A blue screen wanting forty-eight digits nobody ever wrote down, with a business or a household on the wrong side of it. Around Norfolk we track down escrowed keys, open leavers' machines in batches, and bring failing encrypted disks back through the cipher rather than around the outside of it — because BitLocker that has genuinely been cracked is not a thing that exists anywhere.
Every bitlocker job is diagnosed free. The quote follows in writing, fixed, before a screwdriver is picked up.
No fix, no fee all jobs except electronic and mechanical failures, chip level work, DVR and Forensic jobs. Full pricing is on the data recovery cost page.
The first job on any bitlocker is matching the symptom to the fault — and after twenty-odd years, these thirty account for very nearly everything that comes through the door.
Some change to the hardware or the firmware unsettled the TPM's measurements, and the data now sits one long number away. That number is usually findable, which is the whole of this page in a sentence.
These mostly finish at escrow: a Microsoft account nobody remembered signing in with, a directory entry somewhere, an exported file, a printout underneath a stapler. The trawl is methodical and it works more often than not.
Weak and middling passwords give way to GPU-speed attack. Truly strong ones that are genuinely lost earn a straight verdict instead of a hopeful invoice.
Motherboard swaps, TPM clears, a BIOS flash, a Secure Boot toggle: each trips the protection precisely as it was designed to be tripped. The recovery key untrips it.
A data partition orphaned by a reinstall opens the moment its key turns up. Underneath, the reinstall moved nothing of consequence.
The compound case: hardware dying underneath encryption. Captured whole while still locked, then decrypted from the stable copy rather than from the failing original.
Encrypted removable media answers to the same three doors as a system drive — the key, the password, or forensic key recovery — and in the same order.
Drives from former staff decrypted in bulk against the organisation's escrowed keys, each one matched to its own drive by identifier rather than by guesswork.
Away from its TPM the volume locks, which is behaviour rather than misfortune. It takes a few minutes to undo, with the key in hand.
Where BitLocker's own structures corrupt on an otherwise sound drive, the backup copies are located and the headers rebuilt before any decryption is attempted.
Security chip cleared, 48 digits demanded, nothing else changed. Recovered through escrow, or coaxed out of what the chip still holds.
Installing Linux or reworking the bootloader alters the measurements and up comes the prompt. It is predictable, reversible, and weekly.
Modern laptops turn device encryption on quietly at first sign-in. Most owners find this out at the lockout screen, which is poor timing for a discovery.
Intune and Active Directory hold keys nobody knew existed. Tracing them and pairing them to drives by identifier is tedious, and it is also usually successful.
Accounts accumulate several keys over the years, and the wrong one always gets tried first. Matching on the key identifier shown on screen removes the guesswork entirely.
Machines that boot from a key file on a USB stick lock solid without it. The escrow and TPM routes stay open regardless, so it is not the end of the road.
A TPM-and-PIN setup left unused for months fades from memory in a way that surprises people. The way back in is via the recovery key, and one can usually be found.
Dissolved business, deleted directory, drives in a box in somebody's garage. Whatever escrow avenues remain, and the TPM, get worked instead.
Encrypted to the previous owner's account and recoverable only with that owner's lawful cooperation. We say so before any money changes hands rather than after.
A decryption run interrupted by a power failure leaves half a cipher on the disk. It gets salvaged from an image, with each half treated correctly according to where the boundary fell.
External drives set to unlock automatically stop doing so after a reinstall, because the stored key departed along with the old Windows. Escrow usually still holds its twin.
Hardware drives doing BitLocker's job inside their own silicon fail on terms of their own, and the older trust model for that had documented holes. Handled at drive level, and candidly.
The only copy of the recovery key, saved as a text file sitting on the very volume that it opens. The irony is appreciated here; escrow appreciates it rather less.
Used-space-only mode encrypts the files and leaves free space unencrypted, including older deleted copies of those same files. Carving reads what the cipher never covered.
A game required TPM and Secure Boot changes, and the next start-up demanded 48 digits. It is the most travelled road to this page among younger callers.
Managed estates rotate recovery keys automatically, and a laptop that has not checked in since the rotation is now protected by a key the directory has replaced. Both the current and the previous key need retrieving, and the older one is the one that works.
Imaging an encrypted drive with consumer cloning software frequently produces a copy that is the wrong size, misaligned, or missing the volume header entirely. The encryption is fine and the container is not. Rebuilding it from the original is straightforward; rebuilding it from the clone is not.
A data partition encrypted separately from the system drive has a separate key, and only one of the two usually gets written down. The identifier on screen tells us which one is being asked for, and the search proceeds from there.
Security chips defend against guessing by shutting the door after a run of wrong PINs, sometimes for hours and sometimes until the machine is left powered down overnight. Patience genuinely is the fix, and hammering at it extends the lockout rather than shortening it.
BitLocker can be unlocked by a smart card or a certificate instead of a password, which is tidy until the card is lost or the certificate expires with a former IT provider. The remaining routes are escrow and the TPM, and we will tell you at the diagnostic stage which of them is still open.
Keys described as lost were mostly never lost, only filed where nobody has thought to look. Windows very seldom encrypts anything without escrowing the key somewhere first — a Microsoft account, a workplace Azure AD tenant, an on-premises directory, a text file exported and forgotten, a printout that went in a drawer during a rushed handover. Newer laptops turn device encryption on quietly during the first sign-in, which is how households end up shut out of drives they had no idea were encrypted at all. So the first move against any lockout is a patient trawl through every account and directory that machine has ever touched. Dull work, and it settles more cases than any of the clever tooling does.
Decryption here runs on Passware Kit Forensic, which is what the forensic trade uses, and it is worth being exact about what that means in practice. Correctly implemented AES is not defeated by anybody, whatever a confident-sounding website claims this week. Passware does not break ciphers; it recovers keys, out of hibernation files and memory captures, from the TPM itself, or by throwing GPUs at a human-chosen password where that is the only thing standing guard. BitLocker and BitLocker To Go make up the everyday work, with VeraCrypt, FileVault, TrueCrypt and LUKS sharing the same bench, and batches of drives from departed staff decrypted for employers as a matter of routine.
A disk failing while it is still encrypted needs its operations in a particular order, and unlock attempts are firmly the wrong first move, since each one spends part of what remains of the drive's healthy running time and proves nothing at all. The disk gets copied cold and still locked on imaging hardware, and decryption then runs against that stable duplicate once a key has been found. One point to be clear on before committing: BitLocker falls in the forensic class of work, so the assessment happens first at no charge, a fixed quote follows on from it, and that figure is settled before work begins rather than afterwards.
BitLocker recovery is key-finding and disciplined imaging, and never code-breaking. The equipment reflects exactly that:
The key-recovery suite the trade actually rates. Keys get lifted from memory captures, hibernation files and security chips, or reached by an accelerated password attack. It locates keys; the AES underneath stays unbroken, for us and for everybody else.
If the machine still starts, the live key can occasionally be read out of RAM or the hibernation file directly. It is the quickest lawful way in when it is available.
Graphics silicon by the rack, grinding through dictionary and brute-force runs at many thousands of attempts a second, around the clock.
A deteriorating encrypted drive is captured in full while it is still locked, write-blocked from end to end. Decryption afterwards happens only on the stable duplicate.
The methodical trawl through Microsoft accounts, workplace directories, exported files and paper in drawers, which is where most lockouts are actually solved in the end.
BitLocker and BitLocker To Go first, then FileVault, LUKS, VeraCrypt and TrueCrypt, along with several hundred password-protected file types.
A sound BitLocker volume without its key stays shut, whatever a confident advertisement may say. Honest recovery here means finding the key: escrow trawls, work on the TPM, password attack at GPU speed — and a straight answer where the key has genuinely gone. Classed as forensic, the work is paid for at the point of quoting rather than on results — while arriving at that quote costs you nothing. The phone is answered by an engineer rather than a script, on 0800 689 0668.
Send every scrap of key material along, the 48-digit key included if anybody ever wrote it down, whichever Microsoft or workplace account might be holding escrow, exported key files, PINs, and your best guesses at the password with its variations. Each item takes hours off the clock. The drive itself travels perfectly well inside an anti-static bag, or in foil if that is what is to hand. Post it tracked and insured, use your own courier, or hand it in at reception at our Cambridge location — we do not offer a collection service.
Most of what reaches this bench arrived by tracked, insured post. It is the steadiest way to move a poorly drive, and a parcel posted in Norfolk is usually on the bench the next working day.
Is the drive still bolted inside a laptop, desktop, MacBook, iMac, server or CCTV / DVR recorder? The hard drive or SSD needs to come out first, and only the bare drive travels — taking drives out of machines is not something we do here. Storage soldered to a motherboard (Apple Silicon Macs, one or two very thin laptops) is the single thing beyond us: if it will not come out, it cannot come in.
↓ Print the shipping & booking-in form (PDF)
Mark the parcel for the attention of Cambridge Data Recovery. From Norwich it is about an hour and twenty down the A11, then two minutes off the A14 at Junction 32 — or next working day by tracked post. You hear from us as soon as it is booked onto the bench.
Unsure what to put in the box? Ring 0800 689 0668 before you seal it, or run the free online diagnostic.
Diagnosis free, one figure written down, most work under no fix no fee. Start online, or ring us.