Home / Devices / BitLocker

BitLocker Recovery & Decryption Liverpool

Forty-eight digits on a blue screen, and no record anywhere of what they were. That is where most of these jobs begin, in a household or an office that never expected to meet that screen at all. Work across Merseyside covers hunting down escrowed keys, clearing batches of machines left behind by departing staff, and getting data off failing encrypted disks through the cipher rather than round it. Nothing gets cracked here, because BitLocker does not crack.

Every bitlocker job is diagnosed free. One fixed figure follows in writing, agreed before a screwdriver comes out of the drawer.

No fix, no fee all jobs except electronic and mechanical failures, chip level work, DVR and Forensic jobs. Every band is listed on the data recovery cost page.

// thirty faults this bench sees most

Thirty ways they call it a day

Matching the symptom to the fault underneath is the first job on any bitlocker, and after twenty-odd years these thirty account for very nearly everything that arrives.

A 48-digit prompt on a machine that used to boot

Something in the hardware or the firmware moved, the TPM's measurements stopped matching, and the disk is now one long number away from opening. Finding that number is what this entire page is about.

No key written down anywhere

Most of these finish at escrow. A Microsoft account somebody forgot they had signed into, an entry in a company directory, an exported key file, a printout in a drawer under a stapler. The search is methodical and it succeeds far more often than it fails.

The password has gone

Weak and middling passwords fall to a GPU attack given time. A genuinely strong password that is genuinely lost gets a straight answer instead of an optimistic invoice.

New motherboard, locked disk

Board swaps, a cleared TPM, a BIOS update, Secure Boot switched either way: each of those trips the protection precisely as designed. The recovery key is what untrips it.

Windows reinstalled around an encrypted partition

A data partition the reinstall left behind opens as soon as its key turns up. Underneath all the noise, very little of consequence was moved.

Encrypted and failing at the same time

The compound case: hardware dying underneath a locked volume. The disk is imaged in full while still locked, and decryption then runs against that stable copy. The original is never asked to do the work twice.

A locked BitLocker To Go stick

Encrypted removable media has the same three ways in as a system disk. The recovery key, the password, or forensic key recovery, tried in that order because that is the order that pays.

A box of drives from people who left

Disks from former staff, decrypted in a batch against whatever the organisation holds in escrow, with each drive paired to its own key by identifier rather than by trial and error.

The disk was moved into another computer

Separated from the TPM that sealed it, the volume locks. That is the design working correctly, not a fault developing. With the key in hand it is a five-minute job.

Corrupt BitLocker metadata

Where the encryption structures themselves are damaged on a disk that is otherwise healthy, we find the backup copies of those structures and repair the headers first. Decryption is not attempted until that is done.

A UEFI update that cleared the TPM

The security chip is wiped, the prompt appears, and nothing else about the machine has changed. Escrow answers most of these. Occasionally the chip still holds enough to work with.

Dual booting set it off

Install Linux or rework the bootloader and the measurements change, so the prompt is waiting at the next start-up. Predictable, reversible, and seen here most weeks.

Encryption nobody switched on

New laptops turn device encryption on by themselves at the first sign-in, quietly and without a dialogue box. Plenty of owners discover it for the first time at a lockout screen, which is the worst moment available for that particular discovery.

Escrow searches across a whole estate

Intune and Active Directory hold keys nobody in the building knows about. Locating them and pairing each to the right disk by identifier is dull work with a good success rate.

A key that gets rejected

Accounts collect several recovery keys over the years, and the first one tried is reliably the wrong one. The key identifier printed on the lockout screen says which key is being asked for, and that ends the guesswork.

The startup key stick has gone missing

Machines configured to take a key file off a USB stick at boot will not start without it, and the stick is usually in a drawer at an old office. Escrow and the TPM both stay open, so a lost stick is not the end of the road.

A PIN that faded over a long winter

A TPM-and-PIN machine left in a cupboard for four months goes out of a person's head more completely than they expect. The recovery key is the route back in, and one can usually be dug out of somewhere.

The company has been dissolved

Directory deleted, tenant closed, and the disks in a box in a garage. Whatever escrow routes still exist get worked, along with the TPM, and you will be told early if neither is going to answer.

Bought locked from an auction site

The disk is encrypted to the previous owner's account, so it needs that owner's lawful cooperation and nothing else will substitute for it. That gets said on the first call, before anybody has spent a penny.

Decryption interrupted at forty per cent

A decryption run cut short by a power failure leaves the disk half enciphered and half not, with a boundary somewhere in the middle. It is salvaged from an image, each side handled according to which side it is.

Auto-unlock that stopped working

External drives set to unlock themselves stop doing it after a Windows reinstall, because the stored key departed with the old installation. Escrow usually still holds the matching copy.

Self-encrypting drives underneath it all

Some disks encrypt inside their own silicon and BitLocker simply hands the work over to them. Those fail in their own way, and the earlier trust model behind that arrangement had documented weaknesses. Handled at drive level, and described without varnish.

The key saved inside the thing it opens

The only copy of the recovery key, in a text file, sitting on the encrypted volume. The irony is genuinely appreciated here. Escrow appreciates it a good deal less.

What fast encryption left uncovered

Used-space-only mode enciphers the files that exist and leaves free space alone, deleted earlier versions of those same files included. Carving reads everything the cipher never reached.

An anti-cheat requirement that locked the machine

A game asked for Secure Boot and the TPM to be turned on, and the next boot asked for 48 digits. Among callers under thirty it is much the most travelled road to this page.

A key rotated while the laptop was away

Managed estates rotate recovery keys automatically, so a machine that has not checked in since the last rotation is protected by a key the directory has already replaced. Both keys need pulling, and it is the older one that opens the disk.

A clone that broke the container

Consumer cloning software makes a poor job of an encrypted disk: wrong size, wrong alignment, or no volume header at all. The cryptography is unharmed; the container around it is not. Rebuild from the original disk and it is routine work. Rebuild from that clone and it is not.

A second volume with a key of its own

Where the data partition was encrypted on its own, it carries a key of its own, and typically only one of the pair was ever recorded anywhere. The identifier on the prompt says which key the machine is asking for, and the search starts from that.

A TPM that has shut itself for the night

Security chips answer repeated wrong PINs by shutting the door, occasionally for a few hours and occasionally until the machine has spent a night switched off. Waiting is genuinely the fix here. Carrying on guessing lengthens the lockout.

A certificate protector nobody kept a copy of

A smart card or a certificate can unlock BitLocker in place of a password. That works neatly until the card goes missing, or the certificate lapses with an IT provider who has since moved on. Escrow and the TPM are the routes left, and the free assessment says whether either of them still answers.

Step one is finding the key, and it usually still exists

A key somebody calls lost has, nine times out of ten, simply been put where nobody has gone looking. Windows almost never encrypts a volume without stashing a copy first. It might be sitting under a Microsoft account, in an employer's Azure AD tenant, in an on-premises directory, in a text file exported during setup and never opened since, or on a sheet of paper that went into a drawer while somebody handed the job over in a hurry. Recent laptops make matters worse by switching device encryption on by themselves at first sign-in, which is how a family ends up shut out of a machine nobody realised was protected. Every lockout therefore starts the same way, with a slow methodical sweep of each account and directory that computer has ever been near. Tedious, and it closes more of these jobs than any of the specialist tooling does.

Step two is Passware, described honestly

The tool on this bench is Passware Kit Forensic, the same package the forensic side of the industry runs, and it deserves an accurate description rather than a sales one. AES implemented properly is beaten by nobody, whatever some confident website is claiming this month. Passware attacks nothing mathematical. What it does is locate keys, lifting them out of hibernation files and memory captures, pulling them from a TPM, or setting graphics cards loose on a password a person chose in the cases where a password is the only guard on the door. Day to day that means BitLocker and BitLocker To Go. VeraCrypt, FileVault, TrueCrypt and LUKS get handled on the same equipment, and clearing a batch of drives belonging to staff who have moved on is ordinary employer work here.

When a disk is failing and locked at the same time

Two faults at once changes the order things have to happen in, and typing the key again is not the opening move. Each attempt burns through some of whatever healthy operating time the disk has left and settles nothing either way. So the drive gets imaged cold, still sealed, on hardware built for reading unreliable media, and the decryption is aimed at that duplicate afterwards, once a key has turned up. Worth knowing before you commit: this work sits in the forensic class at £400 + VAT, meaning the assessment happens first and costs nothing, a fixed figure comes out of it, and that figure is paid before the job rather than after.

// what the bench runs on

Proper engineering kit, not a downloaded scanner

Nothing on this bench breaks encryption. The equipment is here to find keys and to image failing disks safely, and that is the whole of it:

Passware Kit Forensic

The key-recovery suite most of this trade relies on. It lifts keys out of memory captures, hibernation files and security chips, and it runs accelerated attacks against passwords. Locating keys is what it does. The AES underneath stays intact, for this lab and for everybody else.

Memory and hibernation capture

On a machine that still starts, the live key can sometimes be read straight out of RAM or out of the hibernation file. Where that is available it is the quickest lawful way in.

A rack of GPUs

Graphics silicon working through dictionaries and brute-force ranges at many thousands of candidates a second, running day and night until it lands or the odds are called honestly.

Imagers and hardware write-blockers

A deteriorating encrypted disk gets captured whole, still locked, behind a hardware write-blocker. Every step after the capture happens on the duplicate.

Key escrow investigation

The patient hunt through Microsoft sign-ins, company directories, exported key files and whatever paperwork has survived. Most lockouts are solved right here rather than at a keyboard.

Decryption across several formats

BitLocker first, and BitLocker To Go with it, then FileVault 2, LUKS, VeraCrypt and TrueCrypt, plus a long list of password-protected document formats.

// makes and models we see

Encryption we work with

BitLocker on WindowsWindows device encryptionBitLocker To Go volumesVeraCrypt containersApple FileVault 2LUKS and LUKS2 on LinuxTrueCrypt, retired but commonDell Data Protection suitesSymantec and PGP DesktopMcAfee drive encryption

Where the key usually turns up

A sound BitLocker volume with no key stays shut, whatever a confident advertisement implies. Honest work here means hunting the key down: escrow trawls, whatever the TPM will still give up, a password attack at GPU speed, and a plain verdict when the key has genuinely gone for good. BitLocker jobs are £400 + VAT where you supply or we recover the key, and the work sits outside no fix, no fee, so the quote is settled before it starts. Reaching that quote costs nothing. The laptops arrive from accountants and architects in the commercial district, from firms in Chester, and from students and staff at LJMU and the other universities. An engineer picks the phone up here, not a script: 0800 689 0668, Monday to Friday, 9:00am to 5:30pm.

// before it goes in the post

Before it goes in the post — work the drive loose if you can

Send anything that might be key material along with the drive: the 48-digit key if it was ever written down, whichever Microsoft or company account could be holding escrow, exported key files, any PINs, and your honest guesses at the password with the variations you tend to use. Every one of those takes hours off the clock and off the bill. The drive itself travels perfectly well in an anti-static bag, or wrapped in foil if that is what the house can offer. Post it tracked and insured to Manchester Data Recovery, Peter House, Oxford Street, Manchester M1 5AN, or send it by a courier of your own. Nobody is sent out to collect it, and there is no shop to walk into in Liverpool, though the Manchester reception will take it by hand during office hours.

// posting your device in

Sending it in — a padded box and a label

Almost every job on this bench came in by tracked, insured post. It is the calmest way to move a drive that is already struggling, and a parcel handed in anywhere on Merseyside usually reaches the bench the following working day.

Still screwed inside a laptop, tower, MacBook, iMac, server or a CCTV recorder? Take the drive out and post that on its own. We do not strip machines here, and any computer shop will do it in a few minutes. The one job nobody can take on is flash soldered straight to a logic board, as on Apple Silicon Macs and a handful of very slim laptops: if the storage will not unbolt, there is nothing to send.

  • Wrap it well and use a box or padded envelope stiff enough that nothing rattles. Hold on to the cables, caddies and power supplies; they are no help at this end.
  • Fill in the shipping and booking-in form (PDF) — name, number, and a line or two about what went wrong — and drop it in the box beside the drive.
  • Royal Mail Special Delivery gets it here tracked and insured. Book your own courier instead if you prefer; either way the parcel is signed for.
  • Driving over instead? Reception at the Manchester address below accepts drop-offs, Mon–Fri 9:00am–5:30pm. What there is not, anywhere, is a Liverpool counter or a collection service.
// the address on the parcel

Manchester Data Recovery

Manchester Data Recovery
Peter House, Oxford Street
Manchester, M1 5AN

↓ Print the shipping & booking-in form (PDF)

Address it to Manchester Data Recovery. It is roughly 35 miles from Liverpool along the M62 if you fancy the run, and next working day by tracked post if you do not. We ring or email the moment it is booked in, and the free diagnostic closes 2 working days after that.

Not sure what belongs in the parcel? Call 0800 689 0668 before you tape it shut, or step through the free online diagnostic first.

// bitlocker recovery questions

Common questions

Seldom. Most of these turn out to have escrowed a copy at some stage, whether under a Microsoft sign-in, in a company directory, or in a file somebody saved and forgot about, and where no copy was ever made the TPM or a memory image will often yield one, while a weak password tends to fall to graphics cards. The single worst thing anyone can do is reset or reinstall the machine, since either can destroy key material that was still sitting there waiting to be found.
No, and a firm that says it can is a red flag rather than a candidate. Well-implemented AES with the key missing stays shut to everybody, for good, and that is arithmetic rather than opinion. The professional route is to go hunting for the key. Where the password was weak it gives way in short order. Where a strong one has genuinely gone for ever, you get told no on the spot instead of being billed for a long attempt that was never going to land.
Yes, and it happens regularly. Ship the lot as a single consignment, and include whatever the organisation still has on file: recovery keys, account names, directory exports, handover notes. The batch then gets worked through in one pass. What decides the timescale and the cost is how complete that supporting material is, far more than how many drives are in the crate.
No. Turn it off. The sequence runs capture first and decryption second, meaning an image gets taken while the volume is still sealed and the key is applied to that image afterwards, rather than hammering hardware which is already unwell. Forensic-class terms apply, so the £400 + VAT figure is agreed before anyone starts, although working it out costs you nothing.
// related services

Other work this bench takes on

Whenever you're ready, the bench is.

Diagnosis free, one figure written down, and £300 + VAT covers a single drive or SSD. Start online or ring.