A blue screen wanting forty-eight digits, and nobody in the building with any idea where those digits went. That is where most of these start, in a house or an office that never chose to encrypt anything in the first place. The work covers tracing keys that were escrowed and then forgotten, opening batches of machines left behind by staff who have moved on, and getting data off encrypted disks that are failing, by going through the cipher rather than around it. Nothing is cracked here. BitLocker does not crack.
Every BitLocker that arrives here is examined at no charge. The figure quoted afterwards is put in writing and settled before anybody reaches for a screwdriver: £400 + VAT on a BitLocker volume or any other encrypted disk.
Logical recoveries carry no fix, no fee. The named exceptions to it are electronic and mechanical failures, chip-level work, DVR jobs and forensic jobs; physical work takes 50% up front. The five bands are set out in full on the data recovery cost page.
Tracing a symptom back to the failure underneath it is where the real work begins, and these thirty account for all but a handful of the boxes opened at the Cambridge bench. A fault missing from the list is not an unfamiliar one — describe it on the telephone and you will get a straight view of the odds before you spend anything on postage.
Windows has decided the machine is no longer the machine it encrypted itself against, and it wants the forty-eight digits before it will go any further. Something changed: firmware, a mainboard, a boot order, a TPM that was cleared. The volume behind the screen is intact and the key almost always still exists somewhere.
The commonest opening line on this page. Windows very rarely encrypts a volume without escrowing a copy of the key first, so the exercise is finding where it went rather than defeating the cipher. A Microsoft account, a company directory, a printed sheet, a text file saved during setup and never opened since.
Recent Windows laptops enable device encryption by themselves the first time somebody signs in with a Microsoft account. The household finds out on the day a firmware update triggers the recovery screen. The key is usually sitting against that Microsoft account and can be retrieved in a few minutes.
The order of work changes here and retyping the key is not the first step. Each attempt spends some of the reliable running time the disk still has and proves nothing either way. The disk is imaged cold with the volume still sealed, and the key is applied to the copy once it has been found.
Ordinary employer work and a regular arrival. Send the whole consignment together with everything the organisation still holds: recovery keys, account names, directory exports, handover notes. The batch is processed in one pass, and how long it takes depends far more on that supporting material than on the number of drives.
Removable media encrypted with BitLocker behaves the same way as a fixed volume and is worked identically. Where a password was set and remembered, this is straightforward. Where neither the password nor a recovery key exists, the honest answer is the same one that applies to any correctly implemented cipher.
Firmware updates change the measurements a TPM seals the key against, and the machine then refuses to release it. Nothing is broken. The recovery key opens it, and where the key cannot be found the TPM itself is sometimes still holding usable material.
The key was sealed to a chip that is now in a bin, and the volume moved to a machine that has never seen it. A recovery key is the only route from here, which is exactly what recovery keys exist for. Where the old board still exists, do not dispose of it.
Clearing a TPM is offered as a fix for unrelated problems and it destroys sealed key material immediately. If a recovery key was escrowed, nothing is lost. If it was not, that action is frequently the point at which a recoverable volume became a permanently closed one.
Resetting or reinstalling Windows to clear the recovery prompt destroys key material that was still on the machine waiting to be found. It is the single most damaging thing to do at this stage, and it is what a good number of people try first. Stop before doing either.
Company-managed devices escrow their keys into the directory, and a great many lockouts end with an administrator finding the entry within minutes. Where the tenant itself has been lost, or the administrator account has gone with a departed employee, the position is harder and gets assessed honestly.
Older domain environments store recovery information against the computer object in Active Directory, and it survives long after the machine has been retired. That is a well-worn route and one worth checking before anything more involved is attempted.
A user-chosen password is the one part of this that yields to equipment, because people choose from a much smaller space than the cipher allows. Graphics cards are put to that, and a weak password falls quickly. A genuinely strong one does not, and that is said at the start rather than after an invoice.
Keys live in memory while a volume is mounted, and hibernation writes memory to disk. A hibernation file from a session when the volume was open frequently contains usable key material. That is one reason a machine should not be reset before it has been looked at.
The volume travels with its own encryption and does not open in a different computer without the key. That is the system working as designed rather than a fault, and it surprises people regularly. Send the drive, and send whatever key material the organisation still holds with it.
Both are properly implemented and neither falls to effort. What can be attempted is the password itself, where a person chose it, and where a hint or a partial recollection narrows the field. Where a strong passphrase is genuinely lost, that answer is given immediately.
Apple's full-disk encryption is handled here the same way, with the same order of work. The recovery key is frequently escrowed against an Apple account or was written down during setup. Where it can be located, the volume opens. Where it cannot, nobody opens it.
LUKS keeps several key slots and it is worth checking every one of them, because an old passphrase or a key file left on another machine will do just as well as the one that has been forgotten. Where the header itself is damaged, a backup header is sometimes recoverable from the disk.
Many drives encrypt everything they store as a matter of course with the key held in the controller. That is invisible until the controller stops, at which point reading the flash or the platters gives back perfectly recovered ciphertext. Where the controller can be revived the data comes back.
The array comes back first and the encryption is dealt with afterwards, in that order and not the other way round. A key or a passphrase is still needed. Array work starts at 500 pounds + VAT and the encryption handling is part of the same job rather than a second one.
BitLocker encrypts in the background and a machine that was switched off partway leaves a volume half sealed and half plain. That is a more complicated object than either state on its own, and it is worked from an image with both regions handled separately.
Recovery keys are tied to a specific protector, and a key from a different machine or a different volume on the same machine will be rejected. Send everything the organisation holds rather than the one that seemed most likely, because matching keys to volumes is quick here and guessy at your end.
A TPM that is failing, or a boot order that changes depending on what is plugged in, produces a machine that sometimes asks and sometimes does not. That is a warning. Copy the contents off while it is still opening rather than waiting for the day it stops.
Where the encryption is done by the enclosure rather than the disk, the disk on its own reads as noise. Send the whole unit, cable included, because the key is on the bridge board. This is the same rule that governs a WD My Passport and it is worth knowing before you open anything.
Regular work, and it needs the paperwork to be right as well as the technical side. Where the material is going to be used in a dispute, say so at the start, because that makes it forensic work at 800 pounds + VAT with a written report rather than ordinary encrypted drive work.
The two get run together and they are entirely different problems. Ransomware encrypts files with a key the attacker holds. BitLocker encrypts a volume with a key you had. Ransomware is priced as ordinary media, 300 pounds + VAT for a drive and from 500 for an array, and it is not forensic work.
An old encrypted disk in a drawer has all the ordinary age-related problems on top of the key problem. It gets imaged first, exactly as any old disk would be, and the key question is dealt with afterwards on the copy.
BitLocker keeps metadata copies at more than one point on the volume, and a damaged primary header does not always mean a lost volume. Recovering the metadata from a secondary location is a standard step and it works more often than the error message suggests.
Say so on the booking form, including what was run and for how long. Several tools write to the volume they are working on. It rarely rules a recovery out and it always changes the order of the work, and the assessment costs nothing whether it is the first attempt or the third.
Not a fault, a priority. A locked accounts drive or a batch of machines nobody can open stops an organisation working just as effectively as a failed array. Say it on the call and the job moves up the list. The free assessment still takes two working days from arrival.
The word people use is lost, and what they almost always mean is mislaid. Windows very seldom seals a volume without putting a copy of the key somewhere first, and the list of places it goes is short and well travelled: the household Microsoft account, an employer's Entra or Azure AD tenant, an older on-premises directory where it hangs off the computer object, a text file saved during setup that nobody has opened since, and a sheet of paper printed during a handover and filed in a drawer. Modern laptops make the problem worse by turning device encryption on by themselves the first time somebody signs in, so an entire household can find itself shut out of protection nobody chose. Every one of these jobs therefore opens with the same unexciting task: working methodically through each account and directory that machine has ever been attached to. It is slow and it is dull and it finishes more of these cases than any piece of software in the building. The one action that turns a solvable case into a permanent one is resetting or reinstalling the machine to clear the prompt, because either can destroy key material that was still sitting on the disk waiting to be found.
The tool used here is Passware Kit Forensic, the same thing the evidential end of the trade uses, and it is worth describing accurately rather than dressing up. It makes no attempt on the arithmetic. Correctly implemented AES is not beaten by budget, patience or equipment, whatever some website is claiming this month. What the software does instead is hunt for keys: pulling them out of hibernation files and captured memory, coaxing them from a TPM, or turning a rack of graphics cards loose on a password a human being invented, in the cases where a chosen password is the only thing in the way. Human passwords come from a far smaller pool than the cipher permits, and a weak one falls in hours. A genuinely strong passphrase that has truly gone does not fall at all, and you hear that on the day rather than after a fortnight of billed effort. The same equipment handles VeraCrypt, FileVault, TrueCrypt and LUKS, and clearing a crate of drives left behind by people who have moved on is routine employer work rather than an unusual request.
Where the disk is failing as well as locked, typing the key is not the first move and should not be the tenth. Each attempt burns a share of whatever dependable running time is left in the mechanism and settles nothing about whether the key is right. The correct sequence is the other way round: take a cold image with the volume still sealed, using equipment designed for reading media that misbehaves, and then apply the key to that duplicate once one has been located. A good number of the encrypted jobs that reach this bench have precisely that shape, which is a disk on its way out, a volume that will not open, and somebody who has spent a fortnight entering the same forty-eight digits into hardware that was never going to open. On price: encrypted drive work is £400 + VAT, the same band as a recorder disk. Encryption is not one of the no fix, no fee exclusions. Those are electronic and mechanical failures, chip-level work, DVR jobs and forensic jobs, so where a drive is both sealed and physically failing it is the mechanical half that carries the 50% deposit.
Two things happen on this bench and they are worth distinguishing. One is finding a key that already exists somewhere, which is unglamorous work and closes most of these jobs. The other is reading a failing disk without ever asking it to decrypt anything, which is what the imaging equipment is for.
This is what the forensic end of the industry uses and it makes no attempt on the mathematics. Its purpose is finding keys: pulling them out of hibernation files and memory captures, retrieving them from a TPM, and putting graphics cards to a password a person chose. Nobody beats correctly implemented AES, whatever a website claims this month.
Microsoft accounts, Entra and Azure AD tenants, on-premises Active Directory, MDM records and the text file that was saved during setup and forgotten. Slow, dull work that closes more of these jobs than any piece of specialist software does.
A disk that is both encrypted and failing is imaged cold, ciphertext and all, using hardware built for reading unreliable media. The key is applied to the copy afterwards. Entering forty-eight digits into a struggling disk spends reads that cannot be replaced.
Where the only barrier is a password a person invented, that is a much smaller space than the cipher allows and it is attacked directly. Dictionary, rule-based and mask attacks informed by whatever the owner can remember about the shape of it.
Keys live in memory while a volume is open, and hibernation writes memory to disk. Extracting key material from a hibernation file or a captured memory image is a well-established route and one more reason not to reset a locked machine before it has been examined.
VeraCrypt, TrueCrypt, FileVault, LUKS and BitLocker To Go, together with vendor encryption in external enclosures and self-encrypting drives. The approach is the same in every case: find the key, or say plainly that it cannot be found.
Encrypted drive work is 400 pounds + VAT, the same band as a recorder disk, and the assessment in front of it costs nothing and closes two working days after the drive is booked in. Encryption work is not on the no fix, no fee exclusion list, and neither is ransomware; the published exclusions are electronic and mechanical failures, chip-level work, recorder jobs and forensic jobs. Where a drive is both encrypted and physically failing, the mechanical part of it takes 50% up front because that part is an exclusion. Two things are worth saying without decoration. The first is that a properly implemented cipher with the key genuinely gone stays closed permanently, and any firm telling you otherwise should be crossed off rather than shortlisted. The second is that in most of these cases the key has not been destroyed at all, only filed somewhere nobody has looked yet, which is why the free assessment starts with a sweep of every account and directory the machine has ever been associated with.
Send the drive, and send everything you still hold that might be a key. Recovery key printouts, screenshots, the text file saved during setup, directory exports, account names, MDM records, handover notes from whoever left. All of that is worth more to this job than any equipment on the bench, and matching keys to volumes takes minutes here. Do not reset the machine and do not reinstall Windows in an attempt to clear the prompt, because either can destroy key material still sitting on the disk. If the drive is encrypted by its enclosure rather than by Windows, send the whole unit with its cable. Post it tracked and insured to Cambridge Data Recovery, Compass House, Vision Park, Chivers Way, Cambridge CB24 9AD, or bring it in: the lab is two minutes off the A14 at Junction 32 with parking outside the door, about seventy miles from Leicester on the M1 south to Junction 19 and then the A14 east. Reception takes drop-offs Monday to Friday, 9:00am to 5:30pm. Nothing is collected. Ring 0800 689 0668 if a batch is large enough to need arranging first.
The post office does most of the work of getting a job here. A drive that is already unwell travels better boxed and insured than rattling around a car for a day of errands, and something dropped into a Leicestershire postbox this afternoon is generally logged in at Cambridge tomorrow.
The general rule is the drive travels and the machine stays behind — out of the laptop, out of the tower, out of the iMac, out of the recorder under the counter. This bench does not dismantle equipment, and a repair shop will do it while you wait. Three things are the other way round, and getting them wrong costs you the recovery: an external drive stays sealed in its own case, a NAS comes as a complete unit, and a WD My Passport or My Book travels whole with its cable, because on those the encryption key is held on the bridge board rather than on the disk — separate the two and the data becomes unreadable even to us. A Fusion Mac needs both of its drives, each labelled. The one thing nobody can work round is flash soldered onto the mainboard, as on Apple Silicon machines: if it will not come off, there is nothing to post.
↓ Print the shipping & booking-in form (PDF)
Address it to Cambridge Data Recovery. It is about seventy miles from Leicester if you fancy driving it — M1 south to Junction 19, then the A14 east — and the lab is two minutes off Junction 32 with parking at the door. Posting costs you a stamp and a day instead. Whichever you choose, you hear from us the moment it is booked in, and the free diagnostic closes two working days after that.
Not certain what belongs in the box? Ring 0800 689 0668 before you tape it up, or let the free online diagnostic ask the questions for you.
The examination is free, one written figure follows it, and the band covering this page is £400 + VAT on a BitLocker volume or any other encrypted disk.