Taking work now — the first look is freeDrives posted in from anywhere in the UK, or handed in at ten drop-off pointsQuicker still, give us a ring:0800 6890668
BLKBitLocker Data Recovery 0800 6890668 Price my job

TPM + PIN · boot PIN · anti-hammering · TPM lockout · recovery key · memory image

TPM and PIN BitLocker recovery. A PIN you type at every boot, until the morning it will not come back to you.

TPM and PIN adds something you know to the chip on the board: at every boot you type a PIN, the TPM checks both the PIN and its own measurements, and only then releases the key. It is stronger than TPM-only precisely because the PIN is not stored on the machine, which also means it can be forgotten, and that a PIN typed wrong too many times trips the TPM's anti-hammering lockout. Either way, the drive falls back to the 48-digit recovery key, which opens it regardless of the PIN. The data is intact throughout. Where it gets interesting is a genuinely forgotten PIN with no recovery key to be found: a BitLocker PIN is often short and numeric, and a short numeric PIN is the one case where an attack on the protector itself can succeed, if a memory image or hibernation file is available, or in some configurations by recovering the PIN with forensic tools before extracting the key. A long passphrase-style PIN is a different matter. These drives are recovered only for their owners, behind proof of ownership, and the free look tells you honestly which case yours is.

Owner-only, proof requiredFree first look£800 + VAT, one diskNo fix, no fee on the balance

Rather talk it through? An engineer answers the bench line
0800 6890668

Stop before you reinstall or reformat anything. If the machine is at the BitLocker recovery screen, the data is intact behind the key; reinstalling Windows, reformatting the drive or clearing the TPM again will not get you in and can overwrite what is there. Do not keep typing the wrong key until a device locks you out. If the machine is still running and unlocked, do not shut it down before you have read the lost-password pages. Find your recovery key first, and send nothing until you have.

The recovery key opens it whatever the PIN.

Forget the PIN, or trip the TPM lockout by typing it wrong, and BitLocker asks for the 48-digit recovery key. That key opens the drive no matter what has happened to the PIN, so it is the first thing to find: in your Microsoft account, your organisation's Entra ID or Active Directory, Intune or MBAM on a managed machine, or a saved or printed copy. The finder page covers each. With the key, you enter it, get in, and can set a new PIN from inside Windows.

The TPM lockout itself is temporary on most machines, a cooldown that lengthens with repeated failures, and it never touches the data; the recovery key bypasses it entirely. So a TPM+PIN lockout is, in the great majority of cases, simply a find-the-key job.

Where there is no key to find, the PIN becomes the question. A short numeric PIN can sometimes be recovered: if the machine is still running with the volume mounted, or a hibernation file or crash dump survives, the Volume Master Key can be lifted from memory with Passware and the drive opened regardless of the PIN; and in some TPM configurations the PIN itself can be recovered with forensic tooling. A long or complex PIN, on a powered-off machine with no memory capture and no escrow key, is not recoverable, and we say so.

Forgotten PIN, lockout, and the limits.

A forgotten PIN is not lost dataThe PIN protects a copy of the key; it is not the key, and it is not the data. Forget it and the recovery key still opens the drive. The data is untouched. The only real problem is a forgotten PIN together with a recovery key that cannot be found.
TPM lockout is a cooldown, not a wipeType the PIN wrong enough times and the TPM enters anti-hammering lockout, refusing PIN attempts for a period that grows with each failure. It protects against guessing; it does not delete anything, and the recovery key works straight through it. Stop guessing and find the key.
A short numeric PIN is the recoverable caseBitLocker PINs are often four to eight digits. If there is no recovery key but a memory image or hibernation file is available, or the machine is still running, a short PIN or the key behind it can sometimes be recovered. This is the one BitLocker case where attacking the protector is realistic, and even then it depends on the sources available.
A strong PIN with no key is not recoverableA long, non-numeric, passphrase-style PIN resists attack the way a strong password does, because BitLocker's key derivation is deliberately slow. On a powered-off drive with no escrow key and no memory capture, a strong PIN cannot be broken in any feasible time, and no legitimate service can promise otherwise.

What you see, and what is behind it.

Describe yours to us →
What you see What is usually behind it Where that leaves you
Forgotten the boot PINThe PIN protects a key copy, not the dataOpen with the recovery key; set a new PIN
Too many wrong PINs; now it will not accept anyTPM anti-hammering lockoutThe recovery key works through it; stop guessing
Forgotten PIN, short and numeric, no keyA recoverable protector, with the right sourcesPossible from a memory image or hibernation file
Forgotten long PIN, powered off, no keyA strong protector, nothing to work fromNot recoverable; we say so at the free look
Drive also failed, PIN known or key heldA physical job plus decryptionImaged, then decrypted from the clone

From the drive arriving to your files going back.

Work we have closed →
01

Logged the day it lands, and the first look costs nothing Free

A number goes on the parcel and the drive the day it is opened, matched to your enquiry by the booking sheet inside. Before anything is read we check the proof of ownership you sent. The drive is then connected through a write blocker, read-only, and examined: whether it is a healthy drive behind a lost key, or a failing drive behind a known key, is settled here, and so is whether what you want is possible. That first look is free, and you may stop at it owing nothing.

Nothing to pay for lookingProof of ownership checked firstRead-only, nothing written to the drive
02

Imaged at the sector level, before anything else

A drive that answers at all is imaged in full on a hardware imager, behind a write blocker, weak areas last, with a map kept of what could not be read. The image is a copy of the encrypted sectors, so it is useless to anyone without your key, which is a privacy gain in itself. Every later step is done on the image. The original drive is never decrypted, never written to, and never worked on directly.

Sector by sector, behind a write blockerNothing written to the original
03

The physical fault repaired on the clone, when there is one

A drive that has failed, that reads slowly or that drops out is stabilised and imaged in passes; a mechanically failed disk is repaired and read on the bench, a dead SSD controller read at the chip level, before any decryption is attempted. The aim at this stage is one clean image of the encrypted volume to decrypt from. Where the drive is healthy and the problem is only the key, this stage is skipped.

Mechanical and chip-level work where neededOne clean encrypted image to work from
04

The image decrypted with your key or password

With your recovery key, recovery password or the drive's password, the image is unlocked: the protector releases the Volume Master Key, the VMK releases the Full Volume Encryption Key, and the volume is decrypted from the clone. Where the metadata or header is damaged, repair-bde and the key package rebuild it at the block level onto a separate target. Where the key is lost but a memory image or hibernation file is available, the Volume Master Key is extracted from it with Passware. Without a key, a password to attack, or a memory capture, the volume cannot be opened, and you are told so at the free look.

Protector → VMK → FVEK → volumeDecrypted from the clone, never the original
05

The file system rebuilt, and the list before the bill

Once the volume is open it is an ordinary NTFS or exFAT file system, and any damage in it is repaired on the image and the files recovered. What was recovered is listed for you first, and only then does a bill exist. The files go home on fresh media. The original drive is returned, or securely destroyed at your request; we never send the key and the data by the same route.

Files listed before any invoiceFresh media, supplied with the job3–7 days at the bench

From the bench

  • Stop entering the PIN once it has failed a few times. You are only extending the TPM lockout; the recovery key is the way in, not the next guess.
  • A short numeric PIN is worth telling us about in detail: its length and anything you remember narrows a memory-based recovery considerably.
  • If the machine is still on, keep it on. A running TPM+PIN machine holds the key in memory; powered off at the recovery screen, with no key, it may be beyond reach.

A short numeric PIN with a memory or hibernation source is the one BitLocker case where attacking the protector itself is realistic.

One job, followed all the way through.

UK · BLK-2026-0702JOB LOGGED ✓

A Lenovo ThinkPad whose owner had changed the boot PIN the week before and could not recall the new one, TPM and PIN, with no recovery key saved and a consultant's current project on it

The machine was still running when they called, which decided it. With ownership confirmed, we captured a memory image from the running machine before anything was shut down, extracted the Volume Master Key from it with Passware, and decrypted a sector image of the drive from that. The project files came back in full. Had the laptop been powered off at the recovery screen first, with no key escrowed, the outcome would have been very different.

100% recovered from the memory image4 days at the bench
Illustrative example — replace with a genuine case

What helps, and what harms.

Do this much first

  • Find the recovery key first; it opens the drive whatever the PIN
  • Stop entering the PIN once it has failed a few times
  • Keep the machine running if it still is, and call before shutting down
  • Tell us the PIN length and anything you remember

What sets us back

  • Guessing the PIN into a longer and longer TPM lockout
  • Assuming a forgotten PIN means lost data; the key still works
  • Powering off a running machine before asking about a memory capture
  • Reinstalling Windows to clear the lockout, which overwrites the data
We recover BitLocker drives for the people who own them. Before any work begins we ask for proof that the drive is yours or that you are authorised to have it recovered: a purchase receipt, the device serial, a letter on company letterhead for a work machine, or written authorisation from the owner, together with photo ID and a signed authorisation. It is a condition of the work, not a formality, and it is what keeps the service on the right side of the Computer Misuse Act. A drive with no proof of ownership is returned unread.

Questions answered before you commit.

I forgot my BitLocker PIN. Is my data gone?

No. The PIN protects a copy of the key, not the data. Enter your 48-digit recovery key instead and the drive opens, then set a new PIN from inside Windows. The data is untouched. Only a forgotten PIN together with a lost recovery key is a real problem.

My laptop is in TPM lockout after wrong PINs. What now?

Stop entering the PIN; the lockout only lengthens with each attempt, and it never deletes anything. Use the recovery key, which works straight through the lockout. If you cannot find the key, the finder page lists everywhere it could be.

Can you recover a forgotten PIN without the recovery key?

Sometimes, if the PIN is short and numeric and there is a memory image, a hibernation file, or a still-running machine to work from. A long or complex PIN on a powered-off machine with no escrow key cannot be recovered, and we tell you which case yours is at the free look rather than take work that cannot succeed.

Does entering the wrong PIN too many times erase the drive?

No. BitLocker's TPM lockout refuses further PIN attempts for a cooldown period; it does not wipe the drive. The recovery key bypasses the lockout. Nothing is deleted by wrong PINs.

What does it cost?

Single-disk BitLocker decryption is £800 + VAT, 50% non-refundable on acceptance and 50% no fix, no fee. If the recovery key is in your account and the drive is healthy, finding it may solve the lockout at no cost beyond the free look.

The data is behind the key, not gone.

Looking at it is free, and it begins with the one question that decides everything: do you have the recovery key or password, or can you retrieve it. Tell us what the recovery screen says and what the drive has done, send the proof that it is yours, and back comes a straight account of what is possible and the one price to do it. Until then, reinstall nothing and reformat nothing.

0800 6890668