Moneycontrol PRO
HomeTechnologyAmid India-Pakistan tensions, CDSL warns depository participants of phishing, malware attacks

Amid India-Pakistan tensions, CDSL warns depository participants of phishing, malware attacks

The alert warns of an increased risk of phishing, malware attacks, and system breaches targeting financial infrastructure

May 08, 2025 / 11:58 IST
CDSL is Asia's only listed depository service, with a market capitalisation of nearly Rs 31,300 crore.

Central Depository Services Ltd (CDSL) has asked its depository participants to remain vigilant, warning of a heightened risk of cyberattacks amid worsening tensions with Pakistan.

In a May 6 communique, CDSL’s chief information security officer Akhil Wadhavkar cautioned participants about the possible increase in phishing campaigns, social engineering attempts and malware attacks.

"In light of the ongoing current geopolitical situation, we urge all depository participants to remain extra vigilant against potential cyber threats. During such period, threat actors often exploit uncertainty to launch phishing attacks, spread misinformation, and attempt to compromise systems and data," the advisory read.

The advisory came a day before Indiana armed forces struck nine terror targets in Pakistan and Pakistan-occupied Kashmir. Operation Sindoor was launched two weeks after 26 people were killed in a terror attack in Pahalgam. Two of the terrorists involved in the April 22 strike were Pakistanis, the authorities have said.

The advisory asked depository participants to issue internal alerts to staff, for sensitising them to avoid suspicious links, report anomalies, and be cautious of unexpected requests for sensitive information.

The advisory singles out Excel files, particularly those with the .XLAM extension, as a common malware delivery mechanism in circulation.

CDSL also stressed the importance of patching critical software vulnerabilities and securing internet-facing systems such as VPNs, firewalls, and email servers.

The advisory recommended organisations to activate 24x7 security monitoring or designate an on-call response team for unusual login attempts, or distributed denial-of-service (DDoS) attacks.

Depository participants have also been directed to revisit their cyber incident response plans to ensure swift internal communication during a breach and to coordinate with government agencies such as CERT-In and SEBI for real-time reporting.

Invite your friends and family to sign up for MC Tech 3, our daily newsletter that breaks down the biggest tech and startup stories of the day

Aihik Sur covers tech policy, drones, space tech among other beats at Moneycontrol
first published: May 8, 2025 11:56 am

Discover the latest Business News, Sensex, and Nifty updates. Obtain Personal Finance insights, tax queries, and expert opinions on Moneycontrol or download the Moneycontrol App to stay updated!

Subscribe to Tech Newsletters

  • On Saturdays

    Find the best of Al News in one place, specially curated for you every weekend.

  • Daily-Weekdays

    Stay on top of the latest tech trends and biggest startup news.

Advisory Alert: It has come to our attention that certain individuals are representing themselves as affiliates of Moneycontrol and soliciting funds on the false promise of assured returns on their investments. We wish to reiterate that Moneycontrol does not solicit funds from investors and neither does it promise any assured returns. In case you are approached by anyone making such claims, please write to us at grievanceofficer@nw18.com or call on 02268882347
CloseOutskill Genai