Home / Devices / BitLocker

BitLocker Recovery & Decryption York

A blue screen demanding 48 digits nobody wrote down, standing between a business and its own files. For York firms and households we trace escrowed keys, bulk-decrypt leavers' drives, and bring failing encrypted disks home through the cipher — never by cracking it, because cracked BitLocker is a thing that does not exist.

Every bitlocker job is diagnosed free. The quote turns up fixed, in writing, before a screwdriver is lifted.

No fix, no fee all jobs except electronic and mechanical failures, chip level work, DVR and Forensic jobs. Full pricing is on the data recovery cost page.

// top 25 faults on this bench

The twenty-five ways they let go

First job on any bitlocker is putting the symptoms against the fault — after twenty-odd years, these twenty-five account for nearly everything that comes through the door.

48 digits demanded at boot

A hardware or firmware change unsettled the TPM's measurements, and your data now sits one long number away. The number is usually findable.

No record of any key

These mostly end at escrow: the Microsoft account nobody remembered, a directory entry, an exported file, a printout under the stapler. We trawl methodically.

The password went missing

Weak and middling passwords fall to GPU-speed attack. Genuinely strong lost ones earn you a straight verdict rather than a hopeful invoice.

New board, instant lockout

Motherboard swaps, TPM clears, BIOS flashes and Secure Boot toggles all trip the protection exactly as designed. The recovery key un-trips it.

Reinstalled Windows around it

A data partition orphaned by reinstallation opens the moment its key surfaces. Underneath, the reinstall moved nothing.

Dying and ciphered simultaneously

The compound case: hardware failing beneath encryption. Captured whole while locked; decrypted afterwards from the stable copy.

A locked To Go stick

Encrypted removables answer to the same three doors as system drives — key, password, or forensic key recovery. Same order, too.

A crate of leaver machines

Ex-staff drives decrypted in bulk against escrowed organisational keys, each matched to its drive by identifier.

Moved to a second machine

Away from its TPM, the volume locks — behaviour, not misfortune. Minutes to reverse with the key in hand.

Header metadata gone bad

When BitLocker's own structures corrupt on an otherwise fair drive, the backup copies get located and the headers rebuilt before decryption.

A UEFI update reset the TPM

Security chip cleared, 48 digits demanded. Recovered through escrow, or coaxed from what the chip still retains.

Tripped by a dual-boot

Installing Linux or reworking the bootloader changes the measurements, and up comes the prompt. Predictable; reversible; weekly.

Encrypted without a word

Modern laptops enable device encryption silently at first sign-in. Most owners learn this at the lockout screen, which is poor timing.

Escrow hunts across estates

Intune and AD hold keys nobody knew existed. We trace and pair them to drives by identifier, tediously and successfully.

A key that 'doesn't work'

Accounts accumulate several keys and the wrong one gets tried first. Matching by the on-screen key ID removes the guesswork.

The startup stick went missing

Machines booting from a USB key file lock solid without it. Escrow and TPM routes stay open regardless.

PIN forgotten by spring

A TPM-plus-PIN setup unused for months fades from memory. The way back in is the recovery key, and it can usually be found.

The company no longer exists

Dissolved business, deleted directory, drives in a box. Remaining escrow avenues and the TPM get worked instead.

Bought locked off eBay

Encrypted to the previous owner's account, recoverable only with that owner's lawful help. We say this before any money changes hands.

Decryption halted at 40-something percent

A manage-bde run interrupted by power failure leaves half a cipher. Salvaged sector by sector from an image, each half treated correctly.

Auto-unlock that forgot how

External drives set to unlock automatically stop after a reinstall — the stored key left with the old Windows. Escrow usually holds its twin.

Self-encrypting drives underneath

Hardware SEDs doing BitLocker's work in drive silicon fail on their own terms, and the old eDrive trust model had holes on record. Handled at drive level, candidly.

The key filed inside the safe

Sole copy of the recovery key, stored as a text file on the very volume it opens. We do appreciate the irony; escrow appreciates it less.

Fast encryption's loose ends

Used-space-only mode ciphered the files yet left free space in plain text — including older deleted copies. Carving reads what the cipher never covered.

Anti-cheat flipped Secure Boot

A game insisted on TPM and Secure Boot changes; next boot demanded 48 digits. The gaming generation's most-travelled road to this page.

Job one: run down the key that almost certainly still exists

Most BitLocker keys called 'lost' were never lost at all — just filed somewhere nobody thought to look. Windows rarely encrypts without escrowing the key first: a Microsoft account, workplace Azure AD or an on-prem directory, an exported text file, a printout at the bottom of a drawer. Modern laptops switch encryption on silently at first sign-in, which is how people end up locked out of drives they never knew were locked. The opening move on any lockout is therefore a methodical sweep of every account and directory the machine ever touched — unglamorous, and it wins more cases than any clever tooling does.

Job two: Passware, described honestly

The decryption side runs Passware Kit Forensic, the suite the forensic trade itself uses — and it's worth being plain about what it can and cannot do. Nobody breaks correctly implemented AES, whatever a confident website says. Passware recovers keys: from memory captures and hibernation files, out of the TPM, or by GPU-driven attack where a human password guards the volume. BitLocker and BitLocker To Go are the staples; VeraCrypt, FileVault, TrueCrypt and LUKS share the same bench, and estates of leavers' drives get decrypted in bulk for employers as routine work.

The double emergency: dying and locked

A drive failing while encrypted demands the right order of operations, and unlock attempts are precisely the wrong one — each spends the drive's last healthy hours proving nothing. The drive is imaged cold, still locked, on hardware rigs; decryption then runs against that stable copy with the recovered key. One thing to have straight before you commit — BitLocker sits in the forensic class, so the free assessment comes first, the fixed quote follows it, and settlement lands before anyone starts.

// the kit on the bench

Engineering tools, not download-and-hope software

Key-finding plus disciplined imaging — never code-breaking — is the whole of BitLocker recovery, and the rigs mirror that:

Passware Kit Forensic

The key-recovery suite the trade actually rates: keys lifted from memory captures, hibernation data and TPMs, or reached by accelerated password attack. It locates keys — AES itself stays unbroken, for us and everyone.

Memory & hibernation capture

If the machine still boots, the live key can occasionally be read straight out of RAM or the hibernation file — the fastest lawful entrance there is.

GPU acceleration cluster

Graphics silicon by the rack, grinding dictionary and brute-force runs at tens of thousands of attempts per second, day and night.

Hardware imagers + write-blockers

A deteriorating encrypted drive is captured whole while still locked, write-blocked end to end; decryption afterwards works only on the stable duplicate.

Key-escrow investigation

The methodical trawl — Microsoft accounts, workplace directories, exported files, paper in drawers — where the majority of lockouts are actually solved.

Multi-format decryption

BitLocker and To Go first, then FileVault, VeraCrypt, TrueCrypt and LUKS, plus several hundred password-protected file types.

// makes & models we see

Encryption systems handled

BitLockerWindows Device EncryptionBitLocker To GoVeraCryptFileVault 2LUKS / LUKS2TrueCryptDell Data ProtectionPGP / SymantecMcAfee Drive Encryption

Where keys are actually found

Sound BitLocker minus its key stays sealed, whatever a confident advert insists. Honest recovery means recovering the key — escrow trawls, TPM work, GPU-pace password attack — plus a plain verdict when the key has genuinely perished. Classed as forensic, the work is paid for at the point of quoting rather than on results — while arriving at that quote costs you nothing. And the phone gets answered by an engineer, not a script.

// before you post it

Before it goes in the post — free the drive if you can

Post every scrap of key material alongside the drive: the 48-digit key if one was ever written down, whichever Microsoft or workplace account might hold escrow, exported key files, PINs, and best guesses at passwords with their variations. Each item trims hours off the clock. The bare drive itself travels happily in an anti-static bag — or, at a pinch, a sheet of foil.

// getting your device to us

Sending it in — easier than you'd think

Nearly every job on our bench arrived by tracked, insured post — it's the quickest, safest route in. There's no collection service, so the parcel is yours to send or hand in.

Is the drive still inside a computer, laptop, MacBook, iMac, CCTV / DVR or server? Take the hard drive or SSD out first and post the bare drive on its own — removing drives from machines isn't a service we offer. Storage that's soldered to a motherboard (Apple Silicon Macs, certain slim laptops) is the one thing we can't work on: if it doesn't come out, it can't come in.

  • Bubble wrap and a sturdy box or padded envelope will do nicely — cables, caddies and power bricks can stay at home.
  • Print off the booking-in & shipping form (PDF), add your name, number and a line or two on what happened, and tuck it in the parcel.
  • Royal Mail Special Delivery keeps it tracked and insured the whole way; your own courier does the same job if you'd sooner book one. There's no collection service at this end.
  • Happier handing it over in person? Reception at the address here takes drop-offs, Mon–Fri 9:00am–5:30pm.
// where your device is headed

Leeds Data Recovery

17th Floor, The Pinnacle
Albion Street
Leeds, LS1 5AA

↓ Print the booking-in & shipping form (PDF)

Address the parcel for the attention of Leeds Data Recovery — about 40 minutes from York via the A64 and A1(M), or next working day by tracked post. You'll hear from us the moment it's booked onto the bench.

Not certain what to pack? Ring 0800 689 0668 first, or run the free online diagnostic.

// bitlocker recovery questions

Common questions

Rarely. In most lockouts a key was escrowed somewhere along the way — a Microsoft sign-in, a work directory, a file exported and forgotten — and where one genuinely never existed, the TPM or a memory image often gives it up, with weak passwords falling to GPU attack. The one way to make things worse is resetting or reinstalling, which can destroy recoverable key material. Don't.
No — and anyone claiming otherwise is a warning sign, not a service. Sound AES minus its key is closed to everyone, mathematically and permanently. Legitimate practice recovers the key instead; weak passwords fall quickly, and strong lost ones earn you a straight no rather than a long invoice.
Very — it's routine. Send the lot in one go, along with whatever the organisation still holds by way of keys, account names and directory records, and the batch gets decrypted together. The completeness of your key material sets the speed and the price more than anything else does.
Stop entirely and power it down. The safe order is capture first, decrypt second — the drive imaged while still locked, the key applied to the copy, never unlock-and-pray on sick hardware. Forensic-class rules apply here: the quoted figure gets settled before anyone starts, though the assessment behind it costs nothing.
// related services

More work we take on

When you’re ready, so is the bench.

Free diagnosis, a fixed written figure, no fix no fee on most work — start online or ring the freephone.