India markets regulator penalises depository over 2022 malware attack

MUMBAI, July 20 : India’s markets regulator on Monday imposed a fine of 10 million rupees on Central Depository Services (India) Ltd (CDSL) for multiple cybersecurity and compliance failures linked to a malware attack that disrupted depository operations in November 2022. Here are the key details• The regul


Business

India markets regulator penalises depository over 2022 malware attack

India markets regulator penalises depository over 2022 malware attack

FILE PHOTO: The logo of Securities and Exchange Board of India (SEBI) is seen on its headquarters in Mumbai, India, March 24, 2025. REUTERS/Hemanshi Kamani/File Photo

Read a summary of this article on FAST.

Get bite-sized news via a new
cards interface. Give it a try.

Click here to return to FAST
Tap here to return to FAST

FAST

MUMBAI, July 20 : India’s markets regulator on Monday imposed a fine of 10 million rupees on Central Depository Services (India) Ltd (CDSL) for multiple cybersecurity and compliance failures linked to a malware attack that disrupted depository operations in November 2022. Here are the key details

• The regulator said the Indian depository, which handles 83 million, or 70 per cent of the country’s investor accounts, had failed to classify an internet-facing server as a critical asset and to safeguard it, despite rules requiring such systems to be treated as such.

• This server was the root cause of the malware attack. By failing to secure this asset, the depository allowed cyber threats to gain access to its systems.

• SEBI also found that the depository failed to detect intrusions in real time, to properly analyse security alerts and to comply with rules for resuming trade settlement through backup sites.

Guess Word

Guess Word
Crack the word, one row at a time


Buzzword

Buzzword
Create words using the given letters


Mini Sudoku

Mini Sudoku
Tiny puzzle, mighty brain teaser


Mini Crossword

Mini Crossword
Small grid, big challenge


Word Search

Word Search
Spot as many words as you can


Show More


Show Less

• The attack disrupted critical depository functions including settlement activities, corporate actions, margin pledges and inter-depository transfers, delaying settlements scheduled for 18 November 2022, SEBI said.

• SEBI noted that the malware attack was the foreseeable outcome of accumulated cyber-security lapses, including inadequate monitoring, weak password controls and failure to implement required cyber-security safeguards.

Source: Reuters

Sign up for our newsletters

Get our pick of top stories and thought-provoking articles in your inbox

Inbox

Get the CNA app

Stay updated with notifications for breaking news and our best stories

Get WhatsApp alerts

Join our channel for the top reads for the day on your preferred chat app

Whatsapp

Get bite-sized news via a new
cards interface. Give it a try.

Click here to return to FAST
Tap here to return to FAST

FAST

About The Author

Leave a Reply

Your email address will not be published. Required fields are marked *

About the Author

Easy WordPress Websites Builder: Versatile Demos for Blogs, News, eCommerce and More – One-Click Import, No Coding! 1000+ Ready-made Templates for Stunning Newspaper, Magazine, Blog, and Publishing Websites.

BlockSpare — News, Magazine and Blog Addons for (Gutenberg) Block Editor

Search the Archives

Access over the years of investigative journalism and breaking reports