2021 itself, whllst the attack was discovered in November 2022. Moreover, CDSL created an admin account in 2021 whose password was set to never expire and its relaxation regarding lock-out threshold to three failed attempts was not addressed until the malware attack. Even after Covid-19, these deviations from the policy continued and the CDSL did not even consider mitigating risk emanating from such deviations.
On 18.11.2022, it was found that a few servers and end user computers of CSDL were not accessible and there was malware attack.
Order imposing penalty of Rs.90 lakhs and Rs.10 lakhs under charging sections 15HB and 19G, respectively, of the SEBI Act
The vulnerabilities and lapses were exploited by the threat actor and enabled the malware attack. As a result of which, 135 out of 547 servers and 177 out of 506 desktops / laptops were infected. As a direct consequence of the attack, critical depository activities including settlement i.e. pay in / pay out, margin related pledge unpledged etc were not carried out on November 18, 2022.
Section 15-I of the SEBI Act and Rule 5 of the SEBI (Procedure for Holding Inquiry and Imposing Penalties) Rules, 1995,
Section 19H of the Depositories Act 1996 and the Depositories (Procedure for Holding Inquiry and Imposing Penalties) Rules, 2005
Order dated 20.7.2026 of the Adjudication Officer, SEBI, in Ref.No.Order / JS / RJ / 2026-27 / 32498-32500 in the matter of the Central Depository Services (India) Liited malware attack on 18 November, 2022.

