A blue screen demanding 48 digits nobody wrote down, standing between a business and its own files. For York firms and households we trace escrowed keys, bulk-decrypt leavers' drives, and bring failing encrypted disks home through the cipher — never by cracking it, because cracked BitLocker is a thing that does not exist.
Every bitlocker job is diagnosed free. The quote turns up fixed, in writing, before a screwdriver is lifted.
No fix, no fee all jobs except electronic and mechanical failures, chip level work, DVR and Forensic jobs. Full pricing is on the data recovery cost page.
First job on any bitlocker is putting the symptoms against the fault — after twenty-odd years, these twenty-five account for nearly everything that comes through the door.
A hardware or firmware change unsettled the TPM's measurements, and your data now sits one long number away. The number is usually findable.
These mostly end at escrow: the Microsoft account nobody remembered, a directory entry, an exported file, a printout under the stapler. We trawl methodically.
Weak and middling passwords fall to GPU-speed attack. Genuinely strong lost ones earn you a straight verdict rather than a hopeful invoice.
Motherboard swaps, TPM clears, BIOS flashes and Secure Boot toggles all trip the protection exactly as designed. The recovery key un-trips it.
A data partition orphaned by reinstallation opens the moment its key surfaces. Underneath, the reinstall moved nothing.
The compound case: hardware failing beneath encryption. Captured whole while locked; decrypted afterwards from the stable copy.
Encrypted removables answer to the same three doors as system drives — key, password, or forensic key recovery. Same order, too.
Ex-staff drives decrypted in bulk against escrowed organisational keys, each matched to its drive by identifier.
Away from its TPM, the volume locks — behaviour, not misfortune. Minutes to reverse with the key in hand.
When BitLocker's own structures corrupt on an otherwise fair drive, the backup copies get located and the headers rebuilt before decryption.
Security chip cleared, 48 digits demanded. Recovered through escrow, or coaxed from what the chip still retains.
Installing Linux or reworking the bootloader changes the measurements, and up comes the prompt. Predictable; reversible; weekly.
Modern laptops enable device encryption silently at first sign-in. Most owners learn this at the lockout screen, which is poor timing.
Intune and AD hold keys nobody knew existed. We trace and pair them to drives by identifier, tediously and successfully.
Accounts accumulate several keys and the wrong one gets tried first. Matching by the on-screen key ID removes the guesswork.
Machines booting from a USB key file lock solid without it. Escrow and TPM routes stay open regardless.
A TPM-plus-PIN setup unused for months fades from memory. The way back in is the recovery key, and it can usually be found.
Dissolved business, deleted directory, drives in a box. Remaining escrow avenues and the TPM get worked instead.
Encrypted to the previous owner's account, recoverable only with that owner's lawful help. We say this before any money changes hands.
A manage-bde run interrupted by power failure leaves half a cipher. Salvaged sector by sector from an image, each half treated correctly.
External drives set to unlock automatically stop after a reinstall — the stored key left with the old Windows. Escrow usually holds its twin.
Hardware SEDs doing BitLocker's work in drive silicon fail on their own terms, and the old eDrive trust model had holes on record. Handled at drive level, candidly.
Sole copy of the recovery key, stored as a text file on the very volume it opens. We do appreciate the irony; escrow appreciates it less.
Used-space-only mode ciphered the files yet left free space in plain text — including older deleted copies. Carving reads what the cipher never covered.
A game insisted on TPM and Secure Boot changes; next boot demanded 48 digits. The gaming generation's most-travelled road to this page.
Most BitLocker keys called 'lost' were never lost at all — just filed somewhere nobody thought to look. Windows rarely encrypts without escrowing the key first: a Microsoft account, workplace Azure AD or an on-prem directory, an exported text file, a printout at the bottom of a drawer. Modern laptops switch encryption on silently at first sign-in, which is how people end up locked out of drives they never knew were locked. The opening move on any lockout is therefore a methodical sweep of every account and directory the machine ever touched — unglamorous, and it wins more cases than any clever tooling does.
The decryption side runs Passware Kit Forensic, the suite the forensic trade itself uses — and it's worth being plain about what it can and cannot do. Nobody breaks correctly implemented AES, whatever a confident website says. Passware recovers keys: from memory captures and hibernation files, out of the TPM, or by GPU-driven attack where a human password guards the volume. BitLocker and BitLocker To Go are the staples; VeraCrypt, FileVault, TrueCrypt and LUKS share the same bench, and estates of leavers' drives get decrypted in bulk for employers as routine work.
A drive failing while encrypted demands the right order of operations, and unlock attempts are precisely the wrong one — each spends the drive's last healthy hours proving nothing. The drive is imaged cold, still locked, on hardware rigs; decryption then runs against that stable copy with the recovered key. One thing to have straight before you commit — BitLocker sits in the forensic class, so the free assessment comes first, the fixed quote follows it, and settlement lands before anyone starts.
Key-finding plus disciplined imaging — never code-breaking — is the whole of BitLocker recovery, and the rigs mirror that:
The key-recovery suite the trade actually rates: keys lifted from memory captures, hibernation data and TPMs, or reached by accelerated password attack. It locates keys — AES itself stays unbroken, for us and everyone.
If the machine still boots, the live key can occasionally be read straight out of RAM or the hibernation file — the fastest lawful entrance there is.
Graphics silicon by the rack, grinding dictionary and brute-force runs at tens of thousands of attempts per second, day and night.
A deteriorating encrypted drive is captured whole while still locked, write-blocked end to end; decryption afterwards works only on the stable duplicate.
The methodical trawl — Microsoft accounts, workplace directories, exported files, paper in drawers — where the majority of lockouts are actually solved.
BitLocker and To Go first, then FileVault, VeraCrypt, TrueCrypt and LUKS, plus several hundred password-protected file types.
Sound BitLocker minus its key stays sealed, whatever a confident advert insists. Honest recovery means recovering the key — escrow trawls, TPM work, GPU-pace password attack — plus a plain verdict when the key has genuinely perished. Classed as forensic, the work is paid for at the point of quoting rather than on results — while arriving at that quote costs you nothing. And the phone gets answered by an engineer, not a script.
Post every scrap of key material alongside the drive: the 48-digit key if one was ever written down, whichever Microsoft or workplace account might hold escrow, exported key files, PINs, and best guesses at passwords with their variations. Each item trims hours off the clock. The bare drive itself travels happily in an anti-static bag — or, at a pinch, a sheet of foil.
Nearly every job on our bench arrived by tracked, insured post — it's the quickest, safest route in. There's no collection service, so the parcel is yours to send or hand in.
Is the drive still inside a computer, laptop, MacBook, iMac, CCTV / DVR or server? Take the hard drive or SSD out first and post the bare drive on its own — removing drives from machines isn't a service we offer. Storage that's soldered to a motherboard (Apple Silicon Macs, certain slim laptops) is the one thing we can't work on: if it doesn't come out, it can't come in.
↓ Print the booking-in & shipping form (PDF)
Address the parcel for the attention of Leeds Data Recovery — about 40 minutes from York via the A64 and A1(M), or next working day by tracked post. You'll hear from us the moment it's booked onto the bench.
Not certain what to pack? Ring 0800 689 0668 first, or run the free online diagnostic.
Free diagnosis, a fixed written figure, no fix no fee on most work — start online or ring the freephone.