Home / Devices / BitLocker

BitLocker Recovery & Decryption Coventry

A recovery screen asking for forty-eight digits, and a household or an office where nobody remembers being asked to encrypt anything. That is the ordinary beginning. Three sorts of work follow from it: tracing a key that was escrowed somewhere and forgotten, opening a batch of machines inherited from staff who have left, and lifting data off a sealed disk that is dying at the same time. Every route runs through the cipher rather than round it, because there is no way round it.

Looking at a BitLocker volume costs nothing. What comes out of that examination is one written figure, agreed between us before anybody picks up a screwdriver: £400 + VAT on a BitLocker volume, and the same on any other encrypted disk.

Logical work is no fix, no fee. Four things sit outside that: electronic and mechanical failures, chip-level work, DVR jobs and forensic work, and anything physical is half up front. All five bands are laid out on the data recovery cost page, while data recovery services follows a postal job from the parcel to the answer.

// thirty faults, roughly by how often they turn up

Thirty ways it fails, and what lies behind each one

Tracing a symptom back to whatever caused it is where the job genuinely starts, and these thirty cover very nearly every box opened on the Oxford bench. A fault that is not on the list is not an unfamiliar one: describe it over the telephone and you will get a straight reading of the odds before you have spent a penny on postage.

A blue screen asking for forty-eight digits

Something underneath changed — firmware, a mainboard, the boot order, a chip somebody reset — and Windows now reads the computer as a different computer from the one it sealed the volume to. It will not move until the digits are typed in. Nothing behind that screen is damaged, and the key nearly always still exists somewhere.

No key anywhere, and the answer that goes with it

This belongs near the top rather than in the small print. Without the recovery key or the password, a correctly sealed BitLocker volume does not open — not here, not anywhere, not for any fee. Nothing on this bench attacks the mathematics, because the mathematics holds. Everything on it is aimed at finding a key that already exists.

Forty-eight digits sitting in a Microsoft account

The commonest ending to these jobs, and an undramatic one. Windows very seldom seals a volume without escrowing a copy first, so the exercise is working out where it went. A household account, signed into on a phone, will frequently produce the key in the time it takes to log in and look.

A work laptop whose key belongs to the employer

Company machines escrow into Entra, Azure AD or an older on-premises directory, and a great many lockouts finish with an administrator finding the entry in a couple of minutes. Where the tenant itself has been lost, or the only administrator account left with a departing employee, the position is harder and is assessed honestly.

Encryption nobody remembers switching on

Recent Windows laptops turn device encryption on by themselves the first time somebody signs in with a Microsoft account, and the household discovers this on the day a firmware update triggers the recovery prompt. Nothing was chosen and nothing is broken. The key is usually filed against that same account.

A firmware update that changed what the chip measures

The TPM releases the key only when the machine measures the same as it did when the volume was sealed. Update the firmware and the measurements move, so the chip holds on to it. The recovery key opens it, and where none can be found the chip itself sometimes still holds usable material.

A mainboard swap and a sealed volume

The key was tied to a chip that is now in a bin, and the disk has been moved into a machine that has never seen it. Only a recovery key gets past that, which is the entire reason the things are issued in the first place. If the old board has not yet gone in a skip, hold on to it.

A chip cleared while chasing an unrelated fault

Clearing the TPM is offered as a remedy for problems that have nothing to do with encryption, and it destroys sealed key material the moment it runs. Where a recovery key was escrowed, nothing has been lost. Where it was not, that action is often the exact point at which an openable volume closed permanently.

Windows reset in an effort to clear the prompt

Resetting or reinstalling to get past the recovery screen destroys key material that was still sitting on the machine waiting to be found. It is the single most damaging response available, and it is what a good number of people reach for first. Stop before doing either of them.

A key that is refused because it belongs elsewhere

Recovery keys are tied to one protector on one volume, so a key from a different machine, or from the second volume on the same machine, is rejected and looks like a wrong key. Rather than picking the likeliest, send every key anyone can lay hands on. Sorting which belongs to which is quick work at this end.

A disk moved into a caddy and still locked

The volume carries its encryption with it, so it does not open in another computer without the key. That is the system behaving exactly as designed rather than a fault, and it surprises people every week. Send the drive, and send whatever key material still exists alongside it.

Locked and failing at the same time

This changes the order of the work, and typing the key is not the first step. Each attempt burns dependable running time that cannot be bought back, and proves nothing in either direction. Take the copy first, ciphertext and all, and unlock the copy after the key turns up.

A crate of drives left behind by people who have gone

Ordinary employer work and a regular arrival. Send the consignment in one go with everything the organisation still holds — recovery key printouts, directory exports, account names, handover notes. How long the batch takes depends far more on that supporting material than on the number of drives in the box.

A BitLocker To Go stick with no password

Removable media sealed with BitLocker behaves like a fixed volume and is worked the same way. Where a password was set and can be remembered or half-remembered, this is straightforward. Where neither a password nor a recovery key exists, the answer is the same one that applies to any properly implemented cipher.

A password somebody invented themselves

This is the one part of the problem that yields to equipment, because people choose from a far smaller space than the cipher allows. Graphics cards are put to it, guided by whatever the owner can recall about the shape of it. A genuinely strong passphrase does not fall, and that is said at the start.

A hibernation file from a session when the volume was open

A mounted volume keeps its key in RAM, and hibernating dumps RAM to the disk. Where the machine went to sleep with everything open, that dump often still holds what is needed. Resetting the computer throws it away.

A tenant nobody can get into any more

Directory escrow only helps while somebody can still sign in and read it. Companies that changed provider, lost an administrator or wound up a subscription end up with keys they own and cannot reach. What can be tried from that position is worth a conversation before anything is posted.

A computer object in a domain that still exists

Older environments store recovery information against the machine's object in Active Directory, and it commonly outlives the machine itself by years. That is a well-worn route and it is worth walking before anything more elaborate is attempted, because it is quick and it costs nothing.

Encryption interrupted partway through

BitLocker works in the background and a machine switched off mid-encryption leaves a volume that is part sealed and part plain. That is a more awkward object than either state on its own. It is imaged and the two regions are handled separately, with the boundary established from the metadata.

A damaged header, and the copies further in

BitLocker writes its metadata to more than one place on the volume, so a damaged primary copy is not automatically a lost volume. Falling back to one of those spare copies is routine, and it succeeds a good deal more often than the message on the screen suggests.

FileVault and a forgotten Apple password

Apple's full-disk encryption is handled here in the same order and on the same terms. The recovery key is often escrowed against an Apple account or was written down when the Mac was set up. Where it can be found the volume opens. Where it cannot, nobody opens it, and that includes this bench.

LUKS with a passphrase nobody wrote down

Several key slots exist on a LUKS volume and any one of them opens it, so an abandoned passphrase or a key file sitting on another computer is worth as much as the phrase nobody can recall. Damaged headers are not automatically fatal either, since a spare copy can sometimes be lifted off the disk.

VeraCrypt and TrueCrypt containers

Both are properly built and neither yields to effort or budget. The passphrase is the only opening, and only where a human invented it and can remember something about its shape. Narrow the field and the hardware has a chance. Leave it wide and it does not, and you are told that on the first call.

A self-encrypting drive whose controller stopped

Plenty of disks scramble everything they store by default, holding the key on the board rather than telling anybody about it. Nobody notices until the board stops, and then a direct read of the platters or the flash returns flawless nonsense. Revive the board and the files come with it.

An external drive whose case does the encrypting

Where the encryption is performed by the enclosure rather than by Windows, the bare disk on its own reads as noise, because the key material lives on the board the disk was plugged into. An external drive in its own enclosure travels whole in any case, so send the unit and its cable rather than opening it up.

An encrypted volume on top of an array that failed

The array is reassembled first and the encryption is dealt with afterwards, in that order and not the reverse. A key or a passphrase is still needed for the second half. Array work opens at £500 + VAT and the unlocking is part of the same job rather than a second invoice.

A machine that asks some days and not others

A failing chip, or a boot order that shifts depending on what is plugged in, produces a computer that prompts intermittently. Treat that as notice rather than a quirk. Copy everything off while it is still opening, because the day it stops opening is the day this becomes a job rather than an annoyance.

Ransomware mistaken for encryption

The two get run together constantly and they are opposite problems. Ransomware seals files with a key an attacker holds. BitLocker seals a volume with a key you held. Attack recovery is priced as ordinary media — £300 + VAT a drive, from £500 + VAT an array — and it is not investigation work.

A decryption tool that has already been run

Say so on the booking form, including what it was and how long it ran, because several of them write to the volume they are working on. It rarely rules a recovery out and it always changes the order of the work. The assessment costs nothing whether it is the first attempt or the third.

A firm locked out of its own records

Not a fault, a priority. A ledger volume nobody can unlock halts a company as thoroughly as a dead array would. Mention it when you ring and the batch is brought forward. The two working days for the free examination hold either way.

Start by looking for the key, because it is usually somewhere

Lost, in this trade, nearly always turns out to mean filed somewhere nobody thought to look. Windows rarely seals a volume without depositing a copy of the recovery key first, and the deposits go to a short list of places: the Microsoft account the machine was signed into, an employer's Entra tenant, an older on-premises directory where the key hangs off the computer object, a text file saved during setup, a printed sheet from a handover that went into a filing cabinet. Recent laptops make matters worse by enabling device encryption on their own the first time an account signs in, which is how families end up locked out of protection they never asked for. So the opening move on every one of these jobs is unglamorous: work through each account, tenant and directory that machine has ever touched. It is slow, it is dull, and it resolves more cases than any software in the building. There is one action that converts a solvable problem into a permanent one, and it is the instinctive response to a prompt that will not go away — resetting or reinstalling the machine, either of which can destroy key material still sitting on the disk.

Passware finds keys. Nothing breaks ciphers

The software on the bench is Passware Kit Forensic, the same package used at the evidential end of this trade, and it is worth being accurate about what it does. It does not attack the mathematics; AES implemented properly is not defeated by money, time or hardware, whatever a website promises this month. It hunts for the key instead. Keys are pulled out of hibernation files and memory captures, coaxed out of a TPM where the configuration allows it, or arrived at by putting a rack of graphics cards against a password that a person chose — and people choose from a vastly smaller pool than the cipher permits, so a weak one falls inside a day. A strong passphrase that has genuinely been forgotten does not fall at all, and you are told that at the point it becomes clear rather than after a fortnight of billed time. The same equipment covers VeraCrypt, FileVault, TrueCrypt and LUKS. Batches of drives from departed employees are ordinary employer work rather than an unusual request.

When the disk is failing as well, the order matters

A sealed volume on a mechanism that is on its way out needs the sequence reversed from what instinct suggests. Typing the key repeatedly costs running time the drive cannot spare and proves nothing about whether the key is right. What happens here is a cold image taken with the volume still locked, on hardware built to read media that stalls and retries, and the key is then applied to that copy as many times as necessary at no cost to the original. A fair share of the encrypted work arriving here has that shape: a disk audibly deteriorating, a volume that will not open, and an owner who has spent two weeks entering the same forty-eight digits into equipment that was never going to respond. The band for an encrypted disk is £400 + VAT, matching the recorder band. Encryption itself is not one of the no fix, no fee exclusions — that list covers electronic and mechanical failure, chip-level work, DVR jobs and forensic instructions — so on a drive that is both locked and physically failing, it is the mechanical half of the job that carries the deposit.

// the tools it takes

What stands on the bench, and why any of it matters

Two quite different jobs happen on this bench and it is worth keeping them apart. The first is finding a key that already exists somewhere in an account, a directory or a file, which is unglamorous work and which closes most of these cases. The second is reading a failing disk without ever asking it to decrypt anything, which is what the imaging hardware is for.

Passware Kit Forensic, described accurately

A key hunter rather than a code breaker. It reads keys out of memory captures, sleep files and chips, and it grinds at passwords a human made up. Between those jobs it covers the working day on this bench, and the arithmetic itself is never touched.

The escrow sweep that closes most of these

A household Microsoft sign-in. An Entra or Azure AD tenant. A computer object in an older domain. Device management records, printed sheets, and the file somebody saved to the desktop on setup day and never opened again. Plodding work, and it settles more of these than every clever tool on the shelf combined.

Cold imaging with the volume left sealed

Where a drive is sealed and dying at once, it goes onto imaging hardware built for awkward media and comes off as an encrypted copy, before a single digit is entered anywhere. Unlocking happens against that copy. Typing into the original spends reads it has no more of.

Graphics cards, and the only thing they are useful for here

Where the sole barrier is a password a human chose, that is a far smaller search space than the cipher permits and it is attacked head-on with dictionary, rule-based and mask work, shaped by whatever the owner half-remembers. Against a random recovery key the same hardware achieves precisely nothing.

Memory and hibernation analysis

Key material lifted from a hibernation file, a page file or a captured memory image taken while the volume was still open. It is a well-established route, and it is the reason a locked machine should be left alone rather than reset in the hope that the prompt goes away.

The other systems, worked the same way

LUKS and dm-crypt, FileVault, TrueCrypt and VeraCrypt, BitLocker To Go, encrypted sticks, the encryption baked into external cases and the sort a NAS applies to its own shares. One method covers all of them. Locate the key, or say straight out that it is gone.

// badges that turn up in the post

Encryption systems worked with

BitLocker on a fixed volumeDevice encryption that switched itself onBitLocker To Go on a stick or a cardFileVault on a MacLUKS or dm-crypt on LinuxA VeraCrypt or TrueCrypt containerAn OPAL or self-encrypting driveAn external case doing the encryptingA pen drive with encryption built inA share on a NAS, encrypted by the box

What these jobs turn out to be

Encrypted drive work is £400 + VAT, the same band as a disk out of a recorder, and the free examination in front of it closes two working days after the drive is booked in. Encryption is not on the no fix, no fee exclusion list. That list has four entries and only four: electronic and mechanical failures, chip-level work, DVR jobs and forensic jobs. Ransomware is not on it either. Where a drive is both sealed and physically failing, the mechanical half is the excluded part and that part takes 50% up front, while the unlocking sits inside the guarantee as normal. Two things are worth saying without ornament. The first is that a properly implemented cipher with the key genuinely gone stays shut for good, and a firm that tells you otherwise should be struck off the list rather than shortlisted. The second is that most of the time nothing has been destroyed at all. The key is sitting in a place nobody has thought to open, which is why the free examination starts by going through every account, directory and drawer the computer has ever touched.

// getting it ready for the post

Before the box is taped shut — take the drive out if it comes out

Send the drive, and send everything you still hold that might turn out to be a key. Printed sheets, screenshots on a phone, the file saved to a desktop years ago, directory exports, account names, management records, whatever the leaver wrote down on their last afternoon. Paperwork settles these jobs more often than hardware does, and sorting a pile of keys against a pile of volumes is quick here and slow anywhere else. Do not reset the machine and do not reinstall Windows to clear the prompt, because either can destroy material still sitting on the disk. Take the drive out of a laptop, a PC or a Mac and send the drive rather than the machine; where the encryption is done by an external case rather than by Windows, send the whole unit with its cable, since an external drive in its own enclosure travels whole. Post it tracked and insured to Oxford Data Recovery, John Eccles House, Oxford Science Park, Robert Robinson Avenue, Littlemore, Oxford, OX4 4GP, or bring it in: Coventry to the door is about fifty-five miles of M40, roughly an hour, and drop-offs are taken Monday to Friday, 9:00am to 5:30pm. There is no counter in Coventry and nobody collects. Ring 0800 689 0668 first if the batch is large enough to need arranging.

// getting your media to Oxford

Posting a device in — what goes in the box

Almost everything worked on here arrived in the post. A drive that is already in trouble has an easier time boxed, padded and insured than it does being carried round in a bag for an afternoon, and a parcel handed over in Coventry today is normally booked in at Oxford tomorrow morning.

As a rule the storage comes out and the machine stays where it is. That applies to a laptop, a tower, an iMac and to the recorder sitting under a counter. Taking equipment apart is not something this bench does, and a repair shop will free a drive in a few minutes. Two things go the other way: an external drive stays sealed inside its own case, and a NAS travels as a complete unit with its disks still in their bays. A Fusion Mac is a third case — both of its drives come out and travel together, each one labelled. The single situation nobody can work around is memory soldered flat onto a mainboard, which is how Apple Silicon Macs and a good many slim laptops are built: if the storage will not unbolt, there is no parcel to send.

  • Use a box or padded mailer with some rigidity to it, and pack around the drive until nothing shifts when the parcel is tilted. Mains adaptors, docks and leads are not wanted at this end.
  • Sending a RAID or a server? Only the member disks travel — not the chassis, not the controller — and each one wants its bay number written on it. Take a photograph of the front of the unit before anything is pulled; it costs nothing and now and again it saves a day.
  • Print the shipping and booking-in form (PDF), add a name, a number you will answer and a sentence on how the trouble began, and drop it in beside the media.
  • Most people use Special Delivery, which is tracked and covered; a courier of your own does the same job. You can also bring it: the Oxford reception takes devices over the counter, Mon–Fri 9:00am–5:30pm. Neither a Coventry counter nor a collection round exists.
// write this on the label

Oxford Data Recovery

John Eccles House
Oxford Science Park
Robert Robinson Avenue
Littlemore, Oxford, OX4 4GP

↓ Print the shipping & booking-in form (PDF)

Put Oxford Data Recovery on the label. From Coventry it is roughly fifty-five miles straight down the M40, about an hour if you would rather drive it in than post it. Either way you are told the moment it is logged, and the free diagnostic finishes two working days later.

Unsure what ought to go in the box? Ring 0800 689 0668 before you seal it, or work through the free online diagnostic and let it do the asking.

// BitLocker recovery questions

Common questions

Rarely. In most cases a copy was escrowed at some point — under a Microsoft sign-in, in a company directory, or in a file somebody saved and forgot about — and finding it is a matter of methodical searching. Where no copy was ever made, a TPM or a hibernation file will often give one up, and a password chosen by a human being frequently falls to a rack of graphics cards. What does close the door for good is reinstalling the machine to clear the prompt.
It cannot, and a supplier who says otherwise has told you something useful about themselves. Properly implemented AES with the key genuinely gone stays shut permanently; that is arithmetic, not a question of budget. The professional job is locating the key. Weak passwords go quickly, strong ones do not go at all, and you hear which you have on the day rather than at the end of an invoice.
Send the whole box in one consignment, together with every scrap of documentation the organisation still holds: escrowed keys, account names, directory exports, handover notes. The batch is then worked through in a single pass. Cost and timescale depend far more on how complete that paperwork is than on how many drives there are.
Stop entering it and switch the machine off. The order that works is image first, decrypt second: a copy is taken while the volume is still locked and the key applied to the copy once it surfaces, rather than making a struggling mechanism work through repeated attempts. The £400 + VAT figure is agreed in writing before anything begins, and getting to that point costs nothing.
// the rest of the week's work

What else reaches this bench

// where to read next

Pages that go further than this one

The bench is ready whenever you are.

Looking at it costs nothing, one written figure follows, and the band governing this page is £400 + VAT on a BitLocker volume, and the same on any other encrypted disk.