Home / Case Studies / Trust Practice & Honest Limits
Trust Practice & Honest Limits · case file

It Was Encrypted, and the Passwords Don't Work

A drive taken out of a retina MacBook Pro some years ago, kept in a drawer, and brought out again with a hope attached. The data on it is encrypted and none of the remembered passwords open it. This is the case where the honest answer is a limit rather than a quote, and it is better delivered early than after somebody has paid for postage. The drive itself is readable — it images cleanly and its health can be confirmed in an hour. What sits on top is full-disk encryption, and full-disk encryption without the password or the recovery key is not a puzzle waiting for better equipment. It is mathematics doing precisely the job it was designed for. Where a working credential exists, the volume opens from the image and the data comes back in full. Where none exists, we say so.

SSD / NVMeMacEncryption / BitLocker
// case at a glance
MediaDrive removed from a retina MacBook Pro. Reads and images without fault; the volume on it is encrypted and no known password unlocks it.
Reported situationDrive from a retina MacBook Pro · data encrypted · no password worked · set aside for some years · recovery hoped for.
Fault classDisk encryption without a working credential. The hardware is sound and the image is complete; the volume requires the password or the recovery key to unlock. Forensic-classed work where a credential exists. The limit is the credential, not the drive.
Equipment usedRead through a hardware write-blocker on PC-3000 UDMA · imaged read-only on DeepSpar and the drive's health confirmed, the presence and type of encryption identified from the image · volume unlocked from the image using the owner's password or recovery key where one is available and mounted read-only, contents validated in R-Studio · position stated plainly where no credential exists, since the encryption is not bypassed.
// the decode

The decode

Two separate things are stacked here and people run them together. Underneath is a drive, which either reads or does not. On top is an encrypted volume, which either unlocks or does not. A drive can be in perfect condition and image start to finish while the volume on it stays completely inaccessible, and that is precisely the situation described.

FileVault on a Mac of this generation encrypts the whole volume with a key that is itself protected by your password or by a recovery key issued when it was switched on. There is no maintenance hatch and no manufacturer override. Anybody offering to break it is either selling you a password-guessing exercise dressed up as a service, or is not being straight with you.

So the useful work happens before anything is packed, and it is not technical. Find the credential. The account password from the era the machine was in use, including the one nobody thinks counts because it was only used for a few months. The recovery key, which macOS displays once at setup and which people photograph, print, or store in a password manager and forget. If the machine was managed by an employer or a university, their administrators may hold it. If it was tied to an Apple ID with escrow enabled, that route is worth pursuing directly with Apple.

Where a credential turns up, the job is straightforward and is forensic-classed work, quoted and settled in advance in full. Where none does, there is no job to take on and nothing to charge for. The assessment costs nothing and is finished within 2 working days of arrival, and the answer it produces is sometimes no. Saying so is cheaper for everyone than pretending otherwise for a fortnight.

// on the bench

On the bench

The drive was read on PC-3000 UDMA through a hardware write-blocker and imaged read-only on DeepSpar, which established two useful things: the hardware is healthy, and the encryption is present and intact across the volume. All further work happened on the image, never on the original. Where the owner produced a working password or recovery key, the volume was unlocked from the image, mounted read-only, and the contents parsed and validated in R-Studio before being written to fresh media. Where no credential existed, the honest position was stated and the drive returned, because there is no version of this work that gets past the encryption without one.

// the outcome

The outcome

The drive imaged read-only, its health confirmed, and the data unlocked and recovered wherever a working credential was available. Where none was, nothing was charged, because nothing could be undertaken. Encryption work of this kind is forensic-classed and is quoted and paid in advance in full when it proceeds — it is slow, manual and does not run under no fix, no fee, and that is stated at the outset rather than discovered later. The genuinely useful outcome in cases like this is often the assessment itself: knowing the drive is healthy tells the owner that the search for the recovery key is worth continuing, because the moment it turns up, the data is there.

An encrypted drive whose passwords do not work

Hunt for the credential before you hunt for a laboratory. Old account passwords, the recovery key photographed or printed at setup, a password manager entry from that era, an employer's or a university's IT department if the machine was ever managed by one, or an Apple ID with key escrow enabled. That search is where the recovery actually lives. Be wary of anybody who promises to break disk encryption for a fee, because that is a guessing service and it usually guesses wrong at your expense. The one thing worth having done is an assessment confirming the drive itself is healthy and the volume intact. It costs nothing here, and it tells you whether to keep looking for the key or stop.

Got one of these on your desk right now? Everything here follows the same route: an assessment you are not charged for, completed inside 2 working days of the box reaching the bench, after which you get one written figure that never climbs afterwards. Logical faults are handled on no fix, no fee. Should the casing need opening, or the electronics rebuilding after a drop, a surge, a soaking or a fire, half of that figure falls due first and the rest only once your data is in hand. Ransomware, camera and DVR recorders, BitLocker volumes and anything else classed as forensic get settled in advance, in full. Where the files live inside a machine — laptop, desktop, Mac, server — pull the drive or the SSD and post that by itself. Computers are not dismantled here, and flash fixed permanently onto a logic board (the newer Apple laptops among them) is the one category refused outright. Unscrews or unplugs and we will take it. Send it tracked and insured to Edinburgh Data Recovery, 4 Redheughs Rigg, Westpoint, South Gyle, Edinburgh EH12 9DQ, arrange and pay for a courier of your own, or bring it to the counter there. No device is ever fetched from a customer. Packing notes and the shipping form sit here.
Start a free diagnostic

Each file below comes from a genuine enquiry taken from households and firms across Aberdeen, Aberdeenshire and the wider north-east, anonymised so nobody can be identified. Each one sets out how the fault was reasoned through, what was done about it, and which equipment did the work.

// related case files

Nearby files worth a look

Browse all case studies →

Recognise your own drive in this one?

Assessment is free and takes 2 working days at most once it lands, the figure is fixed in writing, and logical work carries no fix no fee. Begin online, or lift the phone.