How to Confirm Your Mac Has Ransomware

    Identify true Mac ransomware vs. lookalike browser pop-ups.

    JDCS
    By Jordan Dickson · Reviewed by CSG Security Engineers

    Updated June 2026 · 1 min read

    Mac ransomware is rare but real (e.g., NotLockBit, Turtle, KeRanger). Most 'your files are encrypted' messages on Mac are actually browser scareware that disappears when you close the tab.

    Signs of real ransomware

    • Files in Documents, Pictures and Desktop have new extensions like .encrypted, .lock, .crypto
    • Files no longer open in Preview, Pages or Photos
    • A README.txt or HOW_TO_DECRYPT.txt file appeared in many folders
    • Persists after restart and after closing the browser

    Signs it is fake browser scareware

    • Goes away when you force-quit Safari/Chrome (⌘ ⌥ Esc)
    • Files still open normally in Preview/Pages
    • Includes a phone number or asks you to call AppleCare (real ransomware never does this)

    Was this guide helpful?

    Know someone who needs this? Send them the guide.

    JD

    Written by

    Jordan Dickson

    Founder, CyberSecurityGuides

    Founder of CyberSecurityGuides, writing practical, jargon-free guides that help everyday people recover from and protect against online attacks.

    Reviewed by CSG Security Engineers

    More from Device Security