SEBI fines CDSL Rs 1 Crore over cybersecurity lapses linked to 2022 malware attack
AI-generated from multiple sources. Verify before acting on this reporting.
MUMBAI — The Securities and Exchange Board of India (SEBI) imposed a fine of 1 crore rupees ($120,000) on Central Depository Services Limited (CDSL) on Sunday for cybersecurity lapses connected to a major malware incident that compromised the depository's systems in 2022. The penalty marks a significant regulatory enforcement action against one of India's two central securities depositories following an investigation into data security failures.
The Securities and Exchange Board of India, which regulates the country's capital markets, cited specific deficiencies in CDSL's internal controls that allowed unauthorized access to its network four years ago. During the 2022 attack, hackers infiltrated CDSL systems using malware, resulting in a massive exfiltration of data belonging to millions of investors and financial institutions. The breach exposed sensitive information including names, addresses, bank account details, and demat account numbers.
SEBI's order states that CDSL failed to maintain adequate cybersecurity protocols required under its regulations at the time of the incident. The regulator noted that while the company eventually detected the intrusion and took steps to contain it, the initial security gaps allowed attackers to operate within the network for an extended period before the breach was fully understood.
CDSL acknowledged the fine in a statement released following SEBI's announcement. The depository operator stated it has since implemented comprehensive upgrades to its cybersecurity infrastructure, including enhanced monitoring systems and stricter access controls, to prevent recurrence of such incidents. Company officials emphasized that no funds were stolen during the attack and that the primary impact was limited to data privacy concerns.
The 2022 malware incident remains one of the most significant cyberattacks on India's financial sector. At the time, the breach disrupted operations for numerous brokers and depository participants who rely on CDSL to hold securities in electronic form. The attack prompted a nationwide review of cybersecurity standards across Indian stock exchanges and clearing corporations.
SEBI has not indicated whether further penalties are expected or if criminal proceedings will be initiated against individuals responsible for the security lapses within CDSL's management structure. Regulators continue to monitor compliance with new directives issued in the aftermath of the breach, which mandate more rigorous third-party audits and real-time threat detection capabilities.
Industry observers note that while the fine serves as a deterrent, it does not address potential civil liabilities from affected investors who may seek compensation for privacy violations stemming from the data leak. Legal experts suggest that class-action lawsuits could emerge in coming months if regulators do not establish a clear framework for redressal regarding non-financial damages caused by cyber incidents.
As of Sunday evening, SEBI had not provided details on whether CDSL has already paid the penalty or intends to appeal the decision before an appellate tribunal. The regulator's order remains effective immediately upon publication.