Google adds AI ransomware protection to Drive for Desktop
- Google added AI ransomware protection to Drive for Desktop.
- It detects attacks early, pauses syncing, and restores files fast for free.
Ransomware continues to be one of the most damaging cyberattacks for businesses and public institutions. These incidents often cause heavy financial losses, disrupt operations, and expose sensitive data. No sector is spared—healthcare, retail, education, manufacturing, and government agencies have all been hit. In 2024, Mandiant (part of Google Cloud) found that ransomware accounted for 21% of all intrusions it investigated. The average cost of a single ransomware or extortion case was more than US$5 million.
Mandiant also reported that most organisations in Japan and across Asia Pacific only learned about ransomware attacks from outsiders. In 89% of the cases investigated, the first alert came from the attackers themselves or law enforcement, not from the victims’ own security systems. This shows that many organisations still lack strong internal detection, leaving them unaware of breaches until the damage is already done.
Some files are naturally safer than others. Native Google Workspace formats like Google Docs and Sheets are not affected by ransomware, and ChromeOS has never experienced a ransomware attack. But other file types—such as PDFs and Microsoft Office documents—remain at riskespecially on desktop operating systems like Windows.
To address this, Google Cloud is adding new AI-based ransomware detection and recovery features to Google Drive for Desktop. The goal is to stop ransomware activity automatically and let users recover files quickly with minimal hassle.
Why traditional defences fall short
For years, the main strategy against ransomware has been antivirus software: detect malicious code early and block it before it spreads. This remains important, but it’s not enough on its own. Modern ransomware can slip past traditional defences, leaving users with no way to recover their files. And these attacks no longer affect only IT systems—they can bring down factories, hospitals, retail services, and government operations. A broader approach is needed to contain the damage.
Hana Raja, Country Manager for Malaysia at Google Cloud, said the new feature acts as an extra line of defence against ransomware. Traditional antivirus tools focus on blocking malicious software from entering a systembut attackers often find ways around those barriers. The new system is designed to step in when that happens.
“Our AI-powered detection and intervention in Google Drive for Desktop identifies the core signature of a ransomware attack—an attempt to encrypt files en masse—and rapidly intervenes to put a ‘protective bubble’ around a user’s files before it can spread,” Raja explained. By stopping file syncing to the cloud at the first sign of unusual activity, the system aims to limit the damage before files are corrupted.
She also pointed out that Drive’s existing malware protections add another layer of security. These built-in defences help prevent ransomware from spreading to other devices and moving across networks. Together, these measures are meant to reduce the kind of widespread disruption that has hit businesses, schools, hospitals, and government agencies in the past.
How Google uses AI to detect ransomware attacks early
Google Drive for Desktop, available on Windows and macOS, is often used to sync files to the cloud. It can now also serve as a security tool. Luke Camery, Product Manager for Security and ComplianceCollaboration Applications at Google Workspace, explained that files uploaded to Drive are already scanned for malware as part of Google’s existing protections. “That already happens today. We are constantly improving our malware detection for Drivebut any files backed up to Drive are already scanned for malware,” he said.
The new ransomware detection feature builds on this foundation. Google Cloud trained a custom AI model on millions of ransomware samples collected from multiple sources, including consumer Drive data, Mandiant, and VirusTotal. According to Camery, the model was designed to handle a wide variety of file formats, “not just PDFs or Office files, but CAD files and basically any format we can interpret—essentially everything except binary files.” The system constantly learns from new examples, making it adaptive to novel ransomware variants without requiring manual updates.
When Google Drive spots unusual activity that looks like ransomware, it immediately pauses syncing of the affected files. This helps contain the attack and prevents it from corrupting the user’s cloud storage. Camery said detection typically kicks in after three to four modified files. “We need to see the first malicious change come throughso it will be at least one file. But given how high our precision is at this point, I wouldn’t expect to lose more than five files,” he explained. Once the attack is detected, syncing is blocked until the device is cleared by the user or admin. Files can then be reverted to their state just before the attack.
Fast recovery and admin controls
Once ransomware activity is detected, users receive alerts on their desktop and by email. They can restore files themselves using a simple web interface. Unlike older recovery methods that involve re-imaging devices or paying for third-party tools, this process only takes a few clicks. It lets people get their files back quickly and reduces downtime.
For IT administrators, ransomware alerts also appear in the Admin console. They can review detailed audit logs through the security centre. The feature is switched on by default for Google Workspace customers, but admins can turn off detection, intervention, or restoration if needed.
Camery added that the system doesn’t require special authentication settings to work, though Google strongly recommends MFA for broader security. “This will apply to nearly all commercial Workspace customers, regardless of their login type,” he said.
Using Google AI features alongside existing backups
The restore feature also has implications for how organisations think about backups. Camery noted that while many businesses still rely on third-party solutions for compliance or regional disaster recovery, Google aims to reduce that dependence. “We focused on a solution that can stay in place without increasing storage costs for customers,” he said. Drive’s built-in protections and file version history already provide strong fallback options for most ransomware incidents.
Availability and future plans
Google has tested the ransomware detection feature with some of its largest Workspace customers, who are expected to adopt it quickly once it rolls out. Camery acknowledged that no system is perfect and false detections can happenoften triggered by testing activity that looks like malicious file encryption. But he emphasised that the goal is to block harmful behaviour early. “If something—whether an AI bot, ransomware, or a user—is destroying corporate PDFs, Google Drive will cut it off,” he said.
Looking ahead, there are no immediate plans to extend this capability to Google Cloud Storage, though Camery said it’s something to watch for in the future. Google has also not partnered directly with Microsoft or Apple on the detection technologythough integration at the system-call level allows it to catch file changes quickly on both platforms.
The AI-powered ransomware detection and recovery feature is rolling out in open beta starting today. It’s included in most Google Workspace commercial plans at no extra cost. Consumers can also use the file restoration feature without paying more.
Want to learn more about Cloud Computing from industry leaders? Check out Cyber Security & Cloud Expo taking place in Amsterdam, California, and London. The comprehensive event is part of TechEx and is co-located with other leading technology eventsclick here for more information.
CloudTech News is powered by TechForge Media. Explore other upcoming enterprise technology events and webinars here.
TNG – Latest News & Reviews

