Lost the recovery key · no escrow copy · the honest answer · memory capture · when it cannot be done
Lost the recovery key, with no copy anywhere. The hardest question, answered straight, without false hope or false despair.
This is the page most sites will not write honestly, so here it is plainly. If your BitLocker recovery key is genuinely lost, with no copy in any Microsoft account, any organisation's directory, any saved file or printout, then whether your data can be recovered depends entirely on what else is true about the drive, and for a certain common configuration the honest answer is that it cannot be recovered by anyone, including us. That is not a sales position; it is the cryptography. But lost-key does not automatically mean lost-data, because there are real routes that do not need the recovery key, and they are worth checking carefully before anyone gives up. A weak password protector can be attacked. A machine still running, or a surviving hibernation file, may hold the key in memory. An escrow copy you have forgotten about may exist. This page walks through each route that can still save a lost-key drive, and is equally clear about the case where none of them applies and the data is gone. We assess all of this free, and we tell you the truth.
Rather talk it through? An engineer answers the bench line
0800 6890668
Every route that can still open a lost-key drive, and the case where none can.
Re-check the escrow, properly. Most keys that feel lost are not: they are in a Microsoft account the owner forgot they used, a family member's account, a work directory, or a printout filed and forgotten. Before anything else, work through the finder page methodically, trying every Microsoft account you or your household might have used and asking IT for a work machine. A found key makes everything else unnecessary.
A weak password protector. If the drive has a password protector as well as, or instead of, the lost recovery key, and that password was human-memorable, it can be attacked by dictionary or mask methods and may be recovered. This is the forgotten-password route, and it works only for weak passwords, but it is a real way in that does not need the recovery key at all.
The key in memory. While a BitLocker volume is mounted, the key sits in the computer's RAM. If the machine is still running with the drive unlocked, the key can sometimes be captured from memory before shutdown; if the machine hibernated while the volume was open, the hibernation file on the disk may contain the key; a crash dump can do the same. These routes are powerful but fragile: once a machine is powered off at the recovery screen with the volume locked, the running-memory route is gone. This is why we say, on every page, not to shut down a still-running machine before asking.
When none of these applies. If the drive is a modern volume encrypted with AES-256-XTS, protected by TPM only or TPM and a strong PIN, with no recovery key anywhere, no password protector to attack, and no memory or hibernation capture, then there is no route in. AES cannot be brute-forced in any feasible time, there is no backdoor, and Microsoft itself cannot reset a lost key. The data is, honestly, gone. We will tell you that at the free look, because the alternative, taking your money for an attack that cannot finish, is not something we will do.
What you see, and what it means.
Describe yours to us →| What you see | The usual reason | Where that leaves you |
|---|---|---|
| Key feels lost, several old accounts exist | It may be in a forgotten account | Re-check every account; keys surface this way |
| Lost key, but a password protector exists | A weak password can be attacked | Dictionary or mask attack on the password |
| Lost key, machine still running and unlocked | The key is in memory now | Capture it from RAM before shutdown |
| Lost key, machine hibernated while open | The key may be in the hibernation file | Extract it from the hibernation file |
| Lost key, modern TPM AES-256, none of the above | No route to the key exists | Not recoverable by anyone; we say so free |
From the drive arriving to your files going back.
Work we have closed →Logged the day it lands, and the first look costs nothing Free
A number goes on the parcel and the drive the day it is opened, matched to your enquiry by the booking sheet inside. Before anything is read we check the proof of ownership you sent. The drive is then connected through a write blocker, read-only, and examined: whether it is a healthy drive behind a lost key, or a failing drive behind a known key, is settled here, and so is whether what you want is possible. That first look is free, and you may stop at it owing nothing.
Imaged at the sector level, before anything else
A drive that answers at all is imaged in full on a hardware imager, behind a write blocker, weak areas last, with a map kept of what could not be read. The image is a copy of the encrypted sectors, so it is useless to anyone without your key, which is a privacy gain in itself. Every later step is done on the image. The original drive is never decrypted, never written to, and never worked on directly.
The physical fault repaired on the clone, when there is one
A drive that has failed, that reads slowly or that drops out is stabilised and imaged in passes; a mechanically failed disk is repaired and read on the bench, a dead SSD controller read at the chip level, before any decryption is attempted. The aim at this stage is one clean image of the encrypted volume to decrypt from. Where the drive is healthy and the problem is only the key, this stage is skipped.
The image decrypted with your key or password
With your recovery key, recovery password or the drive's password, the image is unlocked: the protector releases the Volume Master Key, the VMK releases the Full Volume Encryption Key, and the volume is decrypted from the clone. Where the metadata or header is damaged, repair-bde and the key package rebuild it at the block level onto a separate target. Where the key is lost but a memory image or hibernation file is available, the Volume Master Key is extracted from it with Passware. Without a key, a password to attack, or a memory capture, the volume cannot be opened, and you are told so at the free look.
The file system rebuilt, and the list before the bill
Once the volume is open it is an ordinary NTFS or exFAT file system, and any damage in it is repaired on the image and the files recovered. What was recovered is listed for you first, and only then does a bill exist. The files go home on fresh media. The original drive is returned, or securely destroyed at your request; we never send the key and the data by the same route.
From the bench
- Re-check every escrow location before giving up. Forgotten Microsoft accounts are the single most common place a supposedly lost key turns out to be.
- If the machine is still running, keep it running and call. The key is in memory while the volume is open, and shutdown may close the only route in.
- We will tell you honestly when it cannot be done. A modern TPM-sealed AES-256 drive with no key and no memory capture is a genuine dead end, and we say so rather than take the work.
A forgotten Microsoft account is the single most common place a supposedly lost recovery key actually turns out to be.
What helps, and what harms.
Do this much first
- Re-check every Microsoft account and escrow location first
- Keep a still-running machine running and call before shutdown
- Tell us about any password protector and what you remember of it
- Send proof the drive is yours
What sets us back
- Reformatting or reinstalling while any route in might exist
- Shutting down a running machine before asking about a memory capture
- Paying anyone who promises to break a strong lost-key AES-256 drive
- Giving up before the escrow has been checked thoroughly
Questions answered before you commit.
I have completely lost my BitLocker recovery key. Can my data be recovered?
It depends on what else is true. If there is a weak password protector, it can be attacked; if the machine is still running or hibernated with the volume open, the key may be recoverable from memory. But a modern AES-256 drive protected only by TPM, or TPM and a strong PIN, with no key and no memory capture, cannot be recovered by anyone. We assess which case you are in, free.
Is there really no way to break BitLocker without the key?
Not on a modern, strongly-configured drive. AES cannot be brute-forced in any feasible time, there is no backdoor, and Microsoft cannot reset a lost key. The only ways in are a protector you can open, a weak password to attack, or the key captured from memory while the volume was mounted. If none of those exists, the data is genuinely gone.
My computer is still running. Does that change anything?
Yes, significantly. While the volume is mounted the key is in RAM, and it can sometimes be captured before the machine is shut down. Once it is powered off at the recovery screen with the volume locked, that route closes. If your machine is still running and the data matters, do not shut it down, and call us first.
Why do some services claim they can recover without the key?
Some misunderstand or misrepresent the cryptography, and some are thinking only of the cases with a weak password or a memory capture, which are genuinely recoverable. For a strong, modern, TPM-sealed drive with no key, no legitimate service can break it, and a promise to do so should make you suspicious, not hopeful.
What does it cost to find out?
The assessment is free. We would rather tell you honestly that your drive is in the recoverable group or the genuinely-lost group than charge you for work that cannot succeed. If recovery is possible, it falls under single-disk recovery at £800 + VAT, 50% non-refundable on acceptance and 50% no fix, no fee.
The data is behind the key, not gone.
Looking at it is free. Tell us what the recovery screen says, what happened just before it, and whether you can find your recovery key, and send proof the drive is yours. Back comes an honest account of what can be done and the one price to do it. Until then, reinstall nothing, reformat nothing, and clear no TPM.