PanicStation.org
uk Technology & digital loss

What to do if…
your files suddenly change names or extensions and you do not know why

Produced and maintained by PanicStation.org Published: Last reviewed: Editorial policy UK guide

Short answer

Treat this as possible ransomware or malware until proven otherwise. Disconnect the affected device from Wi-Fi, Ethernet, and mobile hotspot or mobile data, then pause cloud sync from a known-clean device if you can.

Do not do these things

  • Don’t keep renaming files, running random cleanup tools, or repeatedly restoring files while the affected device may still be connected.
  • Don’t plug in extra USB drives or external drives to “back up quickly”.
  • Don’t pay, message attackers, or follow ransom-note instructions in a rush.
  • Don’t wipe or reinstall straight away if you may need help from work IT, a trusted repair professional, insurance, or a reporting service.
  • Don’t assume it is only a display setting if many files changed at once, files will not open, or a ransom note appears.

What to do now

  1. Isolate the affected device first.

    • Turn off Wi-Fi on the device.
    • Unplug Ethernet.
    • Disconnect it from any mobile hotspot or mobile data connection.
    • If it is on a home or work network and files are still changing, consider turning off Wi-Fi at the router briefly while you get help.
  2. Stop sync and sharing without reconnecting the suspect device.

    • From another device you trust, open the cloud provider’s website and pause sync, unlink the affected device, or stop sharing for the affected folders if those options are available.
    • If the affected files are on a shared drive or NAS, disconnect that storage from the network if you can do so safely.
    • Leave external drives unplugged until someone trusted has checked the situation.
  3. Record what changed.

    • Take photos or screenshots of changed file names, new extensions, error messages, ransom notes, and the time and date you noticed the problem.
    • Write down which folders, drives, or cloud areas look affected.
    • Do not open ransom-note links or download anything from them.
  4. Check for spread from a known-clean device.

    • Check whether the same changed files appear in your cloud storage, shared drive, or other devices.
    • If another device shows the same sudden changes, disconnect that device from networks too.
    • Do not reconnect the first device to “compare” files.
  5. Use the right help route.

    • If this is a work, school, charity, or organisation device, contact IT or the person responsible for systems immediately and say: “possible ransomware, file renaming, and encryption”.
    • If you are an individual in England, Wales, or Northern Ireland, use Report Fraud to report cyber crime or fraud.
    • If you are in Scotland, use 101 unless it is an emergency.
  6. If changes continue while the device is offline, stop using it.

    • If file names or extensions keep changing after you have disconnected networks and storage, shut the device down.
    • Leave it off until IT or a reputable computer security professional can advise.

What can wait

  • You do not need to decide today whether to wipe the device.
  • You do not need to identify the exact malware name right now.
  • You do not need to attempt full recovery immediately.
  • You do not need to contact everyone you know before you have contained the device and checked whether anything else is affected.

Important reassurance

It is normal to feel panicked when many files suddenly change. Pausing, disconnecting, and documenting before trying fixes is a strong first move and can reduce further damage.

Scope note

These are first steps only, focused on containment and avoiding irreversible mistakes. Recovery, restoring backups, rebuilding devices, account security, insurance, and organisational reporting may need specialist help.

Important note

This is general information, not professional forensic, legal, financial, or technical advice. If you are unsure what caused the change, acting cautiously as if it may be ransomware is usually the safer first step.

Additional Resources

About this guide

This guide was produced and is maintained by PanicStation.org using its published editorial process. Official and specialist sources are checked where relevant, and AI-assisted tools may be used for drafting, organisation, and consistency checks. The site operator remains responsible for publication, revision, and removal decisions.

Support us