India’s market regulator, SEBI, has penalized CDSL Rs 1 crore for cybersecurity lapses that enabled a severe 2022 malware attack. The investigation exposed critical unaudited internet servers, poor access management, and weak administrator passwords that disrupted national trade settlements and clearing operations for over 46 hours.
MUMBAI — The Securities and Exchange Board of India (SEBI) has imposed a monetary penalty of Rs 1 crore ($10\text{ million rupees}$) on Central Depository Services (India) Ltd (CDSL) following severe cybersecurity and compliance failures linked to a disruptive November 2022 malware attack.
According to the official adjudication order passed on July 20, 2026, the market regulator cited prolonged lapses in protecting critical infrastructure, weak administrative access controls, and inadequate real-time security monitoring. The 2022 cyber incident paralyzed key depository operations, causing significant downstream delays across broader Indian securities settlement cycles.
Gaps in ADFS Server Security Exploited by Threat Actor
The regulatory probe revealed that the root cause of the system breach was an inadequately secured, internet-accessible Active Directory Federation Services (ADFS) server. SEBI determined that despite clear rules mandating all internet-facing applications be cataloged as critical infrastructure assets, CDSL failed to include this specific server in mandatory vulnerability assessment and penetration testing (VAPT) cycles.
Furthermore, the server lacked integration with CDSL’s automated alert systems, including Security Information and Event Management (SIEM) and Privileged Identity Management (PIM) platforms. This structural blind spot permitted the digital threat actor to infiltrate internal networks silently and execute lateral movements without triggering defensive warnings.
The regulatory order rejected arguments from CDSL management that the server was non-critical because it did not directly host retail investor applications or proprietary financial data. SEBI emphasized that the repository's interconnected nature poses vast systemic risks to the entire financial ecosystem.
Systemic Fallout Halts Market Trade Settlements for Hours
The structural vulnerabilities culminated in a major service freeze beginning around 3:00 AM on November 18, 2022, when tech staff discovered restricted access to multiple operational servers. Network isolation measures successfully halted the malware's spread but simultaneously disabled core financial pipelines.
| Impacted Service Metric | Outage Duration Period |
| Inter-Depository Transfers | 54.5 Hours Disruption |
| Core Settlement Processes | 46.0 Hours Disruption |
| Scheduled Trading Clearances | Delayed from Nov 18 until Nov 20, 2022 |
SEBI’s enforcement order noted that the disruption directly stalled margin pledges, corporate action bookings, and trade clearances. Because national clearing corporations and stock exchanges rely heavily on immediate depository updates, the freeze caused immediate spillover backlogs for individual market participants, retail brokers, and institutional clearers.
Admin Password Left Unchanged Since 2021
In addition to structural omission flaws, the investigation unmasked fundamental hygiene lapses in CDSL's data security framework. Investigators noted that a domain administrator account created on the ADFS server back in 2021 was assigned a weak password highly vulnerable to basic brute-force dictionary attacks.
Compounding the risk, the credential parameters for this privileged account were explicitly configured to "Never Expire". This configuration omission allowed the threat actor to establish persistent access over an extended duration. During the breach, the hacker successfully overrode the terminal endpoint detection and response (EDR) software entirely by exploiting these excessive privileges.
Official Sources Section
The regulatory sanctions and technical findings are based directly on the final adjudication order issued by the Securities and Exchange Board of India (SEBI) under Section 15HB of the SEBI Act and Section 19G of the Depositories Act. The investigation integrated tech review proceedings from the High-Powered Steering Committee on Cyber Security (HPSC-CS) and historical disclosures from Central Depository Services (India) Ltd (CDSL).
Quote Section
"According to officials at the market regulator, the malware attack was the completely foreseeable outcome of accumulated cybersecurity lapses, including inadequate real-time monitoring and a severe failure to comply with rules for resuming trade settlement through backup recovery sites."
Why It Matters
For everyday investors and market participants, the action highlights a stricter enforcement era for market infrastructure institutions handling public wealth records. Demat account holders rely on instantaneous, uninterrupted clearing systems to manage capital risk. By penalizing top-tier repositories for background infrastructure neglect, the regulator enforces maximum operational resilience, protecting local investors from sudden liquidity blocks during volatile market windows.
Key Facts at a Glance
Financial Sanction: SEBI penalized CDSL a total of Rs 1 crore ($10\text{ million rupees}$), splitting the fine between the SEBI Act and the Depositories Act.
The Root Cause: An internet-facing application server was completely excluded from necessary vulnerability audits, permitting unalerted network infiltration.
Hygiene Failures: A critical domain administrator account was secured with a weak password and set to "Never Expire" parameters since 2021.
Extended Gridlock: Essential settlement operations and transfer capabilities were paralyzed for 46 to 54.5 hours, delaying nationwide transactions across a full weekend.
Executive Impact: Proceedings against the depository’s former Chief Information Security Officer (CISO) and Chief Technology Officer (CTO) were disposed of without personal monetary fines.
FAQ Section
What caused the 2022 market settlement delays at CDSL?
A localized malware attack forced the depository to isolate its network servers, disabling trade processing and delaying Friday’s financial settlements until Sunday afternoon.
How long does CDSL have to clear the penalty?
The capital markets regulator has directed CDSL to deposit the total Rs 1 crore penalty within 45 days of receiving the official adjudication mandate.
Was any retail investor data leaked during the cyberattack?
Initial post-incident assessments conducted alongside infrastructure institutions indicated that no specific investor data or financial balances were compromised or exfiltrated by the threat actor.
Source: Securities and Exchange Board of India Adjudication Registry, Central Depository Services (India) Ltd Corporate Relations