Taking work now — the first look is freeDrives posted in from anywhere in the UK, or handed in at ten drop-off pointsQuicker still, give us a ring:0800 6890668
BLKBitLocker Data Recovery 0800 6890668 Price my job
BLK / When it cannot be recovered

The honest answer · AES cannot be brute-forced · no backdoor · no reset

When BitLocker data cannot be recovered. Most sites will not write this page. Here it is, plainly, because you deserve the truth before you spend anything.

Most BitLocker lockouts end well: the data is intact, the key is found, and the drive opens. But some do not, and an honest recovery service has to say so clearly rather than take money for work that cannot succeed. The hard truth is that BitLocker, correctly configured on a modern machine, is genuinely strong: it uses AES encryption, which cannot be brute-forced in any feasible time; there is no Microsoft master key and no backdoor; and Microsoft itself cannot reset a lost recovery key. So when a key is truly lost, whether your data can be recovered depends entirely on whether there is some other way to the key, and for one common configuration there is none. This page explains exactly when recovery is still possible and when it is not, so you can tell the difference, and so you can recognise that any service promising to break a strong, lost-key BitLocker drive is not being straight with you.

AES cannot be brute-forcedNo backdoor, no master keyNo reset of a lost keyWe say so before you pay

Rather talk it through? An engineer answers the bench line
0800 6890668

When BitLocker data can still be recovered.

Before the hard truth, the hopeful part, because lost-key does not automatically mean lost-data. Recovery is still possible, and often routine, in these cases:

You have, or can retrieve, the recovery key or password. This is almost everything. The key is usually escrowed in a Microsoft account or an organisation's directory, and with it the drive opens even if it has physically failed. Most people who fear their data is gone simply have not yet found their key; the finder page is the place to start.

The drive has a weak, human-chosen password. If a password protector was used and the password was memorable, a word, a name, a date, a familiar pattern, it can often be recovered by a dictionary or mask attack, and the more you remember about it the better the odds. This does not need the recovery key at all.

The machine is still running, or a hibernation file survives. While a BitLocker volume is mounted, the key sits in the computer's memory. If the machine is still running with the drive unlocked, or it hibernated while the volume was open, the key can sometimes be lifted from memory or the hibernation file, regardless of the protector. This is why we say, everywhere, not to shut down a still-running machine before asking.

When it genuinely cannot, and why.

Now the part most sites avoid. If a drive is encrypted with AES-256-XTS, protected by TPM only or TPM and a strong PIN, with no recovery key escrowed anywhere, no password protector to attack, and no memory or hibernation capture available, then the data cannot be recovered by anyone, including us. This is not a limitation of our equipment or a matter of trying harder; it is the mathematics of the encryption, and it is worth understanding why.

AES cannot be brute-forced. BitLocker's encryption key is effectively impossible to guess by trying every possibility. The number of possible keys is so vast that trying them all would take longer than the age of the universe, with any amount of computing power; this is the same AES encryption that protects government and banking data precisely because it cannot be broken by force. A rig of fast GPUs does not change this, because those GPUs can only help against a weak password, not against the encryption key itself.

There is no backdoor and no master key. BitLocker was not built with a secret way in, and Microsoft did not keep a master key. The only things that open a BitLocker drive are a protector you can unlock and the recovery key. There is no override, no special tool, and no service, legitimate or otherwise, with a secret method, whatever their advertising implies.

Microsoft cannot reset a lost key. Microsoft states this plainly in its own documentation: it cannot access or reset a lost BitLocker recovery key. If the key was never escrowed, or the account holding it is gone, there is nothing for Microsoft, or anyone, to retrieve.

Put those together and the conclusion is unavoidable: a strong, modern, TPM-sealed BitLocker drive with a genuinely lost key and no other way to it is, honestly, unrecoverable. We will tell you that at the free look, with nothing to pay, because the alternative, taking your money for an attack that cannot finish, is not something we are willing to do.

Be cautious of anyone who promises to recover a strong, lost-key BitLocker drive. For a weak password or a memory capture, recovery is genuine and we offer it. But for a modern AES-256 drive with a genuinely lost key and nothing to fall back on, no legitimate service can break it, and a confident promise to do so should make you suspicious, not hopeful. Ask what, specifically, they would attack, and if the answer is the encryption itself rather than a weak password, the claim does not hold.

The questions that come up first.

Can a specialist crack BitLocker if Microsoft cannot?

No specialist can brute-force the encryption itself, because AES cannot be broken by force in any feasible time, and there is no backdoor. A specialist can attack a weak password or lift the key from a running machine's memory, which are real services. But for a strong, modern, TPM-sealed drive with a genuinely lost key and no memory capture, no one can open it.

Is there really no master key or backdoor?

No. BitLocker was not built with one, and Microsoft did not keep a master key. The only ways in are a protector you can unlock and the recovery key, and Microsoft cannot reset a lost key. Any claim of a secret method or override is not accurate.

So when exactly is my data gone?

When the drive is a modern AES-256 drive, protected by TPM only or TPM and a strong PIN, with no recovery key escrowed anywhere, no weak password protector to attack, and no memory or hibernation capture available. With none of those, there is no route to the key, and the data cannot be recovered by anyone.

Why would you turn away work by telling me this?

Because taking money for recovery that cannot succeed is not something we are willing to do. We would rather give you an honest answer for free, and keep the trust, than charge you for an attack on encryption that cannot be broken. If there is a genuine route, a weak password, a memory capture, the key itself, we will find it and tell you.

What should I do if my drive might be in the recoverable group?

Send us what you have, the key ID from the recovery screen, an account of what happened, whether there was a password and what you remember of it, whether the machine is still running, and proof the drive is yours. The free look will tell you honestly which group your drive is in, and it costs nothing.

The honest answer, free, either way.

If there is a route to your data, a key to find, a weak password to attack, a running machine to capture, we will find it and tell you what it costs. If there is genuinely none, we will tell you that too, with nothing to pay, rather than sell you false hope.

0800 6890668