Google Drive ransomware detection enabled by default for paying users

by

Google said its AI-powered Google Drive ransomware detection feature is now generally available and enabled by default for paying users, after a rollout that began in beta for Google Workspace customers in October 2025.

KEY FACTS

  • Default setting The feature is on by default for users in business, enterprise, education and frontline organizations.
  • Response Drive pauses file syncing when it detects ransomware and alerts users and admins.
  • Restoration Users can restore corrupted files with the Drive restoration tool after an attack.
  • Coverage Google said its latest AI model detects 14 times more infections than the beta version.

Google said the system scans files as they sync from a desktop computer to Drive. If ransomware-encrypted files are found, desktop sync is paused, an email alert is sent to the affected user and a notice appears in Drive. An alert is also created in the Google Admin console.

The company said the feature can stop cloud files from being damaged even though it does not prevent files on the compromised computer from being encrypted. It also said the restoration tool can help undo ransomware changes once the infection is resolved.

Google said admins can turn the feature off for their organizations in the Admin console. It also said version 114 or later of Google Drive for desktop is needed on endpoints to enable detection alerts, although syncing will still pause on older versions.

Google Drive’s ransomware protection is part of a broader set of cloud storage defenses that also includes OneDrive ransomware detection and recovery and similar features from Dropbox.

WHY IT MATTERS

The default setting gives organizations a built-in way to limit the damage from ransomware by stopping cloud sync before more files are overwritten. It also gives users and administrators a faster path to recovery when encrypted files are detected.