Home / Devices / BitLocker

BitLocker Recovery & Decryption Norwich

A blue screen wanting forty-eight digits nobody ever wrote down, with a business or a household on the wrong side of it. Around Norfolk we track down escrowed keys, open leavers' machines in batches, and bring failing encrypted disks back through the cipher rather than around the outside of it — because BitLocker that has genuinely been cracked is not a thing that exists anywhere.

Every bitlocker job is diagnosed free. The quote follows in writing, fixed, before a screwdriver is picked up.

No fix, no fee all jobs except electronic and mechanical failures, chip level work, DVR and Forensic jobs. Full pricing is on the data recovery cost page.

// thirty faults this bench knows well

The thirty ways they give up

The first job on any bitlocker is matching the symptom to the fault — and after twenty-odd years, these thirty account for very nearly everything that comes through the door.

48 digits demanded at start-up

Some change to the hardware or the firmware unsettled the TPM's measurements, and the data now sits one long number away. That number is usually findable, which is the whole of this page in a sentence.

No record of any key at all

These mostly finish at escrow: a Microsoft account nobody remembered signing in with, a directory entry somewhere, an exported file, a printout underneath a stapler. The trawl is methodical and it works more often than not.

The password gone from memory

Weak and middling passwords give way to GPU-speed attack. Truly strong ones that are genuinely lost earn a straight verdict instead of a hopeful invoice.

New board, instant lockout

Motherboard swaps, TPM clears, a BIOS flash, a Secure Boot toggle: each trips the protection precisely as it was designed to be tripped. The recovery key untrips it.

Windows reinstalled around it

A data partition orphaned by a reinstall opens the moment its key turns up. Underneath, the reinstall moved nothing of consequence.

Failing and encrypted at the same time

The compound case: hardware dying underneath encryption. Captured whole while still locked, then decrypted from the stable copy rather than from the failing original.

A locked To Go stick

Encrypted removable media answers to the same three doors as a system drive — the key, the password, or forensic key recovery — and in the same order.

A crate of machines from leavers

Drives from former staff decrypted in bulk against the organisation's escrowed keys, each one matched to its own drive by identifier rather than by guesswork.

Moved into a second machine

Away from its TPM the volume locks, which is behaviour rather than misfortune. It takes a few minutes to undo, with the key in hand.

Header metadata gone bad

Where BitLocker's own structures corrupt on an otherwise sound drive, the backup copies are located and the headers rebuilt before any decryption is attempted.

A UEFI update that reset the TPM

Security chip cleared, 48 digits demanded, nothing else changed. Recovered through escrow, or coaxed out of what the chip still holds.

Tripped by dual booting

Installing Linux or reworking the bootloader alters the measurements and up comes the prompt. It is predictable, reversible, and weekly.

Encrypted without anyone being told

Modern laptops turn device encryption on quietly at first sign-in. Most owners find this out at the lockout screen, which is poor timing for a discovery.

Escrow searches across an estate

Intune and Active Directory hold keys nobody knew existed. Tracing them and pairing them to drives by identifier is tedious, and it is also usually successful.

A key that does not work

Accounts accumulate several keys over the years, and the wrong one always gets tried first. Matching on the key identifier shown on screen removes the guesswork entirely.

The startup stick gone missing

Machines that boot from a key file on a USB stick lock solid without it. The escrow and TPM routes stay open regardless, so it is not the end of the road.

A PIN forgotten over the winter

A TPM-and-PIN setup left unused for months fades from memory in a way that surprises people. The way back in is via the recovery key, and one can usually be found.

The company no longer exists

Dissolved business, deleted directory, drives in a box in somebody's garage. Whatever escrow avenues remain, and the TPM, get worked instead.

Bought locked from an auction site

Encrypted to the previous owner's account and recoverable only with that owner's lawful cooperation. We say so before any money changes hands rather than after.

Decryption stopped at forty-something percent

A decryption run interrupted by a power failure leaves half a cipher on the disk. It gets salvaged from an image, with each half treated correctly according to where the boundary fell.

Auto-unlock that forgot how

External drives set to unlock automatically stop doing so after a reinstall, because the stored key departed along with the old Windows. Escrow usually still holds its twin.

Self-encrypting drives underneath

Hardware drives doing BitLocker's job inside their own silicon fail on terms of their own, and the older trust model for that had documented holes. Handled at drive level, and candidly.

The key filed inside the safe

The only copy of the recovery key, saved as a text file sitting on the very volume that it opens. The irony is appreciated here; escrow appreciates it rather less.

Fast encryption's loose ends

Used-space-only mode encrypts the files and leaves free space unencrypted, including older deleted copies of those same files. Carving reads what the cipher never covered.

Anti-cheat flipping Secure Boot

A game required TPM and Secure Boot changes, and the next start-up demanded 48 digits. It is the most travelled road to this page among younger callers.

A key rotated after the machine went offline

Managed estates rotate recovery keys automatically, and a laptop that has not checked in since the rotation is now protected by a key the directory has replaced. Both the current and the previous key need retrieving, and the older one is the one that works.

A clone that broke the volume

Imaging an encrypted drive with consumer cloning software frequently produces a copy that is the wrong size, misaligned, or missing the volume header entirely. The encryption is fine and the container is not. Rebuilding it from the original is straightforward; rebuilding it from the clone is not.

A second encrypted volume with its own key

A data partition encrypted separately from the system drive has a separate key, and only one of the two usually gets written down. The identifier on screen tells us which one is being asked for, and the search proceeds from there.

A TPM that has locked itself for the day

Security chips defend against guessing by shutting the door after a run of wrong PINs, sometimes for hours and sometimes until the machine is left powered down overnight. Patience genuinely is the fix, and hammering at it extends the lockout rather than shortening it.

A certificate protector nobody kept

BitLocker can be unlocked by a smart card or a certificate instead of a password, which is tidy until the card is lost or the certificate expires with a former IT provider. The remaining routes are escrow and the TPM, and we will tell you at the diagnostic stage which of them is still open.

First job: find the key, which normally still exists somewhere

Keys described as lost were mostly never lost, only filed where nobody has thought to look. Windows very seldom encrypts anything without escrowing the key somewhere first — a Microsoft account, a workplace Azure AD tenant, an on-premises directory, a text file exported and forgotten, a printout that went in a drawer during a rushed handover. Newer laptops turn device encryption on quietly during the first sign-in, which is how households end up shut out of drives they had no idea were encrypted at all. So the first move against any lockout is a patient trawl through every account and directory that machine has ever touched. Dull work, and it settles more cases than any of the clever tooling does.

Second job: Passware, described accurately

Decryption here runs on Passware Kit Forensic, which is what the forensic trade uses, and it is worth being exact about what that means in practice. Correctly implemented AES is not defeated by anybody, whatever a confident-sounding website claims this week. Passware does not break ciphers; it recovers keys, out of hibernation files and memory captures, from the TPM itself, or by throwing GPUs at a human-chosen password where that is the only thing standing guard. BitLocker and BitLocker To Go make up the everyday work, with VeraCrypt, FileVault, TrueCrypt and LUKS sharing the same bench, and batches of drives from departed staff decrypted for employers as a matter of routine.

Both at once: dying and locked

A disk failing while it is still encrypted needs its operations in a particular order, and unlock attempts are firmly the wrong first move, since each one spends part of what remains of the drive's healthy running time and proves nothing at all. The disk gets copied cold and still locked on imaging hardware, and decryption then runs against that stable duplicate once a key has been found. One point to be clear on before committing: BitLocker falls in the forensic class of work, so the assessment happens first at no charge, a fixed quote follows on from it, and that figure is settled before work begins rather than afterwards.

// what sits on the bench

Engineering kit, not download-and-hope software

BitLocker recovery is key-finding and disciplined imaging, and never code-breaking. The equipment reflects exactly that:

Passware Kit Forensic

The key-recovery suite the trade actually rates. Keys get lifted from memory captures, hibernation files and security chips, or reached by an accelerated password attack. It locates keys; the AES underneath stays unbroken, for us and for everybody else.

Memory and hibernation capture

If the machine still starts, the live key can occasionally be read out of RAM or the hibernation file directly. It is the quickest lawful way in when it is available.

GPU acceleration cluster

Graphics silicon by the rack, grinding through dictionary and brute-force runs at many thousands of attempts a second, around the clock.

Hardware imagers and write-blockers

A deteriorating encrypted drive is captured in full while it is still locked, write-blocked from end to end. Decryption afterwards happens only on the stable duplicate.

Key escrow investigation

The methodical trawl through Microsoft accounts, workplace directories, exported files and paper in drawers, which is where most lockouts are actually solved in the end.

Multi-format decryption

BitLocker and BitLocker To Go first, then FileVault, LUKS, VeraCrypt and TrueCrypt, along with several hundred password-protected file types.

// makes & models we see

Encryption systems handled

BitLockerWindows Device EncryptionBitLocker To GoVeraCryptFileVault 2LUKS and LUKS2TrueCryptDell Data ProtectionPGP / SymantecMcAfee Drive Encryption

Where keys are actually found

A sound BitLocker volume without its key stays shut, whatever a confident advertisement may say. Honest recovery here means finding the key: escrow trawls, work on the TPM, password attack at GPU speed — and a straight answer where the key has genuinely gone. Classed as forensic, the work is paid for at the point of quoting rather than on results — while arriving at that quote costs you nothing. The phone is answered by an engineer rather than a script, on 0800 689 0668.

// before you post it

Before you post it — get the drive loose if you can

Send every scrap of key material along, the 48-digit key included if anybody ever wrote it down, whichever Microsoft or workplace account might be holding escrow, exported key files, PINs, and your best guesses at the password with its variations. Each item takes hours off the clock. The drive itself travels perfectly well inside an anti-static bag, or in foil if that is what is to hand. Post it tracked and insured, use your own courier, or hand it in at reception at our Cambridge location — we do not offer a collection service.

// getting your device to us

Getting it here — no great performance

Most of what reaches this bench arrived by tracked, insured post. It is the steadiest way to move a poorly drive, and a parcel posted in Norfolk is usually on the bench the next working day.

Is the drive still bolted inside a laptop, desktop, MacBook, iMac, server or CCTV / DVR recorder? The hard drive or SSD needs to come out first, and only the bare drive travels — taking drives out of machines is not something we do here. Storage soldered to a motherboard (Apple Silicon Macs, one or two very thin laptops) is the single thing beyond us: if it will not come out, it cannot come in.

  • Bubble wrap and a firm box or padded envelope, packed so nothing shifts about. Cables, caddies and power bricks are no use to us — keep them.
  • Print the shipping & booking-in form (PDF), write your name, your number and a couple of lines on what happened, and put it in with the drive.
  • Royal Mail Special Delivery covers it tracked and insured door to door; a courier of your own does the same job if that suits you better.
  • Rather hand it over yourself? Reception at the address below takes drop-offs, Mon–Fri 9:00am–5:30pm.
// where your device is headed

Cambridge Data Recovery

Compass House, Vision Park
Chivers Way
Cambridge, CB24 9AD

↓ Print the shipping & booking-in form (PDF)

Mark the parcel for the attention of Cambridge Data Recovery. From Norwich it is about an hour and twenty down the A11, then two minutes off the A14 at Junction 32 — or next working day by tracked post. You hear from us as soon as it is booked onto the bench.

Unsure what to put in the box? Ring 0800 689 0668 before you seal it, or run the free online diagnostic.

// bitlocker recovery questions

Common questions

Rarely. Most lockouts turn out to have escrowed a key at some point — a Microsoft sign-in, a company directory, a file saved and forgotten about — and where one truly never existed, the TPM or a memory capture will often produce it, with weak passwords giving way to GPU attack. The one action that makes matters permanently worse is a reset or a reinstall, either of which can wipe out key material that was still within reach.
No, and anybody claiming otherwise is a warning sign rather than a supplier. Sound AES minus its key is shut to everyone, permanently, as a matter of arithmetic. Proper practice goes after the key instead: a weak password falls quickly, and a strong one that is genuinely gone earns you a straight refusal rather than a long and expensive attempt.
Very, and it is routine. Send the box as one consignment together with anything the organisation still holds — keys, account names, directory records — and the batch is worked through together. How complete that material is governs both the speed and the price rather more than the number of drives does.
Stop, and switch it off. Capture comes first and decryption second: the disk copied while still locked, the key then applied to that copy, rather than repeated unlocking attempts on hardware already in trouble. Forensic-class rules govern this work: the figure quoted gets settled before anybody starts, though the assessment that produced it costs nothing.
// related services

More work we take on

Whenever you’re ready, the bench is.

Diagnosis free, one figure written down, most work under no fix no fee. Start online, or ring us.