Advertisement
Market

SEBI imposes Rs.1 crore penalty on CDSL, Know the whole story of 2022 malware attack

Connect with Us

SEBI has imposed a penalty of Rs 1 crore on Central Depository Services (India) Ltd (CDSL) for cybersecurity lapses that led to the November 2022 malware attack.

SEBI said that the breach was “foreseeable” and could have been prevented through compliance with mandatory security standards.

Advertisement

The Securities and Exchange Board of India (SEBI) levied a Rs 90 lakh penalty under the SEBI Act and Rs 10 lakh under the Depositories Act.

First understand what is CDSL and why is it important?

Central Depository Services (India) Limited (CDSL) is one of the two depositories in India that allows investors to keep their shares and other securities in electronic (demat) form instead of paper certificates.

Advertisement

It was established in 1999 and is regulated by the Securities and Exchange Board of India (SEBI). CDSL helps investors buy, sell, and transfer shares safely and quickly. It works through banks, stockbrokers, and other financial institutions, known as Depository Participants (DPs), which provide demat account services. CDSL plays an important role in making the Indian stock market secure, transparent, and efficient.

Malware Attack on CDSL

On 18 November 2022, CDSL witnessed a malware attack that infected 135 of CDSL’s 547 servers and 177 of its 506 desktops and laptops. This disrupted critical operations such as securities settlement, pay-in/pay-out and pledge-related services.

CDSL press release informing about malware attack
CDSL press release informing about malware attack

According to Sebi, key settlement systems remained disrupted for nearly 47 hours, while inter-depository transfer services were affected for more than 54 hours, impacting the smooth functioning of India’s securities market.

Sebi also said hackers had gained access to CDSL’s systems as early as November 2021, nearly a year before the attack was detected. It flagged several policy lapses, including an administrator account whose password was set to never expire even after Covid-era relaxations had ended.

Advertisement

SEBI said it had flagged these shortcomings to CDSL in August 2022, months before the malware attack, but the depository failed to fix them and instead relied on an earlier security assessment that Sebi found to be inadequate.

After around 4 years, SEBI has imposed penalty of Rs.1 crore on CDSL.

Proceedings against Top Officers of SEBI

Proceedings were started against CDSL’s former Chief Information Security Officer Rajesh Nadkarni and former Chief Technology Officer Amit Mahajan, but now SEBI has dropped these proceedings saying that the alleged lapses could not be held against them individually.

Advertisement

Advertisement
Advertisement

Hellobanker Team

Hellobanker.in is India's leading banking and finance news portal. Our expert team covers banking policies, RBI updates, financial markets, and investment insights.
Advertisement