Taking work now — the first look is freeDrives posted in from anywhere in the UK, or handed in at ten drop-off pointsQuicker still, give us a ring:0800 6890668
BLKBitLocker Data Recovery 0800 6890668 Price my job

Password protector · data drive · To Go · dictionary and mask attack · GPU · no backdoor

BitLocker password recovery. A password you set, and the honest truth about getting past it when it is gone.

A password protector is the kind you meet on a fixed data drive or a BitLocker To Go stick: no TPM involved, just a password you set and type to unlock the drive. Forget it and, as always with BitLocker, the 48-digit recovery key opens the drive if you have it. The interesting and honest part is what happens when there is no recovery key and the password is genuinely gone, because the answer depends entirely on the password you chose. BitLocker deliberately makes password attacks slow: its key derivation runs the password through a heavy, salted, million-round transformation, so even a rig of fast GPUs tries only a few thousand candidates a second, not billions. That means a human-memorable password, a word, a name, a date, a familiar pattern, can often be recovered by a dictionary or mask attack that tries likely candidates, especially when you can tell us roughly what it was like. A long, random, unguessable password cannot be recovered, by us or anyone, because there is no backdoor and no feasible brute force. We take these drives only for their owners, behind proof of ownership, and the free look is an honest read of which side of that line your password falls.

Owner-only, proof requiredFree first look£800 + VAT, one diskNo fix, no fee on the balance

Rather talk it through? An engineer answers the bench line
0800 6890668

Stop before you reinstall or reformat anything. If the machine is at the BitLocker recovery screen, the data is intact behind the key; reinstalling Windows, reformatting the drive or clearing the TPM again will not get you in and can overwrite what is there. Do not keep typing the wrong key until a device locks you out. If the machine is still running and unlocked, do not shut it down before you have read the lost-password pages. Find your recovery key first, and send nothing until you have.

The recovery key first; the password attack second.

Even on a password-protected drive, a 48-digit recovery key was usually created when BitLocker was turned on, and it opens the drive without the password. Look for it first: a saved text file or printout, a .BEK or key file on a USB stick, a Microsoft account, or an organisation's Entra ID or Active Directory for a work drive. The finder page covers each. If you have the key, you do not need a password attack at all.

With no key and a forgotten password, the job becomes an attack on the password, and this is where honesty matters most. BitLocker's password key derivation is intentionally expensive, so attacks are slow and only weak passwords fall. A dictionary attack tries words, names and leaked passwords; a mask attack tries structured guesses when you remember the shape, say eight characters ending in two digits; a rule-based attack mutates likely candidates. The more you can tell us about the password, its length, whether it was a word or a phrase, numbers you tend to use, the better the odds and the shorter the time.

If the password was long and random, none of this helps, and we will say so. There is no master password, no Microsoft backdoor, and no feasible way to brute-force a strong BitLocker password. Anyone who tells you they can reset or recover a strong BitLocker password without the key is misrepresenting the cryptography.

Why a weak password falls and a strong one does not.

The slowness is by designBitLocker runs a password through a salted key-derivation function with around a million rounds before it becomes a key. That is deliberate: it caps how fast anyone can guess. On strong GPU hardware the rate is a few thousand candidates a second, against the billions a second that weak hashes allow. Slowness is the whole defence, and it is why only weak passwords are recoverable.
A human password leaves cluesPeople choose passwords they can remember: a word, a pet's name, a birthday, a keyboard pattern, a familiar phrase with a number on the end. A dictionary or mask attack built around those patterns, and around whatever you can tell us, tries the likely candidates first and often lands within a feasible time.
What you remember changes everythingThe difference between recoverable and not is often what you can tell us. Length, whether it was one word or several, capital letters, numbers you reuse, the language it was in: each narrows the search enormously. A password you remember the shape of is far more recoverable than one you recall nothing about.
A strong random password is a dead endA long string of random characters has no pattern to exploit and too many combinations to try at a few thousand a second. It cannot be recovered without the key, and no legitimate service can claim otherwise. We would rather tell you that free than take money for an attack that cannot finish.

What you see, and what is behind it.

Describe yours to us →
What you see What is usually behind it Where that leaves you
Forgotten the drive password, recovery key heldThe key opens it without the passwordEnter the recovery key; no attack needed
Forgotten a simple or familiar password, no keyA weak protector with patterns to exploitOften recoverable by dictionary or mask attack
Forgotten password, you remember its shape, no keyA narrowed search spaceGood odds with a mask built from what you recall
Long random password, no keyNo pattern, too many combinationsNot recoverable; no backdoor; we say so
To Go stick also unreadable or failingA physical fault plus the passwordImaged first, then the password attacked on the clone

From the drive arriving to your files going back.

Work we have closed →
01

Logged the day it lands, and the first look costs nothing Free

A number goes on the parcel and the drive the day it is opened, matched to your enquiry by the booking sheet inside. Before anything is read we check the proof of ownership you sent. The drive is then connected through a write blocker, read-only, and examined: whether it is a healthy drive behind a lost key, or a failing drive behind a known key, is settled here, and so is whether what you want is possible. That first look is free, and you may stop at it owing nothing.

Nothing to pay for lookingProof of ownership checked firstRead-only, nothing written to the drive
02

Imaged at the sector level, before anything else

A drive that answers at all is imaged in full on a hardware imager, behind a write blocker, weak areas last, with a map kept of what could not be read. The image is a copy of the encrypted sectors, so it is useless to anyone without your key, which is a privacy gain in itself. Every later step is done on the image. The original drive is never decrypted, never written to, and never worked on directly.

Sector by sector, behind a write blockerNothing written to the original
03

The physical fault repaired on the clone, when there is one

A drive that has failed, that reads slowly or that drops out is stabilised and imaged in passes; a mechanically failed disk is repaired and read on the bench, a dead SSD controller read at the chip level, before any decryption is attempted. The aim at this stage is one clean image of the encrypted volume to decrypt from. Where the drive is healthy and the problem is only the key, this stage is skipped.

Mechanical and chip-level work where neededOne clean encrypted image to work from
04

The image decrypted with your key or password

With your recovery key, recovery password or the drive's password, the image is unlocked: the protector releases the Volume Master Key, the VMK releases the Full Volume Encryption Key, and the volume is decrypted from the clone. Where the metadata or header is damaged, repair-bde and the key package rebuild it at the block level onto a separate target. Where the key is lost but a memory image or hibernation file is available, the Volume Master Key is extracted from it with Passware. Without a key, a password to attack, or a memory capture, the volume cannot be opened, and you are told so at the free look.

Protector → VMK → FVEK → volumeDecrypted from the clone, never the original
05

The file system rebuilt, and the list before the bill

Once the volume is open it is an ordinary NTFS or exFAT file system, and any damage in it is repaired on the image and the files recovered. What was recovered is listed for you first, and only then does a bill exist. The files go home on fresh media. The original drive is returned, or securely destroyed at your request; we never send the key and the data by the same route.

Files listed before any invoiceFresh media, supplied with the job3–7 days at the bench

From the bench

  • Tell us everything you remember about the password. Length, words, numbers, language, the rough shape: it is the single biggest factor in whether an attack succeeds and how long it takes.
  • Look for the recovery key even on a password drive. One was usually made at setup, and it skips the attack entirely.
  • Do not trust any promise to reset a strong password. There is no backdoor; a strong BitLocker password without the key is genuinely unrecoverable.

A few thousand guesses a second is all BitLocker's key derivation allows on strong hardware, which is why only weak passwords fall.

One job, followed all the way through.

UK · BLK-2026-0703JOB LOGGED ✓

A BitLocker To Go backup drive whose owner had set a password years before and remembered only that it was a phrase about a holiday, with family photographs that existed nowhere else

There was no recovery key. With ownership confirmed, we built a mask and dictionary attack around what the owner remembered: a short phrase, a place name they gave us, and the way they tended to add a year. On GPU hardware the attack found the password within two days. The drive mounted and the photographs were copied off. Had they remembered nothing and the password been random, the answer would have been no.

Password found from what the owner remembered2 days on GPU hardware
Illustrative example — replace with a genuine case

What helps, and what harms.

Do this much first

  • Look for the recovery key first; it skips the attack
  • Tell us everything you remember about the password
  • Say how long it was and whether it was a word or a phrase
  • Send proof the drive is yours

What sets us back

  • Paying anyone who promises to reset a strong password
  • Assuming a forgotten password always means lost data
  • Reformatting a To Go stick to make it usable again
  • Expecting a random password to be recoverable; it is not
We recover BitLocker drives for the people who own them. Before any work begins we ask for proof that the drive is yours or that you are authorised to have it recovered: a purchase receipt, the device serial, a letter on company letterhead for a work machine, or written authorisation from the owner, together with photo ID and a signed authorisation. It is a condition of the work, not a formality, and it is what keeps the service on the right side of the Computer Misuse Act. A drive with no proof of ownership is returned unread.

Questions answered before you commit.

Can you recover a forgotten BitLocker password?

If it was human-memorable, often: a dictionary or mask attack built around likely patterns, and around what you remember, recovers weak passwords within a feasible time. If it was long and random, no, and no legitimate service can, because BitLocker's slow key derivation makes brute force infeasible and there is no backdoor.

Is there a master password or backdoor for BitLocker?

No. There is no Microsoft master password and no backdoor. The only things that open a BitLocker drive are a protector you can unlock, the 48-digit recovery key, or, for a weak password, a successful password attack. Anyone claiming a backdoor is misrepresenting how BitLocker works.

How long does a password attack take?

It depends entirely on the password and what you remember. A familiar word or a shape you can describe can fall in hours or a day or two; a password you recall nothing about is slower and less likely; a strong random password does not fall at all. The free look gives you an honest read before you commit.

Why can a GPU rig crack some passwords but not BitLocker's key?

Because a GPU rig only helps against the password, and BitLocker deliberately makes password guessing slow, a few thousand tries a second. That is enough to catch weak passwords and nowhere near enough for strong ones, and it does nothing against the underlying AES key, which cannot be brute-forced at all.

What does it cost?

Single-disk BitLocker decryption is £800 + VAT, 50% non-refundable on acceptance and 50% no fix, no fee. The non-refundable half reflects the forensic effort of the attack, which depends on the password rather than on us; if you have the recovery key, it is a straightforward decryption instead.

The data is behind the key, not gone.

Looking at it is free, and it begins with the one question that decides everything: do you have the recovery key or password, or can you retrieve it. Tell us what the recovery screen says and what the drive has done, send the proof that it is yours, and back comes a straight account of what is possible and the one price to do it. Until then, reinstall nothing and reformat nothing.

0800 6890668