Forty-eight digits on a blue screen, and no record anywhere of what they were. That is where most of these jobs begin, in a household or an office that never expected to meet that screen at all. Work across Merseyside covers hunting down escrowed keys, clearing batches of machines left behind by departing staff, and getting data off failing encrypted disks through the cipher rather than round it. Nothing gets cracked here, because BitLocker does not crack.
Every bitlocker job is diagnosed free. One fixed figure follows in writing, agreed before a screwdriver comes out of the drawer.
No fix, no fee all jobs except electronic and mechanical failures, chip level work, DVR and Forensic jobs. Every band is listed on the data recovery cost page.
Matching the symptom to the fault underneath is the first job on any bitlocker, and after twenty-odd years these thirty account for very nearly everything that arrives.
Something in the hardware or the firmware moved, the TPM's measurements stopped matching, and the disk is now one long number away from opening. Finding that number is what this entire page is about.
Most of these finish at escrow. A Microsoft account somebody forgot they had signed into, an entry in a company directory, an exported key file, a printout in a drawer under a stapler. The search is methodical and it succeeds far more often than it fails.
Weak and middling passwords fall to a GPU attack given time. A genuinely strong password that is genuinely lost gets a straight answer instead of an optimistic invoice.
Board swaps, a cleared TPM, a BIOS update, Secure Boot switched either way: each of those trips the protection precisely as designed. The recovery key is what untrips it.
A data partition the reinstall left behind opens as soon as its key turns up. Underneath all the noise, very little of consequence was moved.
The compound case: hardware dying underneath a locked volume. The disk is imaged in full while still locked, and decryption then runs against that stable copy. The original is never asked to do the work twice.
Encrypted removable media has the same three ways in as a system disk. The recovery key, the password, or forensic key recovery, tried in that order because that is the order that pays.
Disks from former staff, decrypted in a batch against whatever the organisation holds in escrow, with each drive paired to its own key by identifier rather than by trial and error.
Separated from the TPM that sealed it, the volume locks. That is the design working correctly, not a fault developing. With the key in hand it is a five-minute job.
Where the encryption structures themselves are damaged on a disk that is otherwise healthy, we find the backup copies of those structures and repair the headers first. Decryption is not attempted until that is done.
The security chip is wiped, the prompt appears, and nothing else about the machine has changed. Escrow answers most of these. Occasionally the chip still holds enough to work with.
Install Linux or rework the bootloader and the measurements change, so the prompt is waiting at the next start-up. Predictable, reversible, and seen here most weeks.
New laptops turn device encryption on by themselves at the first sign-in, quietly and without a dialogue box. Plenty of owners discover it for the first time at a lockout screen, which is the worst moment available for that particular discovery.
Intune and Active Directory hold keys nobody in the building knows about. Locating them and pairing each to the right disk by identifier is dull work with a good success rate.
Accounts collect several recovery keys over the years, and the first one tried is reliably the wrong one. The key identifier printed on the lockout screen says which key is being asked for, and that ends the guesswork.
Machines configured to take a key file off a USB stick at boot will not start without it, and the stick is usually in a drawer at an old office. Escrow and the TPM both stay open, so a lost stick is not the end of the road.
A TPM-and-PIN machine left in a cupboard for four months goes out of a person's head more completely than they expect. The recovery key is the route back in, and one can usually be dug out of somewhere.
Directory deleted, tenant closed, and the disks in a box in a garage. Whatever escrow routes still exist get worked, along with the TPM, and you will be told early if neither is going to answer.
The disk is encrypted to the previous owner's account, so it needs that owner's lawful cooperation and nothing else will substitute for it. That gets said on the first call, before anybody has spent a penny.
A decryption run cut short by a power failure leaves the disk half enciphered and half not, with a boundary somewhere in the middle. It is salvaged from an image, each side handled according to which side it is.
External drives set to unlock themselves stop doing it after a Windows reinstall, because the stored key departed with the old installation. Escrow usually still holds the matching copy.
Some disks encrypt inside their own silicon and BitLocker simply hands the work over to them. Those fail in their own way, and the earlier trust model behind that arrangement had documented weaknesses. Handled at drive level, and described without varnish.
The only copy of the recovery key, in a text file, sitting on the encrypted volume. The irony is genuinely appreciated here. Escrow appreciates it a good deal less.
Used-space-only mode enciphers the files that exist and leaves free space alone, deleted earlier versions of those same files included. Carving reads everything the cipher never reached.
A game asked for Secure Boot and the TPM to be turned on, and the next boot asked for 48 digits. Among callers under thirty it is much the most travelled road to this page.
Managed estates rotate recovery keys automatically, so a machine that has not checked in since the last rotation is protected by a key the directory has already replaced. Both keys need pulling, and it is the older one that opens the disk.
Consumer cloning software makes a poor job of an encrypted disk: wrong size, wrong alignment, or no volume header at all. The cryptography is unharmed; the container around it is not. Rebuild from the original disk and it is routine work. Rebuild from that clone and it is not.
Where the data partition was encrypted on its own, it carries a key of its own, and typically only one of the pair was ever recorded anywhere. The identifier on the prompt says which key the machine is asking for, and the search starts from that.
Security chips answer repeated wrong PINs by shutting the door, occasionally for a few hours and occasionally until the machine has spent a night switched off. Waiting is genuinely the fix here. Carrying on guessing lengthens the lockout.
A smart card or a certificate can unlock BitLocker in place of a password. That works neatly until the card goes missing, or the certificate lapses with an IT provider who has since moved on. Escrow and the TPM are the routes left, and the free assessment says whether either of them still answers.
A key somebody calls lost has, nine times out of ten, simply been put where nobody has gone looking. Windows almost never encrypts a volume without stashing a copy first. It might be sitting under a Microsoft account, in an employer's Azure AD tenant, in an on-premises directory, in a text file exported during setup and never opened since, or on a sheet of paper that went into a drawer while somebody handed the job over in a hurry. Recent laptops make matters worse by switching device encryption on by themselves at first sign-in, which is how a family ends up shut out of a machine nobody realised was protected. Every lockout therefore starts the same way, with a slow methodical sweep of each account and directory that computer has ever been near. Tedious, and it closes more of these jobs than any of the specialist tooling does.
The tool on this bench is Passware Kit Forensic, the same package the forensic side of the industry runs, and it deserves an accurate description rather than a sales one. AES implemented properly is beaten by nobody, whatever some confident website is claiming this month. Passware attacks nothing mathematical. What it does is locate keys, lifting them out of hibernation files and memory captures, pulling them from a TPM, or setting graphics cards loose on a password a person chose in the cases where a password is the only guard on the door. Day to day that means BitLocker and BitLocker To Go. VeraCrypt, FileVault, TrueCrypt and LUKS get handled on the same equipment, and clearing a batch of drives belonging to staff who have moved on is ordinary employer work here.
Two faults at once changes the order things have to happen in, and typing the key again is not the opening move. Each attempt burns through some of whatever healthy operating time the disk has left and settles nothing either way. So the drive gets imaged cold, still sealed, on hardware built for reading unreliable media, and the decryption is aimed at that duplicate afterwards, once a key has turned up. Worth knowing before you commit: this work sits in the forensic class at £400 + VAT, meaning the assessment happens first and costs nothing, a fixed figure comes out of it, and that figure is paid before the job rather than after.
Nothing on this bench breaks encryption. The equipment is here to find keys and to image failing disks safely, and that is the whole of it:
The key-recovery suite most of this trade relies on. It lifts keys out of memory captures, hibernation files and security chips, and it runs accelerated attacks against passwords. Locating keys is what it does. The AES underneath stays intact, for this lab and for everybody else.
On a machine that still starts, the live key can sometimes be read straight out of RAM or out of the hibernation file. Where that is available it is the quickest lawful way in.
Graphics silicon working through dictionaries and brute-force ranges at many thousands of candidates a second, running day and night until it lands or the odds are called honestly.
A deteriorating encrypted disk gets captured whole, still locked, behind a hardware write-blocker. Every step after the capture happens on the duplicate.
The patient hunt through Microsoft sign-ins, company directories, exported key files and whatever paperwork has survived. Most lockouts are solved right here rather than at a keyboard.
BitLocker first, and BitLocker To Go with it, then FileVault 2, LUKS, VeraCrypt and TrueCrypt, plus a long list of password-protected document formats.
A sound BitLocker volume with no key stays shut, whatever a confident advertisement implies. Honest work here means hunting the key down: escrow trawls, whatever the TPM will still give up, a password attack at GPU speed, and a plain verdict when the key has genuinely gone for good. BitLocker jobs are £400 + VAT where you supply or we recover the key, and the work sits outside no fix, no fee, so the quote is settled before it starts. Reaching that quote costs nothing. The laptops arrive from accountants and architects in the commercial district, from firms in Chester, and from students and staff at LJMU and the other universities. An engineer picks the phone up here, not a script: 0800 689 0668, Monday to Friday, 9:00am to 5:30pm.
Send anything that might be key material along with the drive: the 48-digit key if it was ever written down, whichever Microsoft or company account could be holding escrow, exported key files, any PINs, and your honest guesses at the password with the variations you tend to use. Every one of those takes hours off the clock and off the bill. The drive itself travels perfectly well in an anti-static bag, or wrapped in foil if that is what the house can offer. Post it tracked and insured to Manchester Data Recovery, Peter House, Oxford Street, Manchester M1 5AN, or send it by a courier of your own. Nobody is sent out to collect it, and there is no shop to walk into in Liverpool, though the Manchester reception will take it by hand during office hours.
Almost every job on this bench came in by tracked, insured post. It is the calmest way to move a drive that is already struggling, and a parcel handed in anywhere on Merseyside usually reaches the bench the following working day.
Still screwed inside a laptop, tower, MacBook, iMac, server or a CCTV recorder? Take the drive out and post that on its own. We do not strip machines here, and any computer shop will do it in a few minutes. The one job nobody can take on is flash soldered straight to a logic board, as on Apple Silicon Macs and a handful of very slim laptops: if the storage will not unbolt, there is nothing to send.
↓ Print the shipping & booking-in form (PDF)
Address it to Manchester Data Recovery. It is roughly 35 miles from Liverpool along the M62 if you fancy the run, and next working day by tracked post if you do not. We ring or email the moment it is booked in, and the free diagnostic closes 2 working days after that.
Not sure what belongs in the parcel? Call 0800 689 0668 before you tape it shut, or step through the free online diagnostic first.
Diagnosis free, one figure written down, and £300 + VAT covers a single drive or SSD. Start online or ring.