# CDSL fined ₹1 crore over cybersecurity lapses behind the 2022 malware attack

**URL:** https://tradingqna.com/t/cdsl-fined-1-crore-over-cybersecurity-lapses-behind-the-2022-malware-attack/196160
**Category:** General
**Created:** [July 21, 2026, 4:30am UTC](https://tradingqna.com/t/cdsl-fined-1-crore-over-cybersecurity-lapses-behind-the-2022-malware-attack/196160 "2026-07-21T04:30:08Z")
**Posts on this page:** 2
**Page:** 1

<div class="post-metadata">

### Author: ![bearishbhaiya](https://tradingqna.com/user_avatar/tradingqna.com/bearishbhaiya/32/84894_2.png) [@bearishbhaiya](https://tradingqna.com/u/bearishbhaiya)
#### Post date: [July 21, 2026, 4:30am UTC](https://tradingqna.com/t/cdsl-fined-1-crore-over-cybersecurity-lapses-behind-the-2022-malware-attack/196160/1 "2026-07-21T04:30:08Z")

</div>

Remember November 2022, when CDSL had a malware attack and settlement activities came to a halt? SEBI has now imposed a ₹1 crore penalty.

According to SEBI’s 88-page order, the attackers had already gained access to CDSL’s systems in November 2021 and remained there for almost a year before the malware attack was detected. The regulator says an internet-facing ADFS server wasn’t classified as a critical system, so it wasn’t covered under vulnerability testing, privileged access management or security monitoring. There was also an administrator account with a password set to never expire, no two-factor authentication, relaxed account lockout policies, and multiple security alerts that were either ignored or not investigated.

SEBI’s conclusion is the impact was largely due to failures in implementing basic cybersecurity controls rather than the sophistication of the attack.

> **[SEBI | Adjudication Order in the matter of Central Depository Services India...](https://www.sebi.gov.in/enforcement/orders/jul-2026/adjudication-order-in-the-matter-of-central-depository-services-india-limited-malware-attack-on-november-18-2022_102967.html)**
>
> Securities and Exchange Board of India is made for protect the interests of investors in securities and to promote the development of, and to regulate the securities market and for matters connected therewith or incidental thereto

Everyone is busy selling the future while the backbone of the market feels stuck in the past. Brokers are in an arms race over AI, instant onboarding, smarter charts, and every new feature imaginable. Yet exchanges, depositories, and other market infrastructure often feel like they’re running on stone age tech and processes.

SEBI’s order doesn’t point to some Hollywood-style cyberattack. It points to basic cybersecurity lapses. That’s the worrying part. You can build the smartest trading app in the world, but if the infrastructure that settles trades and holds our securities can’t consistently get the fundamentals right, every shiny new feature is built on a weak foundation.

> **[SEBI penalises CDSL for cybersecurity lapses behind 2022 malware attack,...](https://www.moneycontrol.com/news/business/markets/sebi-penalises-cdsl-for-cybersecurity-lapses-behind-2022-malware-attack-imposes-1-crore-penalty-13978860.html)**
>
> SEBI has penalised CDSL, holding that multiple cybersecurity failures, including leaving an internet-facing server outside critical security controls, weak access management and inadequate monitoring of alerts.

---

<div class="post-metadata">

### Author: ![Shayoni](https://tradingqna.com/user_avatar/tradingqna.com/shayoni/32/74474_2.png) [@Shayoni](https://tradingqna.com/u/Shayoni)
#### Post date: [July 21, 2026, 5:55am UTC](https://tradingqna.com/t/cdsl-fined-1-crore-over-cybersecurity-lapses-behind-the-2022-malware-attack/196160/2 "2026-07-21T05:55:27Z")

</div>

> [@bearishbhaiya](#):
>
> Remember November 2022, when CDSL had a malware attack and settlement activities came to a halt? SEBI has now imposed a ₹1 crore penalty.

Now the question is, who holds the regulator accountable? It took nearly four years for this matter to reach a conclusion.

Wonder who audits the regulator’s response time.
