A recovery screen asking for forty-eight digits, and a household or an office where nobody remembers being asked to encrypt anything. That is the ordinary beginning. Three sorts of work follow from it: tracing a key that was escrowed somewhere and forgotten, opening a batch of machines inherited from staff who have left, and lifting data off a sealed disk that is dying at the same time. Every route runs through the cipher rather than round it, because there is no way round it.
Looking at a BitLocker volume costs nothing. What comes out of that examination is one written figure, agreed between us before anybody picks up a screwdriver: £400 + VAT on a BitLocker volume, and the same on any other encrypted disk.
Logical work is no fix, no fee. Four things sit outside that: electronic and mechanical failures, chip-level work, DVR jobs and forensic work, and anything physical is half up front. All five bands are laid out on the data recovery cost page, while data recovery services follows a postal job from the parcel to the answer.
Tracing a symptom back to whatever caused it is where the job genuinely starts, and these thirty cover very nearly every box opened on the Oxford bench. A fault that is not on the list is not an unfamiliar one: describe it over the telephone and you will get a straight reading of the odds before you have spent a penny on postage.
Something underneath changed — firmware, a mainboard, the boot order, a chip somebody reset — and Windows now reads the computer as a different computer from the one it sealed the volume to. It will not move until the digits are typed in. Nothing behind that screen is damaged, and the key nearly always still exists somewhere.
This belongs near the top rather than in the small print. Without the recovery key or the password, a correctly sealed BitLocker volume does not open — not here, not anywhere, not for any fee. Nothing on this bench attacks the mathematics, because the mathematics holds. Everything on it is aimed at finding a key that already exists.
The commonest ending to these jobs, and an undramatic one. Windows very seldom seals a volume without escrowing a copy first, so the exercise is working out where it went. A household account, signed into on a phone, will frequently produce the key in the time it takes to log in and look.
Company machines escrow into Entra, Azure AD or an older on-premises directory, and a great many lockouts finish with an administrator finding the entry in a couple of minutes. Where the tenant itself has been lost, or the only administrator account left with a departing employee, the position is harder and is assessed honestly.
Recent Windows laptops turn device encryption on by themselves the first time somebody signs in with a Microsoft account, and the household discovers this on the day a firmware update triggers the recovery prompt. Nothing was chosen and nothing is broken. The key is usually filed against that same account.
The TPM releases the key only when the machine measures the same as it did when the volume was sealed. Update the firmware and the measurements move, so the chip holds on to it. The recovery key opens it, and where none can be found the chip itself sometimes still holds usable material.
The key was tied to a chip that is now in a bin, and the disk has been moved into a machine that has never seen it. Only a recovery key gets past that, which is the entire reason the things are issued in the first place. If the old board has not yet gone in a skip, hold on to it.
Clearing the TPM is offered as a remedy for problems that have nothing to do with encryption, and it destroys sealed key material the moment it runs. Where a recovery key was escrowed, nothing has been lost. Where it was not, that action is often the exact point at which an openable volume closed permanently.
Resetting or reinstalling to get past the recovery screen destroys key material that was still sitting on the machine waiting to be found. It is the single most damaging response available, and it is what a good number of people reach for first. Stop before doing either of them.
Recovery keys are tied to one protector on one volume, so a key from a different machine, or from the second volume on the same machine, is rejected and looks like a wrong key. Rather than picking the likeliest, send every key anyone can lay hands on. Sorting which belongs to which is quick work at this end.
The volume carries its encryption with it, so it does not open in another computer without the key. That is the system behaving exactly as designed rather than a fault, and it surprises people every week. Send the drive, and send whatever key material still exists alongside it.
This changes the order of the work, and typing the key is not the first step. Each attempt burns dependable running time that cannot be bought back, and proves nothing in either direction. Take the copy first, ciphertext and all, and unlock the copy after the key turns up.
Ordinary employer work and a regular arrival. Send the consignment in one go with everything the organisation still holds — recovery key printouts, directory exports, account names, handover notes. How long the batch takes depends far more on that supporting material than on the number of drives in the box.
Removable media sealed with BitLocker behaves like a fixed volume and is worked the same way. Where a password was set and can be remembered or half-remembered, this is straightforward. Where neither a password nor a recovery key exists, the answer is the same one that applies to any properly implemented cipher.
This is the one part of the problem that yields to equipment, because people choose from a far smaller space than the cipher allows. Graphics cards are put to it, guided by whatever the owner can recall about the shape of it. A genuinely strong passphrase does not fall, and that is said at the start.
A mounted volume keeps its key in RAM, and hibernating dumps RAM to the disk. Where the machine went to sleep with everything open, that dump often still holds what is needed. Resetting the computer throws it away.
Directory escrow only helps while somebody can still sign in and read it. Companies that changed provider, lost an administrator or wound up a subscription end up with keys they own and cannot reach. What can be tried from that position is worth a conversation before anything is posted.
Older environments store recovery information against the machine's object in Active Directory, and it commonly outlives the machine itself by years. That is a well-worn route and it is worth walking before anything more elaborate is attempted, because it is quick and it costs nothing.
BitLocker works in the background and a machine switched off mid-encryption leaves a volume that is part sealed and part plain. That is a more awkward object than either state on its own. It is imaged and the two regions are handled separately, with the boundary established from the metadata.
BitLocker writes its metadata to more than one place on the volume, so a damaged primary copy is not automatically a lost volume. Falling back to one of those spare copies is routine, and it succeeds a good deal more often than the message on the screen suggests.
Apple's full-disk encryption is handled here in the same order and on the same terms. The recovery key is often escrowed against an Apple account or was written down when the Mac was set up. Where it can be found the volume opens. Where it cannot, nobody opens it, and that includes this bench.
Several key slots exist on a LUKS volume and any one of them opens it, so an abandoned passphrase or a key file sitting on another computer is worth as much as the phrase nobody can recall. Damaged headers are not automatically fatal either, since a spare copy can sometimes be lifted off the disk.
Both are properly built and neither yields to effort or budget. The passphrase is the only opening, and only where a human invented it and can remember something about its shape. Narrow the field and the hardware has a chance. Leave it wide and it does not, and you are told that on the first call.
Plenty of disks scramble everything they store by default, holding the key on the board rather than telling anybody about it. Nobody notices until the board stops, and then a direct read of the platters or the flash returns flawless nonsense. Revive the board and the files come with it.
Where the encryption is performed by the enclosure rather than by Windows, the bare disk on its own reads as noise, because the key material lives on the board the disk was plugged into. An external drive in its own enclosure travels whole in any case, so send the unit and its cable rather than opening it up.
The array is reassembled first and the encryption is dealt with afterwards, in that order and not the reverse. A key or a passphrase is still needed for the second half. Array work opens at £500 + VAT and the unlocking is part of the same job rather than a second invoice.
A failing chip, or a boot order that shifts depending on what is plugged in, produces a computer that prompts intermittently. Treat that as notice rather than a quirk. Copy everything off while it is still opening, because the day it stops opening is the day this becomes a job rather than an annoyance.
The two get run together constantly and they are opposite problems. Ransomware seals files with a key an attacker holds. BitLocker seals a volume with a key you held. Attack recovery is priced as ordinary media — £300 + VAT a drive, from £500 + VAT an array — and it is not investigation work.
Say so on the booking form, including what it was and how long it ran, because several of them write to the volume they are working on. It rarely rules a recovery out and it always changes the order of the work. The assessment costs nothing whether it is the first attempt or the third.
Not a fault, a priority. A ledger volume nobody can unlock halts a company as thoroughly as a dead array would. Mention it when you ring and the batch is brought forward. The two working days for the free examination hold either way.
Lost, in this trade, nearly always turns out to mean filed somewhere nobody thought to look. Windows rarely seals a volume without depositing a copy of the recovery key first, and the deposits go to a short list of places: the Microsoft account the machine was signed into, an employer's Entra tenant, an older on-premises directory where the key hangs off the computer object, a text file saved during setup, a printed sheet from a handover that went into a filing cabinet. Recent laptops make matters worse by enabling device encryption on their own the first time an account signs in, which is how families end up locked out of protection they never asked for. So the opening move on every one of these jobs is unglamorous: work through each account, tenant and directory that machine has ever touched. It is slow, it is dull, and it resolves more cases than any software in the building. There is one action that converts a solvable problem into a permanent one, and it is the instinctive response to a prompt that will not go away — resetting or reinstalling the machine, either of which can destroy key material still sitting on the disk.
The software on the bench is Passware Kit Forensic, the same package used at the evidential end of this trade, and it is worth being accurate about what it does. It does not attack the mathematics; AES implemented properly is not defeated by money, time or hardware, whatever a website promises this month. It hunts for the key instead. Keys are pulled out of hibernation files and memory captures, coaxed out of a TPM where the configuration allows it, or arrived at by putting a rack of graphics cards against a password that a person chose — and people choose from a vastly smaller pool than the cipher permits, so a weak one falls inside a day. A strong passphrase that has genuinely been forgotten does not fall at all, and you are told that at the point it becomes clear rather than after a fortnight of billed time. The same equipment covers VeraCrypt, FileVault, TrueCrypt and LUKS. Batches of drives from departed employees are ordinary employer work rather than an unusual request.
A sealed volume on a mechanism that is on its way out needs the sequence reversed from what instinct suggests. Typing the key repeatedly costs running time the drive cannot spare and proves nothing about whether the key is right. What happens here is a cold image taken with the volume still locked, on hardware built to read media that stalls and retries, and the key is then applied to that copy as many times as necessary at no cost to the original. A fair share of the encrypted work arriving here has that shape: a disk audibly deteriorating, a volume that will not open, and an owner who has spent two weeks entering the same forty-eight digits into equipment that was never going to respond. The band for an encrypted disk is £400 + VAT, matching the recorder band. Encryption itself is not one of the no fix, no fee exclusions — that list covers electronic and mechanical failure, chip-level work, DVR jobs and forensic instructions — so on a drive that is both locked and physically failing, it is the mechanical half of the job that carries the deposit.
Two quite different jobs happen on this bench and it is worth keeping them apart. The first is finding a key that already exists somewhere in an account, a directory or a file, which is unglamorous work and which closes most of these cases. The second is reading a failing disk without ever asking it to decrypt anything, which is what the imaging hardware is for.
A key hunter rather than a code breaker. It reads keys out of memory captures, sleep files and chips, and it grinds at passwords a human made up. Between those jobs it covers the working day on this bench, and the arithmetic itself is never touched.
A household Microsoft sign-in. An Entra or Azure AD tenant. A computer object in an older domain. Device management records, printed sheets, and the file somebody saved to the desktop on setup day and never opened again. Plodding work, and it settles more of these than every clever tool on the shelf combined.
Where a drive is sealed and dying at once, it goes onto imaging hardware built for awkward media and comes off as an encrypted copy, before a single digit is entered anywhere. Unlocking happens against that copy. Typing into the original spends reads it has no more of.
Where the sole barrier is a password a human chose, that is a far smaller search space than the cipher permits and it is attacked head-on with dictionary, rule-based and mask work, shaped by whatever the owner half-remembers. Against a random recovery key the same hardware achieves precisely nothing.
Key material lifted from a hibernation file, a page file or a captured memory image taken while the volume was still open. It is a well-established route, and it is the reason a locked machine should be left alone rather than reset in the hope that the prompt goes away.
LUKS and dm-crypt, FileVault, TrueCrypt and VeraCrypt, BitLocker To Go, encrypted sticks, the encryption baked into external cases and the sort a NAS applies to its own shares. One method covers all of them. Locate the key, or say straight out that it is gone.
Encrypted drive work is £400 + VAT, the same band as a disk out of a recorder, and the free examination in front of it closes two working days after the drive is booked in. Encryption is not on the no fix, no fee exclusion list. That list has four entries and only four: electronic and mechanical failures, chip-level work, DVR jobs and forensic jobs. Ransomware is not on it either. Where a drive is both sealed and physically failing, the mechanical half is the excluded part and that part takes 50% up front, while the unlocking sits inside the guarantee as normal. Two things are worth saying without ornament. The first is that a properly implemented cipher with the key genuinely gone stays shut for good, and a firm that tells you otherwise should be struck off the list rather than shortlisted. The second is that most of the time nothing has been destroyed at all. The key is sitting in a place nobody has thought to open, which is why the free examination starts by going through every account, directory and drawer the computer has ever touched.
Send the drive, and send everything you still hold that might turn out to be a key. Printed sheets, screenshots on a phone, the file saved to a desktop years ago, directory exports, account names, management records, whatever the leaver wrote down on their last afternoon. Paperwork settles these jobs more often than hardware does, and sorting a pile of keys against a pile of volumes is quick here and slow anywhere else. Do not reset the machine and do not reinstall Windows to clear the prompt, because either can destroy material still sitting on the disk. Take the drive out of a laptop, a PC or a Mac and send the drive rather than the machine; where the encryption is done by an external case rather than by Windows, send the whole unit with its cable, since an external drive in its own enclosure travels whole. Post it tracked and insured to Oxford Data Recovery, John Eccles House, Oxford Science Park, Robert Robinson Avenue, Littlemore, Oxford, OX4 4GP, or bring it in: Coventry to the door is about fifty-five miles of M40, roughly an hour, and drop-offs are taken Monday to Friday, 9:00am to 5:30pm. There is no counter in Coventry and nobody collects. Ring 0800 689 0668 first if the batch is large enough to need arranging.
Almost everything worked on here arrived in the post. A drive that is already in trouble has an easier time boxed, padded and insured than it does being carried round in a bag for an afternoon, and a parcel handed over in Coventry today is normally booked in at Oxford tomorrow morning.
As a rule the storage comes out and the machine stays where it is. That applies to a laptop, a tower, an iMac and to the recorder sitting under a counter. Taking equipment apart is not something this bench does, and a repair shop will free a drive in a few minutes. Two things go the other way: an external drive stays sealed inside its own case, and a NAS travels as a complete unit with its disks still in their bays. A Fusion Mac is a third case — both of its drives come out and travel together, each one labelled. The single situation nobody can work around is memory soldered flat onto a mainboard, which is how Apple Silicon Macs and a good many slim laptops are built: if the storage will not unbolt, there is no parcel to send.
↓ Print the shipping & booking-in form (PDF)
Put Oxford Data Recovery on the label. From Coventry it is roughly fifty-five miles straight down the M40, about an hour if you would rather drive it in than post it. Either way you are told the moment it is logged, and the free diagnostic finishes two working days later.
Unsure what ought to go in the box? Ring 0800 689 0668 before you seal it, or work through the free online diagnostic and let it do the asking.
Looking at it costs nothing, one written figure follows, and the band governing this page is £400 + VAT on a BitLocker volume, and the same on any other encrypted disk.