A blue screen asking for forty-eight digits nobody wrote down, with a household or a company stuck on the wrong side of it. Three jobs come out of that. Trace the key that was escrowed somewhere. Open leavers' machines in batches for an employer. Or handle a drive that is dying and locked at the same time. Cracked BitLocker is not a thing that exists, and any supplier hinting otherwise is selling you a story.
Every bitlocker job is diagnosed free. The fixed figure reaches you in writing first, before any tools come out.
No fix, no fee all jobs except electronic and mechanical failures, chip level work, DVR and Forensic jobs. Full pricing is on the data recovery cost page.
First job on any bitlocker is matching the symptom to the fault. Twenty-odd years in, these twenty-five cover nearly every one that reaches this bench.
Something changed in the hardware or the firmware, the TPM's measurements no longer match, and your data now sits behind one long number. That number can usually be found, which is this page in a sentence.
Nearly all of these end up at escrow: some Microsoft account nobody remembers signing into, an entry in a directory, an exported file, a printout that has spent five years under a stapler. Intune and Active Directory hold keys people forgot existed. The trawl is methodical, and more often than not it works.
GPU-speed attack takes down weak and middling passwords. A genuinely strong password that is genuinely lost earns you a straight verdict, not an invoice ticking over by the hour.
Motherboard swap, TPM clear, BIOS flash, Secure Boot toggle, UEFI update. Every one of those trips the protection precisely as intended by its designers. Your recovery key untrips it.
Orphan a data partition through a reinstall and it opens again the moment its key surfaces. Below that reinstall, nothing of consequence was moved or written over.
This is the compound case: hardware dying beneath live encryption. We capture it whole, still locked, then decrypt from the stable copy instead of the failing original.
There are three doors into encrypted removable media, and they are the three that open a system drive: your key, your password, or forensic key recovery. In that order of preference.
Drives left behind by leavers get decrypted in bulk against the keys your organisation escrowed, with every key matched to its drive on identifier rather than on guesswork.
Separated from its TPM, the volume locks. Designed behaviour, not misfortune. Undoing it takes a few minutes when you hold the key, and considerably longer when you do not.
Should BitLocker's own structures corrupt on a drive that is otherwise sound, we locate the backup copies and rebuild the headers, and only then attempt decryption.
Install Linux, or rework the bootloader, and the measurements change and up comes the prompt. Predictable, reversible, and it happens somewhere every week of the year.
Device encryption switches itself on quietly at first sign-in on modern laptops. Owners generally learn about it at a lockout screen, which is poor timing for that discovery.
An account collects several keys across the years, and the wrong one gets tried first every time. Match on the key identifier shown on screen and guesswork disappears entirely.
A machine that boots from a key file held on a USB stick locks solid the moment that stick goes missing. Escrow and the TPM remain open regardless, so a lost stick settles nothing.
Leave a TPM-and-PIN setup unused for a few months and the PIN fades in a way that genuinely surprises people. Your route back in is that recovery key, and one can usually be turned up somewhere.
Business dissolved, directory deleted, drives sitting in a box in somebody's garage. We work whichever escrow avenues survive, plus the TPM where the machine still has one.
That encryption belongs to the previous owner's account, and only their lawful cooperation opens it. We tell you that before money changes hands, not afterwards.
Interrupt a decryption run with a power failure and half a cipher is left on the disk. Salvage happens from an image, each half handled correctly according to where the boundary fell.
Set an external drive to unlock itself automatically and it stops obliging once Windows has been reinstalled, because the stored key departed with the old copy. Escrow usually holds a twin.
A hardware drive doing BitLocker's job in its own silicon fails on its own terms, and the older trust model behind it had documented holes in it. Handled at drive level, and candidly.
One solitary copy of a recovery key, saved as a text file, parked on the exact volume it unlocks. We appreciate the irony. Escrow appreciates it a good deal less.
In used-space-only mode the files get encrypted and free space is left alone, older deleted copies of those same files included. Carving reads whatever the cipher never covered.
Recovery keys rotate automatically across a managed estate, so a laptop that missed checking in around a rotation now sits behind a key the directory replaced weeks ago. Both current and previous keys need retrieving, and it is the older one that works.
Image an encrypted drive with consumer cloning software and the copy frequently comes out the wrong size, misaligned, or missing its volume header. The encryption is fine. The container is not. Rebuilding from the original is straightforward. Rebuilding from the clone is not.
A run of wrong PINs makes a security chip defend itself by closing the door, for a few hours in some cases and until the machine has stood powered down all night in others. Patience really is the fix here. Hammering away at it lengthens the lockout rather than shortening it.
Start with the cheerful part. A key described as lost has usually just been filed where nobody has looked. Windows almost never encrypts a volume without escrowing the key first, and it goes to a short list of predictable places. The Microsoft account the machine was signed into. An Azure AD tenant at work. An on-premises directory. A text file someone exported and never mentioned again. A printed sheet that got put in a drawer during a rushed handover. Then there is the modern trap. Recent laptops turn device encryption on quietly during first sign-in, and that is how ordinary households get shut out of drives they never knew were protected. So the first action on any lockout is a methodical trawl of every account and directory the machine has ever touched. Tedious. And it resolves more cases here than the expensive tooling does.
Decryption on this bench runs on Passware Kit Forensic, which is the standard product across the forensic trade. Worth stating exactly what it does. It does not break AES. Nothing breaks correctly implemented AES, whatever some website is asserting this week. What Passware does is recover keys. From hibernation files. From memory captures. Straight out of the TPM. Or by aiming GPUs at a human-chosen password, in the cases where a password is the only guard on the door. BitLocker and BitLocker To Go are the everyday volume. VeraCrypt, FileVault, TrueCrypt and LUKS get the same treatment on the same bench. Employers send drives from staff who have moved on and those go through in batches.
Order of operations matters enormously when a drive is encrypted and dying at the same time. Unlock attempts are the wrong opening move: each one consumes some of the limited healthy running time left in the drive, and proves precisely nothing. What happens instead is that the disk is imaged cold, still locked, on forensic imaging hardware. Only then, against a stable duplicate, does decryption get attempted with whatever key has been traced. Be clear on one thing before you commit. BitLocker falls in the forensic class of work, so the assessment happens first at no charge, a fixed quote follows on from it, and that figure is settled before work begins rather than afterwards.
BitLocker work is key-finding and disciplined imaging. It is never code-breaking, and the equipment reflects precisely that:
The key-recovery suite this trade genuinely rates. It lifts keys out of memory captures, out of hibernation files, out of security chips, or reaches one through an accelerated password attack. Keys are what it finds. Nobody breaks the AES underneath, us included.
Given a machine that will still start, the live key can occasionally be lifted out of RAM directly, or from the hibernation file. Quickest lawful entry there is, when it is available.
Graphics silicon by the rack, grinding out dictionary and brute-force runs at several thousand attempts a second, unattended, round the clock.
An encrypted drive that is deteriorating gets captured in full, still locked, and write-blocked throughout. Decryption then happens against the stable duplicate and never against the original.
The methodical trawl: Microsoft accounts, workplace directories, Intune and Active Directory records, exported files, paper in drawers. Most lockouts finish there.
BitLocker first, along with BitLocker To Go, then FileVault, LUKS, VeraCrypt, TrueCrypt, plus several hundred kinds of password-protected file.
Without its key, a sound BitLocker volume stays shut, whatever some confident advertisement tells you. Honest recovery here means finding that key. Escrow trawls. Work against the TPM. GPU-speed attack on the password. And a straight answer wherever that key has genuinely gone for good. Classed as forensic, the work is paid for at the point of quoting rather than on results — while arriving at that quote costs you nothing. Ring 0800 689 0668 and an engineer picks up, not a script.
Every scrap of key material should travel with the drive. That means the 48-digit key if it was ever written down, plus whichever Microsoft or workplace account may hold escrow, any exported key files, PINs, plus your best guesses at the password and the variations you might have used. Each item shortens the clock. As for the drive, an anti-static bag suits it, or kitchen foil at a push. Post it tracked and insured, book a courier of your own, or bring it to reception at our Edinburgh location, Edinburgh Data Recovery, 4 Redheughs Rigg, Westpoint, South Gyle, Edinburgh EH12 9DQ, open Monday to Friday, 9am to 5:30pm. No collection service runs from here.
Nearly everything on this bench came by tracked, insured post. It is the safest way to shift a failing drive, and a parcel handed in at a North-East post office is usually here the next working day.
Still bolted into a laptop, desktop, MacBook, iMac, server or CCTV / DVR box? Get the hard drive or SSD out first. The bare drive travels on its own. Stripping machines down is not a job this lab takes on. Flash soldered to a motherboard, as on Apple Silicon Macs and a couple of very thin laptops, is our one flat no: if it will not unbolt, it cannot be worked on.
↓ Print the shipping & booking-in form (PDF)
Address it for the attention of Edinburgh Data Recovery. From Aberdeen that is roughly 130 miles and two and a half hours down the A90, or next working day by tracked post if you would rather not make the run. You get a call the moment it is booked onto the bench.
Not sure what belongs in the box? Ring 0800 689 0668 before you tape it shut, or work through the free online diagnostic.
Free diagnosis, one number written down, no fix no fee on the bulk of jobs. Start online or phone it in.