Stuck encrypting · interrupted decryption · partly-encrypted volume · the delicate case · key held
Stuck or interrupted part way through encrypting. Encryption stopped half done, leaving a drive that is part clear, part encrypted, and wholly delicate.
BitLocker encrypts or decrypts a drive in the background, sector by sector, and it can take hours on a large drive. If that process is interrupted part way, by a power cut, a crash, a forced shutdown, or a drive that failed mid-operation, the result is a partly-encrypted volume: some sectors encrypted, some still in the clear, and a conversion that never finished. This is the most delicate BitLocker case, and worth being honest about. Microsoft's own repair tool explicitly cannot repair a drive that failed during the encryption or decryption process, because the tool assumes a volume is either fully encrypted or not, and a half-converted drive breaks that assumption. It is not hopeless, though. With the recovery key and careful work, the encrypted and clear regions can often be told apart and reassembled, and a great deal of the data recovered, especially where the interruption was clean rather than a hardware failure. It calls for an imaged, methodical approach and realistic expectations, both of which we bring. We recover these drives only for their owners, behind proof of ownership.
Rather talk it through? An engineer answers the bench line
0800 6890668
Why a partly-encrypted drive is the delicate case, and what can still be done.
During conversion, BitLocker keeps track of how far it has got, and a drive in mid-conversion is genuinely two things at once: a region already encrypted, a region still in the clear, and a marker of the boundary. Interrupt it, and that in-between state is frozen. If the interruption was clean, a power cut on a healthy drive, the state is at least consistent; if it was a hardware failure mid-conversion, the boundary information itself may be damaged, which is harder.
This is why Microsoft's repair-bde cannot help here: it is built on the assumption that a volume is either fully encrypted or fully not, and it treats any encryption as covering the whole drive. A half-converted volume violates that, so the standard tool declines it. That is a real limit, and any honest account of BitLocker recovery has to state it rather than pretend the usual tool covers this case.
What can be done is more bespoke. With the recovery key and a sector image of the drive, the encrypted region can be decrypted and the clear region read directly, and the two reassembled into the original data, once the boundary between them is established. How much comes back depends on where the conversion had reached, whether the interruption was clean or a failure, and how much of the file system fell in each region. Often a substantial majority of the data is recoverable; sometimes, where a failure damaged the boundary or the drive, less. We work from an image, establish the state carefully, and tell you honestly what we are seeing and what we expect, rather than promising a clean result the situation may not allow.
What you see, and what it means.
Describe yours to us →| What you see | The usual reason | Where that leaves you |
|---|---|---|
| Encryption stuck at a percentage for good, key held | The conversion stalled part way | Imaged; encrypted and clear regions reassembled |
| Power cut during encryption, healthy drive, key held | A clean interruption, consistent state | Often substantially recoverable with the key |
| Drive failed during encryption | The boundary information may be damaged | Harder and partial; honestly assessed free |
| Interrupted decryption, half back to clear | The reverse conversion stalled | Reassembled from an image with the key |
| repair-bde refuses the drive | It cannot handle a mid-conversion volume | Bespoke reassembly, not the standard tool |
From the drive arriving to your files going back.
Work we have closed →Logged the day it lands, and the first look costs nothing Free
A number goes on the parcel and the drive the day it is opened, matched to your enquiry by the booking sheet inside. Before anything is read we check the proof of ownership you sent. The drive is then connected through a write blocker, read-only, and examined: whether it is a healthy drive behind a lost key, or a failing drive behind a known key, is settled here, and so is whether what you want is possible. That first look is free, and you may stop at it owing nothing.
Imaged at the sector level, before anything else
A drive that answers at all is imaged in full on a hardware imager, behind a write blocker, weak areas last, with a map kept of what could not be read. The image is a copy of the encrypted sectors, so it is useless to anyone without your key, which is a privacy gain in itself. Every later step is done on the image. The original drive is never decrypted, never written to, and never worked on directly.
The physical fault repaired on the clone, when there is one
A drive that has failed, that reads slowly or that drops out is stabilised and imaged in passes; a mechanically failed disk is repaired and read on the bench, a dead SSD controller read at the chip level, before any decryption is attempted. The aim at this stage is one clean image of the encrypted volume to decrypt from. Where the drive is healthy and the problem is only the key, this stage is skipped.
The image decrypted with your key or password
With your recovery key, recovery password or the drive's password, the image is unlocked: the protector releases the Volume Master Key, the VMK releases the Full Volume Encryption Key, and the volume is decrypted from the clone. Where the metadata or header is damaged, repair-bde and the key package rebuild it at the block level onto a separate target. Where the key is lost but a memory image or hibernation file is available, the Volume Master Key is extracted from it with Passware. Without a key, a password to attack, or a memory capture, the volume cannot be opened, and you are told so at the free look.
The file system rebuilt, and the list before the bill
Once the volume is open it is an ordinary NTFS or exFAT file system, and any damage in it is repaired on the image and the files recovered. What was recovered is listed for you first, and only then does a bill exist. The files go home on fresh media. The original drive is returned, or securely destroyed at your request; we never send the key and the data by the same route.
From the bench
- Do not resume or force the conversion. A half-converted volume is fragile, and pushing it can destroy the boundary that makes reassembly possible.
- The standard repair tool will not touch this case, which is exactly why it needs careful, bespoke, imaged work rather than a one-command fix.
- Expectations matter here. A clean interruption with the key often recovers most of the data; a hardware failure mid-conversion recovers less, and we tell you which we are seeing.
A clean interruption with the key often recovers most of a partly-encrypted drive; a hardware failure mid-conversion recovers less.
What helps, and what harms.
Do this much first
- Stop the drive and leave the conversion where it is
- Have your recovery key ready
- Send the drive to be imaged before anything is attempted
- Send proof the drive is yours
What sets us back
- Resuming, restarting or forcing the conversion
- Running repair-bde or chkdsk on a half-converted drive
- Expecting the standard tools to handle this; they will not
- Assuming it is hopeless; much is often recoverable with the key
Questions answered before you commit.
My BitLocker encryption got stuck half way. Is the drive recoverable?
Often, at least substantially, with the recovery key. A partly-encrypted drive is delicate because it is part encrypted and part clear with an unfinished conversion, but with the key and a sector image the two regions can usually be reassembled. How much comes back depends on where it had reached and whether the interruption was clean or a hardware failure.
Why will repair-bde not fix my partly-encrypted drive?
Because repair-bde assumes a volume is either fully encrypted or fully not, and treats any encryption as covering the whole drive. A half-converted volume breaks that assumption, so Microsoft's tool explicitly cannot repair a drive that failed during encryption or decryption. This case needs bespoke work rather than the standard tool.
The encryption was interrupted by a power cut. Is that better or worse than a crash?
Generally better, if the drive itself is healthy. A clean interruption on a good drive leaves a consistent half-converted state that can be reassembled with the key. A hardware failure during conversion can damage the boundary information between the encrypted and clear regions, which makes recovery harder and more partial.
Can you guarantee you will recover everything from a partly-encrypted drive?
No, and we will not pretend to. It is the one BitLocker case where even with the key the outcome genuinely varies with where the conversion stopped and how. We image the drive, establish the state, and tell you honestly what we expect before you commit, rather than promising a clean result the situation may not allow.
What does it cost?
Recovering a partly-encrypted BitLocker drive falls under single-disk recovery at £800 + VAT, 50% non-refundable on acceptance and 50% no fix, no fee. The drive must be removed from the computer and sent in on its own, and the free look sets honest expectations first.
The data is behind the key, not gone.
Looking at it is free. Tell us what the recovery screen says, what happened just before it, and whether you can find your recovery key, and send proof the drive is yours. Back comes an honest account of what can be done and the one price to do it. Until then, reinstall nothing, reformat nothing, and clear no TPM.