Taking work now — the first look is freeDrives posted in from anywhere in the UK, or handed in at ten drop-off pointsQuicker still, give us a ring:0800 6890668
BLKBitLocker Data Recovery 0800 6890668 Price my job
BLK / Why you are seeing the recovery screen / The CrowdStrike recovery loop

CrowdStrike · July 2024 · 8.5 million devices · blue screen · recovery loop · recovery key

The CrowdStrike BitLocker recovery loop. One faulty update, millions of recovery screens, and no data actually at risk.

On 19 July 2024 a defective update to CrowdStrike's Falcon security software blue-screened an estimated 8.5 million Windows machines around the world, and a great many of them landed in a BitLocker recovery loop: the fix required booting into Safe Mode or a recovery environment to delete one faulty file, but on a BitLocker-encrypted machine that recovery environment first demanded the 48-digit recovery key. The incident was a vivid, painful lesson in why the recovery key matters, because organisations that had their keys to hand recovered quickly, while those whose keys were poorly escrowed, or stored on servers that were themselves blue-screening, struggled for days. Through all of it, no data was ever at risk from the encryption: every affected drive was intact, and the recovery key opened it so the faulty file could be removed. If you still have a machine stuck from that event, or it left you distrustful of where your keys are, the answer is the same as it ever was: the data is fine, and the key is what unlocks the fix. We are for failed drives and genuinely lost keys, not for a machine that simply needs its key entered.

Owner-only, proof requiredFree first look£800 + VAT, one diskThe honest answer either way

Rather talk it through? An engineer answers the bench line
0800 6890668

No data was ever at risk from the encryption in this event. Do not reinstall Windows or reformat a machine stuck from it; the drive is intact and the key plus the documented file deletion is the fix. If the key is escrowed, retrieve it; do not try to repair your way past the recovery screen by destroying the volume.

What the event was, and why the key was the bottleneck.

The CrowdStrike Falcon sensor runs at a deep level in Windows, and on 19 July 2024 a defective configuration update caused it to crash the operating system at boot, producing a blue screen on every affected machine, an estimated 8.5 million of them by Microsoft's own figure. The only fix was to boot into Safe Mode or the Windows Recovery Environment and delete a single faulty file, after which the machine started normally.

On a machine encrypted with BitLocker, that recovery environment is itself behind the encryption, so before anyone could delete the file, the machine demanded the 48-digit recovery key. That is where the incident turned from a quick fix into a crisis for many organisations: the fix per machine was simple, but it required that machine's recovery key, and at scale, with keys sometimes stored on servers that were themselves down, retrieving thousands of keys by hand was the real bottleneck. It was, in effect, a mass demonstration of why key escrow matters.

Crucially, the encryption never endangered any data. Every affected drive was intact; BitLocker was doing exactly what it should, asking for the key before letting anyone into the recovery environment. Machines whose keys were readily available were fixed quickly. If you still have a machine that never recovered from the event, the position is unchanged: the drive is fine, the documented file deletion is the fix, and the recovery key is what gets you into the environment to do it. If the drive has since failed, or the key was lost in the chaos, that is where we can help.

What you see, and what it means.

Describe yours to us →
What you see The usual reason Where that leaves you
Machine stuck in a recovery loop since July 2024The CrowdStrike fix needed the recovery keyEnter the key, delete the faulty file in Safe Mode
Recovery key was on a server that was also downEscrow was centralised on affected infrastructureRetrieve it now the infrastructure is back
Fleet of machines all demanding keys at onceEvery encrypted machine needed its own keyBulk-retrieve keys from AD, Entra ID or Intune
A machine's drive failed during the scrambleA coincident hardware faultImaged, then decrypted with the key
Key genuinely lost in the incidentEscrow gap exposed by the eventHonestly assessed free; may not be recoverable

From the drive arriving to your files going back.

Work we have closed →
01

Logged the day it lands, and the first look costs nothing Free

A number goes on the parcel and the drive the day it is opened, matched to your enquiry by the booking sheet inside. Before anything is read we check the proof of ownership you sent. The drive is then connected through a write blocker, read-only, and examined: whether it is a healthy drive behind a lost key, or a failing drive behind a known key, is settled here, and so is whether what you want is possible. That first look is free, and you may stop at it owing nothing.

Nothing to pay for lookingProof of ownership checked firstRead-only, nothing written to the drive
02

Imaged at the sector level, before anything else

A drive that answers at all is imaged in full on a hardware imager, behind a write blocker, weak areas last, with a map kept of what could not be read. The image is a copy of the encrypted sectors, so it is useless to anyone without your key, which is a privacy gain in itself. Every later step is done on the image. The original drive is never decrypted, never written to, and never worked on directly.

Sector by sector, behind a write blockerNothing written to the original
03

The physical fault repaired on the clone, when there is one

A drive that has failed, that reads slowly or that drops out is stabilised and imaged in passes; a mechanically failed disk is repaired and read on the bench, a dead SSD controller read at the chip level, before any decryption is attempted. The aim at this stage is one clean image of the encrypted volume to decrypt from. Where the drive is healthy and the problem is only the key, this stage is skipped.

Mechanical and chip-level work where neededOne clean encrypted image to work from
04

The image decrypted with your key or password

With your recovery key, recovery password or the drive's password, the image is unlocked: the protector releases the Volume Master Key, the VMK releases the Full Volume Encryption Key, and the volume is decrypted from the clone. Where the metadata or header is damaged, repair-bde and the key package rebuild it at the block level onto a separate target. Where the key is lost but a memory image or hibernation file is available, the Volume Master Key is extracted from it with Passware. Without a key, a password to attack, or a memory capture, the volume cannot be opened, and you are told so at the free look.

Protector → VMK → FVEK → volumeDecrypted from the clone, never the original
05

The file system rebuilt, and the list before the bill

Once the volume is open it is an ordinary NTFS or exFAT file system, and any damage in it is repaired on the image and the files recovered. What was recovered is listed for you first, and only then does a bill exist. The files go home on fresh media. The original drive is returned, or securely destroyed at your request; we never send the key and the data by the same route.

Files listed before any invoiceFresh media, supplied with the job3–7 days at the bench

From the bench

  • No data was ever at risk from the encryption. The drives were intact; the key was only needed to enter the recovery environment and delete the faulty file.
  • The event exposed where key escrow was weak. If it left you unsure where your keys are, the finder page and a review of your escrow are the lasting fix.
  • A machine still stuck needs its key, not a reinstall. The documented file deletion, once you are past the recovery screen, is all it takes.

8.5 million Windows devices were affected (Microsoft's estimate); the per-machine bottleneck was retrieving each one's recovery key.

What helps, and what harms.

Do this much first

  • Enter the recovery key to reach Safe Mode, then delete the faulty file
  • Retrieve keys in bulk from AD, Entra ID or Intune for a fleet
  • Review where your keys are escrowed after the event
  • Come to us for a failed drive or a genuinely lost key

What sets us back

  • Reinstalling Windows on a machine that just needs its key
  • Reformatting an intact encrypted drive
  • Assuming the encryption put your data at risk; it did not
  • Leaving your key escrow as weak as the event revealed
We recover BitLocker drives for the people who own them. Before any work begins we ask for proof that the drive is yours or that you are authorised to have it recovered: a purchase receipt, the device serial, a letter on company letterhead for a work machine, or written authorisation from the owner, together with photo ID and a signed authorisation. It is a condition of the work, not a formality, and it is what keeps the service on the right side of the Computer Misuse Act. A drive with no proof of ownership is returned unread.

Questions answered before you commit.

Why did the CrowdStrike outage cause BitLocker recovery screens?

The fix required booting into Safe Mode or the recovery environment to delete a faulty file, and on a BitLocker-encrypted machine that environment demands the 48-digit recovery key first. So every affected encrypted machine asked for its key before it could be fixed. The encryption itself harmed nothing.

Was any data lost because of BitLocker in the outage?

No. Every affected drive was intact; BitLocker was simply doing its job, requiring the key before allowing access to the recovery environment. Machines whose keys were available were fixed quickly. The data was never at risk from the encryption.

I still have a machine stuck from July 2024. What do I do?

Enter its 48-digit recovery key to reach Safe Mode or the recovery environment, then follow the documented step of deleting the faulty CrowdStrike file, and it starts normally. If you cannot find the key, the finder page lists where it is escrowed; if the drive has since failed, we can image and decrypt it.

How many machines were affected?

Microsoft estimated about 8.5 million Windows devices, which it described as less than one percent of all Windows machines. It was nonetheless one of the most disruptive IT events on record, largely because of the manual, per-machine recovery each encrypted device required.

What does it cost?

A machine that only needs its key entered costs nothing from us. A failed drive, or genuine recovery work, falls under single-disk recovery at £800 + VAT, 50% non-refundable on acceptance and 50% no fix, no fee.

The data is behind the key, not gone.

Looking at it is free. Tell us what the recovery screen says, what happened just before it, and whether you can find your recovery key, and send proof the drive is yours. Back comes an honest account of what can be done and the one price to do it. Until then, reinstall nothing, reformat nothing, and clear no TPM.

0800 6890668