A blue screen demanding 48 digits nobody ever wrote down, standing between a business and its own files. For Swindon and Wiltshire we trace escrowed keys, bulk-decrypt leavers' drives, and bring failing encrypted disks home through the cipher — never by cracking it, because cracked BitLocker doesn't exist.
Free diagnostic on every bitlocker job. One fixed quote in writing before any work begins.
No fix, no fee all jobs except electronic and mechanical failures, chip level work, DVR and Forensic jobs. Full pricing is on the data recovery cost page.
Every bitlocker job starts by matching the symptoms to the fault — these twenty cover almost everything that reaches the bench.
Some hardware or firmware change upset the TPM's measurements — while the data sits whole on the far side of the prompt.
Most of these end at escrow: a Microsoft account, a workplace directory, an exported file, a printout at the back of a drawer.
GPU-speed attack retrieves weak and middling passwords; genuinely strong lost ones get told straight.
A fresh motherboard, a TPM clear, a BIOS flash or a Secure Boot toggle — the protection trips precisely as designed.
An encrypted data partition orphaned by a reinstall opens again once its key is traced.
The compound emergency: a dying drive under encryption, captured whole while locked, decrypted from the copy.
Encrypted sticks and externals open by the same three doors: key, password or forensic recovery.
Boxes of ex-staff drives decrypted in bulk against the organisation's escrowed key material.
Parted from its TPM, the volume locks — expected behaviour, reversed with the recovery key.
When the encryption headers themselves corrupt on an otherwise fine drive, they get rebuilt first and decryption follows.
A UEFI update resets the security chip and Windows wants its 48 digits — recovered via escrow, or from what the TPM still holds.
A GRUB install or bootloader change flips the machine into recovery mode precisely as designed.
Modern laptops switch device encryption on silently at first sign-in; owners discover BitLocker only at lockout.
Keys sitting in company directories get traced and paired with each drive by its identifier across a leaver estate.
Accounts often hold several keys and the wrong one gets tried — the key ID picks the right one without guesswork.
Machines configured to boot from a key file on a stick lock hard when the stick goes missing — escrow and TPM routes remain.
A PIN unused for months evaporates from memory; the recovery key, not the PIN, is the door back in.
Drives from a wound-up business arrive with their Azure AD long deleted — remaining escrow and TPM avenues are worked instead.
An eBay purchase encrypted to its previous owner's account — recoverable only with that owner's lawful cooperation.
A manage-bde decrypt cut off by power loss leaves the volume half-ciphered — salvaged sector by sector from an image.
Most 'lost' BitLocker keys aren't lost — they're parked somewhere forgotten. Windows rarely encrypts without escrowing the recovery key first: a Microsoft account, workplace Azure AD or on-prem directory, an exported text file, a printout in a drawer. Modern laptops even switch encryption on silently at first sign-in. So the opening move on any lockout is a methodical sweep of every account and directory the machine ever touched — and it wins more cases than any clever tooling does.
The decryption side runs Passware Kit Forensic, the suite the forensic trade itself uses. Understand what it can and cannot do: nobody breaks correctly implemented AES, whatever a confident website claims. Passware recovers keys — from memory captures and hibernation files, out of the TPM, or by GPU-driven attack where a human password protects the volume. The staples are BitLocker and BitLocker To Go; VeraCrypt, FileVault, TrueCrypt and LUKS share the same bench, and estates of leavers' drives are decrypted in bulk for employers routinely.
A drive failing while encrypted demands the right order of operations. Unlock attempts are precisely wrong — each one spends the drive's last healthy hours proving nothing. Instead the drive is imaged cold, still locked, on hardware rigs; decryption then runs against that stable copy with the recovered key. Worth knowing before you commit: BitLocker work is classed as forensic, quoted after the free assessment and settled before the work starts.
BitLocker recovery is key-finding plus disciplined imaging — never code-breaking — and the bench mirrors that:
The forensic trade's standard decryption suite: keys pulled from memory captures, hibernation files and the TPM, or reached by accelerated password attack. It finds keys — the AES itself is never broken.
On a machine that still starts, the live key can sometimes be captured straight out of RAM or hibernation data — often the quickest legitimate door into a locked volume.
Racks of NVIDIA and AMD cards driving dictionary and brute-force password runs at tens of thousands of guesses each second.
A sick encrypted drive gets captured while still locked, write-blocked throughout; decryption afterwards touches only the stable copy.
A patient trawl of Microsoft accounts, workplace directories, exported key files and paper records — the ground where most lockouts are actually won.
Past BitLocker and BitLocker To Go, the bench opens FileVault, VeraCrypt, TrueCrypt and LUKS, plus hundreds of password-protected file types.
Sound BitLocker minus its key stays sealed — end of story, whoever advertises otherwise. Real recovery is key recovery, which is exactly what Passware Kit Forensic does on this bench, with a straight verdict when the key is truly gone. As forensic-classed work it's settled up front once quoted; the assessment beforehand costs nothing.
Include with the drive whatever key material exists: a 48-digit recovery key if one was ever saved, whichever Microsoft or work account might hold the escrow, exported key files, PINs and best-guess passwords. Each item trims hours and pounds off the job. A removed drive travels perfectly well in an anti-static bag or a sheet of kitchen foil.
Most customers post or courier their media to us.
Sending a drive from a computer, laptop, MacBook, iMac, CCTV / DVR or server? Please remove the internal hard drive or SSD and send us just the drive — we don't provide an internal drive-removal service. We don't recover storage soldered to a motherboard (e.g. Apple Silicon Macs and some thin laptops) — only drives that can be removed and sent to us.
↓ Print the booking-in & shipping form (PDF)
Mark the package for the attention of Oxford Data Recovery and we'll call you as soon as we diagnose your media.
Not sure what to send? Call 0800 689 0668 first or use the free online diagnostic.
Free diagnostic, fixed quote, no fix no fee — start now or call the freephone.