Home / Devices / BitLocker

BitLocker Recovery & Decryption Swindon

A blue screen demanding 48 digits nobody ever wrote down, standing between a business and its own files. For Swindon and Wiltshire we trace escrowed keys, bulk-decrypt leavers' drives, and bring failing encrypted disks home through the cipher — never by cracking it, because cracked BitLocker doesn't exist.

Free diagnostic on every bitlocker job. One fixed quote in writing before any work begins.

No fix, no fee all jobs except electronic and mechanical failures, chip level work, DVR and Forensic jobs. Full pricing is on the data recovery cost page.

// top 20 faults we recover from

The twenty ways they fail

Every bitlocker job starts by matching the symptoms to the fault — these twenty cover almost everything that reaches the bench.

Recovery screen every boot

Some hardware or firmware change upset the TPM's measurements — while the data sits whole on the far side of the prompt.

Key never recorded

Most of these end at escrow: a Microsoft account, a workplace directory, an exported file, a printout at the back of a drawer.

Password forgotten

GPU-speed attack retrieves weak and middling passwords; genuinely strong lost ones get told straight.

Hardware swap tripped the lock

A fresh motherboard, a TPM clear, a BIOS flash or a Secure Boot toggle — the protection trips precisely as designed.

Windows reinstalled over it

An encrypted data partition orphaned by a reinstall opens again once its key is traced.

Failing and encrypted at once

The compound emergency: a dying drive under encryption, captured whole while locked, decrypted from the copy.

BitLocker To Go locked

Encrypted sticks and externals open by the same three doors: key, password or forensic recovery.

Leaver-drive estates

Boxes of ex-staff drives decrypted in bulk against the organisation's escrowed key material.

Drive moved between machines

Parted from its TPM, the volume locks — expected behaviour, reversed with the recovery key.

Damaged BitLocker metadata

When the encryption headers themselves corrupt on an otherwise fine drive, they get rebuilt first and decryption follows.

TPM cleared by a firmware update

A UEFI update resets the security chip and Windows wants its 48 digits — recovered via escrow, or from what the TPM still holds.

Dual-boot tripwire

A GRUB install or bootloader change flips the machine into recovery mode precisely as designed.

Encrypted without anyone asking

Modern laptops switch device encryption on silently at first sign-in; owners discover BitLocker only at lockout.

Intune / AD escrow hunts

Keys sitting in company directories get traced and paired with each drive by its identifier across a leaver estate.

'The key doesn't work'

Accounts often hold several keys and the wrong one gets tried — the key ID picks the right one without guesswork.

USB startup key lost

Machines configured to boot from a key file on a stick lock hard when the stick goes missing — escrow and TPM routes remain.

TPM + PIN forgotten

A PIN unused for months evaporates from memory; the recovery key, not the PIN, is the door back in.

Company dissolved, directory gone

Drives from a wound-up business arrive with their Azure AD long deleted — remaining escrow and TPM avenues are worked instead.

Second-hand laptop arrived locked

An eBay purchase encrypted to its previous owner's account — recoverable only with that owner's lawful cooperation.

Decryption interrupted midway

A manage-bde decrypt cut off by power loss leaves the volume half-ciphered — salvaged sector by sector from an image.

Job one: find the key that probably exists

Most 'lost' BitLocker keys aren't lost — they're parked somewhere forgotten. Windows rarely encrypts without escrowing the recovery key first: a Microsoft account, workplace Azure AD or on-prem directory, an exported text file, a printout in a drawer. Modern laptops even switch encryption on silently at first sign-in. So the opening move on any lockout is a methodical sweep of every account and directory the machine ever touched — and it wins more cases than any clever tooling does.

Job two: Passware, used truthfully

The decryption side runs Passware Kit Forensic, the suite the forensic trade itself uses. Understand what it can and cannot do: nobody breaks correctly implemented AES, whatever a confident website claims. Passware recovers keys — from memory captures and hibernation files, out of the TPM, or by GPU-driven attack where a human password protects the volume. The staples are BitLocker and BitLocker To Go; VeraCrypt, FileVault, TrueCrypt and LUKS share the same bench, and estates of leavers' drives are decrypted in bulk for employers routinely.

The double emergency: dying and locked

A drive failing while encrypted demands the right order of operations. Unlock attempts are precisely wrong — each one spends the drive's last healthy hours proving nothing. Instead the drive is imaged cold, still locked, on hardware rigs; decryption then runs against that stable copy with the recovered key. Worth knowing before you commit: BitLocker work is classed as forensic, quoted after the free assessment and settled before the work starts.

// the equipment we use

A professional lab, not software guesswork

BitLocker recovery is key-finding plus disciplined imaging — never code-breaking — and the bench mirrors that:

Passware Kit Forensic

The forensic trade's standard decryption suite: keys pulled from memory captures, hibernation files and the TPM, or reached by accelerated password attack. It finds keys — the AES itself is never broken.

Memory & hibernation capture

On a machine that still starts, the live key can sometimes be captured straight out of RAM or hibernation data — often the quickest legitimate door into a locked volume.

GPU acceleration cluster

Racks of NVIDIA and AMD cards driving dictionary and brute-force password runs at tens of thousands of guesses each second.

Hardware imagers + write-blockers

A sick encrypted drive gets captured while still locked, write-blocked throughout; decryption afterwards touches only the stable copy.

Key-escrow investigation

A patient trawl of Microsoft accounts, workplace directories, exported key files and paper records — the ground where most lockouts are actually won.

Multi-format decryption

Past BitLocker and BitLocker To Go, the bench opens FileVault, VeraCrypt, TrueCrypt and LUKS, plus hundreds of password-protected file types.

// manufacturers & models

Encryption formats we handle

BitLockerBitLocker To GoWindows Device EncryptionFileVault 2VeraCryptTrueCryptLUKS / LUKS2PGP / SymantecMcAfee Drive EncryptionDell Data Protection

Where your key really turns up

Sound BitLocker minus its key stays sealed — end of story, whoever advertises otherwise. Real recovery is key recovery, which is exactly what Passware Kit Forensic does on this bench, with a straight verdict when the key is truly gone. As forensic-classed work it's settled up front once quoted; the assessment beforehand costs nothing.

// before you post it

Sending it in — remove the drive if you can

Include with the drive whatever key material exists: a 48-digit recovery key if one was ever saved, whichever Microsoft or work account might hold the escrow, exported key files, PINs and best-guess passwords. Each item trims hours and pounds off the job. A removed drive travels perfectly well in an anti-static bag or a sheet of kitchen foil.

// getting your device to us

Post or courier your device — it's simple

Most customers post or courier their media to us.

Sending a drive from a computer, laptop, MacBook, iMac, CCTV / DVR or server? Please remove the internal hard drive or SSD and send us just the drive — we don't provide an internal drive-removal service. We don't recover storage soldered to a motherboard (e.g. Apple Silicon Macs and some thin laptops) — only drives that can be removed and sent to us.

  • Wrap the device in bubble wrap or a padded envelope — no need to include cables or power supplies.
  • Print and enclose the booking-in & shipping form (PDF) with your name, phone number and a brief description of what happened.
  • Send by Royal Mail Special Delivery or any tracked courier for full insurance in transit.
  • Prefer to hand it over in person? You can drop it in at reception at the address shown, Mon–Fri 9:00am–5:30pm.
// send your device to your nearest location

Oxford Data Recovery

John Eccles House, Oxford Science Park
Robert Robinson Avenue, Littlemore
Oxford, OX4 4GP

↓ Print the booking-in & shipping form (PDF)

Mark the package for the attention of Oxford Data Recovery and we'll call you as soon as we diagnose your media.

Not sure what to send? Call 0800 689 0668 first or use the free online diagnostic.

// bitlocker recovery questions

Common questions

Usually not. Keys hide in Microsoft accounts, Azure AD and exported files more often than owners believe, and where one truly never existed, it can often be pulled from the TPM or from a memory image, with weak passwords attacked at GPU speed. Just don't reset or reinstall anything — that genuinely can destroy key material.
No — and treat anyone claiming otherwise as a warning sign. Sound AES minus its key is mathematically closed to everyone. Legitimate practice recovers the key instead; weak passwords fall quickly, strong lost ones earn you an honest no.
Very. Ship the drives together with every key, account name and directory detail the organisation holds, and they're decrypted in bulk. How complete your key material is drives the speed and the price more than anything else.
Stop entirely and power it down. The safe order is: capture the drive while still locked, then decrypt that capture — never unlock-and-pray on sick hardware. Being forensic-classed, the job is paid up front once quoted; the assessment itself remains free.
// related services

Also recovered here

Ready when you are.

Free diagnostic, fixed quote, no fix no fee — start now or call the freephone.