Detect ransomware by checking for sudden file encryption, ransom notes, large-scale file changes, disabled security tools or backups, and unusual account or network activity. If you suspect an active attack, disconnect affected devices from the network immediately.

Last reviewed:

The 9 signs below can help you identify ransomware activity before or during encryption. A single unreadable file does not confirm an attack, but rapid changes across many files, systems or accounts require immediate investigation.

Ransomware Detection at a Glance

Sign What you may notice What it can indicate
Ransom note A text, HTML or image file demanding payment The attack has reached encryption or extortion
Files will not open Documents, photos or databases show errors Files may have been encrypted or damaged
New file extensions Files have unfamiliar extensions or renamed filenames Automated encryption activity
Mass file changes Many files are modified, renamed or deleted within minutes Active ransomware behavior
Shared drives affected Network folders and servers become inaccessible Ransomware may be spreading through the network
Backups unavailable Shadow copies, backup software or recovery tools stop working Attackers may be blocking recovery
Suspicious account activity New administrator accounts, unusual VPN logins or privilege changes Possible attacker access before encryption
Security controls disabled Antivirus, logging or endpoint protection stops working Attackers may be preparing to deploy ransomware
Unusual data transfers Large outbound uploads or cloud downloads Possible data theft before extortion

What to Do if Ransomware May Be Active

  1. Disconnect affected computers from Wi-Fi, Ethernet and shared networks.
  2. Isolate impacted servers and network segments.
  3. Do not reconnect backup drives or begin restoration yet.
  4. Contact your IT team, managed security provider, cyber insurer or incident-response firm.
  5. Preserve ransom notes, suspicious files, logs and screenshots.
  6. Use a separate communication method, such as a phone, if attackers may have access to email or messaging.

CISA recommends isolating affected systems immediately. If a device cannot be disconnected from the network, powering it down may limit further spread. However, shutting it down can destroy evidence stored in volatile memory.

1. Look for Ransom Notes

A ransom note is one of the clearest signs of ransomware. It may appear as:

  • A text file in multiple folders
  • A changed desktop wallpaper
  • An HTML page that opens when users sign in
  • A cryptocurrency payment demand
  • Instructions to contact an attacker by email, chat service or website

A ransom note confirms extortion activity, but it does not show the full scope of the compromise. Attackers may steal data before encrypting systems, and more than one ransomware variant can affect the same environment.

Do not delete the note. Preserve a copy for your incident-response team and law enforcement.

2. Check Whether Files Were Encrypted or Renamed

Ransomware often changes file names or extensions and prevents normal applications from opening the files.

Common symptoms include:

  • Word, Excel, PDF, image or database files suddenly failing to open
  • Files receiving a new or unfamiliar extension
  • Large numbers of filenames changing
  • Duplicate ransom notes appearing across folders
  • File timestamps changing unexpectedly
  • Shared folders becoming inaccessible at the same time

One damaged or unreadable file does not prove ransomware. A failing disk, software error, cloud-sync conflict or permissions problem can cause similar symptoms. Rapid changes across many files and folders are more consistent with automated encryption.

Microsoft identifies endpoint file encryption, widespread malware activity and unusual file deletion as ransomware detection signals.

3. Watch for Mass File Deletion and Modification

Ransomware may encrypt files and delete the original versions. In cloud environments, attackers may also create unusual patterns of uploads, downloads or deletions.

Investigate activity such as:

  • Hundreds or thousands of files modified within a short period
  • A user deleting far more files than usual
  • Large numbers of files uploaded to unfamiliar cloud services
  • File activity outside the user's normal working hours
  • One account accessing many folders or shared drives
  • Backup snapshots or recovery files being deleted without a valid reason

Cloud security systems can identify these changes by comparing current activity with a user's normal behavior.

4. Check Whether Backups and Recovery Tools Were Targeted

Attackers may try to block recovery before deploying ransomware. Warning signs include:

  • Backup jobs suddenly failing
  • Backup credentials being changed
  • Recovery snapshots being deleted
  • Volume Shadow Copies being removed
  • Windows recovery settings being modified
  • Backup servers becoming inaccessible
  • Security or monitoring tools being disabled

CISA recommends checking for unusual use of tools such as vssadmin.exe, wbadmin.exe, wmic.exe, bcdedit.exe and fsutil.exe. Attackers may use these tools to interfere with system recovery.

A backup is not necessarily safe because it still exists. Scan backups for malware and confirm that the initial compromise has been removed before restoring systems.

5. Investigate Early Warning Signs Before Encryption

Ransomware is often the final stage of a broader intrusion. Attackers may spend hours or days stealing credentials, moving through the network and copying data before encrypting files.

Look for:

  • New user or administrator accounts
  • Unexpected privilege escalation
  • Suspicious VPN or remote desktop logins
  • Unusual use of remote monitoring and management software
  • Unexpected PowerShell or PsTools activity
  • New scheduled tasks or services
  • Credential-dumping tools or suspicious access to Active Directory
  • Endpoint-to-endpoint connections that are not normal for the environment
  • Security or PowerShell logs being cleared
  • Antivirus, EDR or other security controls being disabled

CISA recommends threat hunting for new privileged accounts, unusual VPN logins, unexpected RMM software, PowerShell use, credential dumping, new services and unusual internal communications. Microsoft also recommends monitoring for new applications, role changes, mailbox-rule changes and attempts to disable security controls.

6. Check for Data Theft as Well as Encryption

Modern ransomware attacks may involve double extortion. In these incidents, attackers steal sensitive data and then encrypt systems or threaten to publish the stolen information.

Possible indicators include:

  • Abnormally large outbound data transfers
  • New connections to file-storage or transfer services
  • Use of Rclone, Rsync, FTP or SFTP without an approved business reason
  • Large downloads from cloud storage
  • Unusual access to sensitive file shares
  • Compressed archives created shortly before data leaves the network

CISA lists abnormal outbound traffic, Rclone, Rsync, FTP/SFTP and cloud-based transfer activity as possible signs of data exfiltration during ransomware investigations.

How Security Teams Confirm Ransomware

A security team should compare several sources of evidence instead of relying on a single alert:

  • Endpoint detection and response: Identify the process modifying files and isolate affected devices.
  • Antivirus and malware alerts: Look for ransomware binaries or earlier malware.
  • File and cloud activity logs: Identify mass encryption, deletion, downloads and uploads.
  • Identity logs: Review VPN, remote desktop, administrator and single sign-on activity.
  • Windows event logs: Check PowerShell, authentication, SMB and remote-connection events.
  • Network monitoring: Look for lateral movement and unusual outbound traffic.
  • Backup logs: Determine whether attackers accessed or deleted recovery systems.

CISA recommends reviewing antivirus, EDR, IDS and other logs to identify both the ransomware and earlier malware that may have enabled the attack.

What Not to Do

Avoid these mistakes:

  • Do not keep using an infected computer normally.
  • Do not reconnect isolated systems to see whether the problem is fixed.
  • Do not delete ransom notes or suspicious files.
  • Do not restore backups before checking that attackers no longer have access.
  • Do not assume that only encrypted computers are compromised.
  • Do not negotiate or pay before consulting legal counsel, law enforcement, your insurer and an incident-response specialist.

The FBI states that paying a ransom does not guarantee data recovery and does not support paying ransom demands.

Report the Incident

In the United States, organizations can report ransomware to:

  • The FBI Internet Crime Complaint Center, known as IC3
  • A local FBI field office
  • CISA
  • The U.S. Secret Service
  • Their cyber-insurance provider and incident-response partner

Record the ransomware name if known, affected file extensions, attacker contact details, cryptocurrency wallet addresses, ransom amount and whether any payment was made. These details can help investigators identify the ransomware variant and connect related incidents.