A blue screen demanding a 48-digit key you've never seen, guarding a drive that holds everything. We recover BitLocker-locked drives for homes and businesses across Sheffield — finding keys, decrypting estates of drives, and rescuing failing disks through their encryption.
Free diagnostic on every bitlocker job. Fixed quote before any work — and no fix, no fee.
Every bitlocker job starts by matching the symptoms to the fault — these ten cover almost everything that reaches the bench.
A hardware, firmware or update change tripped BitLocker into recovery mode — the data is intact, the key just needs finding or recovering.
The key was escrowed somewhere (a Microsoft or work account, a file, a printout) or can be recovered from the TPM or a memory image.
Where a password protects the volume, accelerated recovery can often retrieve it — fast if it's weak, honest odds if it's strong.
A new motherboard, TPM clear, BIOS update or Secure Boot change invalidates the seal and forces the recovery key.
A reinstall can strand an encrypted data partition — recoverable with the key or through key recovery.
The compound case: a dying encrypted drive, imaged gently in its locked state before any decryption is attempted.
Encrypted removable media locked the same way — opened with the key, password or forensic recovery.
Bulk decryption of encrypted drives from leavers and retired machines against escrowed keys.
BitLocker locks when a drive leaves its original machine — expected behaviour, recoverable with the key.
Damaged encryption headers on an otherwise healthy drive — reconstructed before decryption.
BitLocker recovery is really two disciplines. The first is finding keys people didn't know they had: BitLocker rarely activates without escrowing a recovery key somewhere — a Microsoft account, an organisation's Azure AD or Active Directory, an exported file or a printout. Modern Windows laptops switch device encryption on silently and save the key the first time you sign in, so the answer to most lockouts is a methodical hunt through every account the machine ever used. The second discipline is the hard one: a drive that is failing and encrypted at the same time.
For business drives and lawful investigations we run Passware Kit Forensic, the industry-standard decryption suite. It doesn't break BitLocker — properly implemented AES encryption without the key is designed to be unbreakable, and any company claiming otherwise is misleading you. What Passware does is recover the key: extracting it from a captured memory image or hibernation file, pulling it from the TPM, or mounting GPU-accelerated dictionary and brute-force attacks against the password where one protects the volume. We decrypt BitLocker and BitLocker To Go, and the same suite handles FileVault, VeraCrypt, TrueCrypt and LUKS if you have those too. Businesses regularly send us estates of ex-staff and retired-machine drives to decrypt in bulk against escrowed keys.
The compound case is the one we see most from businesses: a BitLocker drive that's also failing — bad sectors sitting in encrypted space, a laptop that crashed into recovery-key purgatory because the disk beneath it is sick. Order of operations is everything. The drive is imaged gently in its encrypted state on hardware imagers first, then the stable image is decrypted with the recovered key — never the other way round. Every unlock attempt on a failing encrypted drive is an expensive read that spends its remaining life, which is why the honest advice is to stop and send it in.
BitLocker work is key recovery and careful imaging — not code-breaking. The bench reflects that:
The industry-standard decryption suite — recovers BitLocker keys from memory images, hibernation files, the TPM, or the password via accelerated attack. It recovers the key; it does not break the AES.
Where a machine can be run, the live encryption key is captured from RAM or the hibernation file — often the fastest route into a locked volume.
NVIDIA and AMD GPUs and rainbow tables drive dictionary and brute-force attacks against BitLocker passwords at tens of thousands of guesses per second.
Failing encrypted drives are imaged in their locked state through write-blockers first — the original is never altered, and decryption runs on the copy.
Methodical recovery of keys escrowed to Microsoft accounts, Azure AD / Active Directory, exported files and printouts — where most lockouts are actually solved.
The same suite opens BitLocker To Go, FileVault, VeraCrypt, TrueCrypt and LUKS volumes, plus 400+ password-protected file types.
Properly implemented BitLocker is unbreakable without the key — reputable recovery means recovering the key, not cracking the encryption. We use Passware Kit Forensic and tell you honestly what's achievable.
Sending a BitLocker drive for decryption? Include every scrap of key material you hold — the 48-digit recovery key, the Microsoft or work account it may be escrowed to, any exported key files or PINs. The more you can supply, the faster and cheaper the decryption. For a drive removed from a machine, an anti-static bag or foil wrap is fine.
Most customers post or courier their device to us — it arrives next morning, and the free diagnostic starts the day it lands.
Sending a drive from a computer, laptop, MacBook, iMac or server? Please remove the internal hard drive or SSD and send us just the drive — we don't provide an internal drive-removal service. If the storage is soldered in (e.g. Apple Silicon), call us first on 0800 689 0668.
↓ Print the booking-in & shipping form (PDF)
Mark the package for the attention of Leeds Data Recovery and we'll call you as soon as we diagnose your media.
Not sure what to send? Call 0800 689 0668 first or use the free online diagnostic.
Free diagnostic, fixed quote, no fix no fee — start now or call the freephone.