CDSL fined ₹1 Cr by SEBI over 2022 malware incident
Central Depository Services (India) Limited was fined ₹1 crore by SEBI regarding a November 2022 malware incident due to observations on cyber security and operational resilience. The penalty was imposed under Section 15HB of the SEBI Act, 1992 and Section 19G of the Depositories Act, 1996. CDSL confirmed no material operational or financial impact beyond the penalty payment.

*this image is generated using AI for illustrative purposes only.
Central Depository Services (India) Limited has been penalized ₹1 crore by the Securities and Exchange Board of India (SEBI) in connection with a malware incident that occurred on November 18, 2022. The regulatory action follows observations regarding cyber security and operational resilience frameworks at the depository. The penalty, amounting to ₹1,00,00,000, was imposed via a letter dated July 20, 2026, under Section 15HB of the SEBI Act, 1992 and Section 19G of the Depositories Act, 1996.
SEBI's order highlights specific lapses in the cyber security and operational resilience measures required under the applicable regulatory framework. The regulator initiated enforcement action after reviewing the incident's circumstances and the company's adherence to prescribed norms. The penalty serves as a monetary consequence for the identified contraventions related to the malware event.
Despite the regulatory sanction, Central Depository Services (India) Limited disclosed that there is no material impact on its financials, operations, or other activities. The company clarified that the only quantifiable monetary effect is the payment of the proposed penalty amount. The disclosure was made to the National Stock Exchange of India Ltd. in compliance with Regulation 30 of the SEBI (Listing Obligations and Disclosure Requirements) Regulations, 2015.
The following table summarizes the key details of the regulatory action:
| Sr. No. | Particulars | Details |
|---|---|---|
| 1. | Name of the Authority | Securities and Exchange Board of India (SEBI) |
| 2. | Nature and details of the action(s) taken | A penalty of ₹ 1,00,00,000/- (Rupees One Crore only) has been imposed in connection with the malware incident that occurred on November 18, 2022. |
| 3. | Date of receipt of direction or order | July 20, 2026 |
| 4. | Details of the violation(s)/contravention(s) | The order contains observations with respect to certain cyber security and operational resilience related matters under the applicable regulatory framework. |
| 5. | Impact on financial, operation or other activities | There is no material impact on financials, operation or other activities of the Company, except the payment of the proposed penalty amount. |
The information was formally submitted by Nilay Rajendra Shah, Company Secretary & Compliance Officer of Central Depository Services (India) Limited. The company has also made the details available on its website.
Historical Stock Returns for CDSL
| 1 Day | 5 Days | 1 Month | 6 Months | 1 Year | 5 Years |
|---|---|---|---|---|---|
| +0.73% | -5.49% | -1.33% | +0.51% | -21.46% | +96.72% |
Will this penalty prompt SEBI to introduce stricter cybersecurity mandates for other depositories and market infrastructure institutions?
How might this regulatory action influence CDSL's client retention and acquisition strategies in the competitive depository market?
What specific technological upgrades or operational changes is CDSL likely to implement to prevent future malware incidents?


































