SEBI Fines CDSL ₹1 Crore Over 2022 LockBit Ransomware Attack

Ruchi Shukla

21 July 2026 8:05 PM IST

  • SEBI Fines CDSL ₹1 Crore Over 2022 LockBit Ransomware Attack

    The Securities and Exchange Board of India (SEBI) has imposed a Rs. 1 crore penalty on securities depository Central Depository Services (India) Limited (CDSL) after finding that its failure to implement prescribed cybersecurity measures enabled the 2022 LockBit ransomware attack, disrupting settlement activities and affecting investors.

    SEBI Adjudicating Officer Jai Sebastian, in an order dated July 20, held that CDSL failed to implement several mandatory cybersecurity controls, resulting in violations of SEBI's cybersecurity framework.

    "On consideration of the aforesaid, it becomes evident that the malware attack was the foreseeable outcome of lapses that had built up over time, which, inter alia, included unwarranted policy deviations, unimplemented regulatory directions, absence of the cybersecurity measures on ADFS server and a failure to re-audit notwithstanding a specific direction," the regulator observed.

    The proceedings against CDSL resulted from SEBI's examination of the malware attack detected at CDSL on November 18, 2022. CDSL discovered that several of its servers and end-user computers were inaccessible due to a malware attack, identified as LockBit 3.0 ransomware. In response, the depository isolated its systems and disconnected its network to prevent malware infection from spreading, and this caused a significant disruption to critical depository operations.

    The malware attack disrupted settlement operations and other critical depository services. According to the regulator, settlement activities remained disrupted for about 46 hours, while inter-depository transfers were affected for over 54 hours, necessitating the completion of the settlement scheduled for November 18 on November 20.

    Following the incident, the regulator examined forensic reports and CDSL's compliance with the Cyber Security and Cyber Resilience Framework prescribed for Market Infrastructure Institutions.

    SEBI alleged that the CDSL violated multiple regulatory mandates by failing to classify the internet-facing ADFS (Active Directory Federation Service) server as a critical asset following a May 2022 circular modification. As a result, it was excluded from mandatory security audits and real-time monitoring.

    It further alleged that CDSL failed to conduct proper vulnerability scanning and penetration testing of all critical assets and infrastructure components. The regulator added that CDSL maintained weak access controls, including the “Never Expire” password for the domain admin account on the ADFS server. It was also alleged that the depository failed to declare a disaster or restore operations within the mandated recovery time.

    CDSL, on the other hand, argued that it had the discretion to choose which internet-facing applications were critical. It maintained that the ADFS server was not deemed critical for business operations at the time based on the risk assessment conducted.

    Rejecting CDSL's claims of discretion, the adjudicating officer (AO) noted that the SEBI's 2022 mandate was intentionally expansive to ensure all internet-facing systems were treated as critical assets.

    The AO also noted that the failure of CDSL to rectify pandemic-era security gaps, even after more than a year of their implementation, was a significant dereliction of duty.

    It further held, “I find that the integrity of the securities was put at risk not by an unforeseeable or random event, but by a series of failures that could, and ought to have been avoided in the normal course.”

    The AO held that CDSL's lapses before and after the malware attack reflected its failure to proactively protect investors' interests and market integrity, citing its failure to identify and classify critical assets properly, conduct mandatory vulnerability assessments, detect security incidents in real time, and declare a disaster within the stipulated time period following the malware attack.

    It was also noted that the disruption at CDSL had a major spillover impact as the settlement activities for the entire securities market were also dependent upon the normal functioning of CDSL systems.

    It was emphasized that considering the systemic importance of CDSL's operations, noting that it is the largest depository of India managing 70% of the demat accounts, the lapses on the part of the depository can not be dismissed as mere technicalities.

    The AO held that the depository had failed to comply with multiple provisions of SEBI's cybersecurity framework and violated regulations under SEBI (Depositories and Participants) Regulations, 2018 and other circulars. Accordingly, SEBI imposed a Rs. 90 lakh penalty on CDSL under Section 15HB of the SEBI Act along with a Rs. 10 lakh penalty under Section 19G of the Depositories Act.

    Noting that these failures were institutional rather than individual, the AO disposed of the charges against the former Chief Information Security Officer and the Chief Information Security Officer.

    Next Story