CDSL Share Price Falls 1% After SEBI Slaps Rs 1 Crore Fine Over 2022 Malware Attack
- July 21, 2026
- Posted by: Ankit Jaiswal
- Category: News
CDSL share price down 1.1% at Rs 1,369.90. SEBI fine: Rs 90 lakh under SEBI Act, Rs 10 lakh under Depositories Act. Attack disrupted settlements for up to 54.5 hours in Nov 2022.
The CDSL share price fell over 1 percent on 21 July 2026 after markets regulator SEBI imposed a Rs 1 crore penalty on the depository for cybersecurity lapses that contributed to a malware attack that disrupted its systems in November 2022. The stock slipped to Rs 1,369.90 on the NSE, down from a previous close of Rs 1,385.20.
SEBI’s order found that CDSL failed to classify an internet facing server as a critical asset, excluded it from vulnerability testing, and ignored cybersecurity deficiencies that the regulator itself had flagged in August 2022, months before the attack occurred. This article covers the details of the SEBI order, the scale of the 2022 disruption, and what it means for the CDSL share price going forward.
Click Here – Get Free Investment Predictions
About CDSL
CDSL (Central Depository Services India Limited) is one of India’s two securities depositories, holding electronic records of shares and other securities for investors instead of physical certificates. The company works through banks, stockbrokers, and other depository participants to provide demat account services to investors across the country.
CDSL handles a significant share of India’s investor accounts, with reports citing the depository as responsible for roughly 70 percent of the country’s demat accounts, a scale that made the November 2022 disruption a matter of systemic concern for the broader securities market rather than an isolated company specific incident.
Consult a SEBI Registered Investment Advisor on Univest
For a stock like the CDSL share price, this kind of regulatory finding matters because it speaks directly to operational resilience, a factor markets increasingly price into financial infrastructure companies.
What SEBI’s Order Against CDSL Found
SEBI’s investigation found that attackers had actually gained access to CDSL’s systems as early as November 2021, a full year before the malware attack was discovered and disrupted operations in November 2022. The regulator described the breach as a foreseeable outcome of accumulated lapses, including unwarranted policy deviations, unimplemented regulatory directions, and gaps in real time intrusion detection.
| Detail | Finding |
|---|---|
| Total penalty | Rs 1 crore (Rs 90 lakh under SEBI Act, Rs 10 lakh under Depositories Act) |
| Root cause | Internet facing ADFS server not classified as critical, excluded from testing |
| Regulator’s prior warning | Deficiencies flagged in August 2022, before the attack |
| Initial unauthorised access | November 2021, a year before the attack was discovered |
| Servers affected | 135 servers and 177 desktops and laptops infected |
| Settlement disruption | Up to 54.5 hours; inter-depository transfer disrupted 46 hours |
| Payment deadline | 45 days from the order |
SEBI also noted that CDSL failed to properly analyse security alerts and did not comply with rules requiring it to resume trade settlement through backup sites within the mandated timeframe, compounding the operational impact of the initial breach.
Why the CDSL Share Price Is Reacting to the SEBI Order
The CDSL share price decline reflects investor concern less about the size of the penalty itself, which at Rs 1 crore is modest relative to CDSL’s overall scale, and more about what the order reveals regarding the depository’s cybersecurity posture at the time of the attack. SEBI’s finding that attackers had access for a full year before detection raises questions about the adequacy of ongoing monitoring systems.
Markets infrastructure institutions like CDSL are treated as systemically important, since disruptions to depository operations ripple across settlement, pay-in and pay-out, and pledge related activities for the entire securities market. SEBI’s order specifically flagged the interconnectedness and interdependency of depositories as carrying broader implications for cyber risk across the financial system, a framing that likely weighs on sentiment beyond the immediate financial penalty.
What Happened in the November 2022 Malware Attack
The malware attack disrupted CDSL’s systems starting 18 November 2022, infecting 135 servers along with 177 desktops and laptops. Settlement activities, corporate actions, margin pledges, and inter-depository transfers were all affected, with the disruption delaying settlements scheduled for that date and forcing brokerages including Zerodha to inform clients about processing delays over the following weekend.
CDSL isolated the affected machines and disconnected from other market constituents as a containment measure, restoring systems by the following Monday after validation checks. Despite the operational severity at the time, SEBI’s order notes that CDSL undertook post-incident remedial measures, which the regulator took into account when calibrating the final penalty amount.
Traders watching the CDSL share price intraday will note the stock has held within a fairly narrow range today, suggesting the market is treating this as a manageable regulatory event rather than a deeper concern about the business.
Download the Univest iOS App or Univest Android App to track CDSL share price live and get regulatory and corporate action alerts.
The CDSL share price has historically traded at a premium multiple given the depository’s dominant market position, so any development that raises governance or operational questions tends to draw outsized scrutiny relative to the size of the actual financial penalty involved.
Individuals Cleared in the SEBI Order
Notably, SEBI dropped proceedings against CDSL’s former Chief Information Security Officer Rajesh Nadkarni and former Chief Technology Officer Amit Mahajan, stating that the lapses identified could not be attributed to them individually. This distinguishes the order as one focused on institutional and systemic failures at CDSL rather than individual accountability, which may factor into how investors read the corporate governance implications for the CDSL share price.
The next few sessions for the CDSL share price will likely hinge on broader market sentiment toward financial infrastructure stocks as much as on this specific order, given the manageable size of the penalty relative to the company’s scale.
Conclusion
SEBI’s Rs 1 crore penalty on CDSL for cybersecurity lapses tied to the November 2022 malware attack has weighed on the CDSL share price, which fell over 1 percent on 21 July 2026. While the financial penalty itself is modest, the regulator’s findings around a year long undetected intrusion and systemic monitoring gaps are likely to keep investor attention on the depository’s cybersecurity investments, an important input for anyone still weighing the CDSL share price today. Investors should track any further regulatory commentary and consult a SEBI registered adviser before acting on the CDSL share price.
Disclaimer: Data and figures in this article are sourced from publicly available information. These may or may not be accurate. Please verify all data with the official NSE (nseindia.com) and BSE (bseindia.com) websites before making any investment decision. Investments in securities are subject to market risk. This content is for educational purposes only and is not investment advice by Univest (SEBI RA INH000013776).
FAQs on CDSL Share Price and the SEBI Malware Attack Fine
Why did CDSL share price fall on 21 July 2026?
Ans. The CDSL share price fell over 1 percent after SEBI imposed a Rs 1 crore penalty on the depository for cybersecurity lapses that contributed to a malware attack that disrupted its systems in November 2022.
How much was the SEBI penalty on CDSL?
Ans. SEBI imposed a total penalty of Rs 1 crore on CDSL, comprising Rs 90 lakh under the SEBI Act and Rs 10 lakh under the Depositories Act, payable within 45 days of the order.
What caused the 2022 CDSL malware attack?
Ans. SEBI found that CDSL failed to classify an internet facing server as a critical asset and excluded it from vulnerability testing, allowing attackers to gain unauthorised access as early as November 2021, a year before the attack was detected.
How badly did the malware attack disrupt CDSL’s operations?
Ans. The attack infected 135 servers and 177 desktops and laptops, disrupting settlement activities for up to 54.5 hours and inter-depository transfers for 46 hours, delaying settlements scheduled for 18 November 2022.
Were any CDSL executives penalised by SEBI?
Ans. No, SEBI dropped proceedings against CDSL’s former Chief Information Security Officer Rajesh Nadkarni and former Chief Technology Officer Amit Mahajan, saying the lapses could not be attributed to them individually.
Is CDSL share price a buy after this SEBI order?
Ans. This article does not constitute investment advice. Investors should evaluate the company’s cybersecurity remediation progress and overall fundamentals, and consult a SEBI registered adviser before acting on the CDSL share price.
Where can I track CDSL share price live?
Ans. You can track the CDSL share price live on the Univest app and website, along with regulatory and corporate action alerts on listed market infrastructure companies.