Home / Devices / BitLocker

BitLocker Recovery & Decryption Staines

A blue screen demanding a 48-digit key you've never seen, standing between you and a drive that holds everything. We recover BitLocker-locked drives for homes and businesses across Staines and Surrey — finding keys, decrypting estates of drives, and rescuing failing disks through their encryption.

Free diagnostic on every bitlocker job. One fixed quote in writing before any work begins.

No fix, no fee all jobs except electronic and mechanical failures, chip level work, DVR and Forensic jobs. Full pricing is on the free diagnostic page.

// top 12 faults we recover from

The twelve ways they fail

Every bitlocker job starts by matching the symptoms to the fault — these twelve cover almost everything that reaches the bench.

Stuck on the recovery-key screen

A hardware, firmware or update change tripped BitLocker into recovery mode — the data is intact, the key just needs finding or recovering.

Lost or never had the 48-digit key

The key was escrowed somewhere (a Microsoft or work account, a file, a printout) or can be recovered from the TPM or a memory image.

Forgotten BitLocker password or PIN

Where a password protects the volume, accelerated recovery can often retrieve it — fast if it's weak, honest odds if it's strong.

Key stopped working after a hardware change

A new motherboard, TPM clear, BIOS update or Secure Boot change invalidates the seal and forces the recovery key.

Windows was reinstalled over it

A reinstall can strand an encrypted data partition — recoverable with the key or through key recovery.

Drive failing AND BitLocker-locked

The compound case: a dying encrypted drive, imaged gently in its locked state before any decryption is attempted.

BitLocker To Go USB / external locked

Encrypted removable media locked the same way — opened with the key, password or forensic recovery.

Business estate of ex-staff drives

Bulk decryption of encrypted drives from leavers and retired machines against escrowed keys.

Moved the drive to another PC

BitLocker locks when a drive leaves its original machine — expected behaviour, recoverable with the key.

Corrupted BitLocker metadata

Damaged encryption headers on an otherwise healthy drive — reconstructed before decryption.

TPM cleared by a BIOS / UEFI update

A firmware update that clears or reseals the TPM forces the recovery key — retrieved from escrow or the TPM state.

Dual-boot or bootloader change tripped lock

A dual-boot install or GRUB/bootloader update trips BitLocker into recovery — the key is recovered and the volume decrypted.

Two problems wearing one name

BitLocker recovery is really two disciplines. The first is tracking down keys people never realised they had: BitLocker rarely switches on without escrowing a recovery key somewhere — a Microsoft account, an organisation's Azure AD or Active Directory, an exported file or a printout. Modern Windows laptops enable device encryption silently and stash the key the first time you sign in, so the answer to most lockouts is a methodical hunt through every account the machine has ever touched. The second discipline is the hard one: a drive that's failing and encrypted at the same time.

How we decrypt — with Passware Kit Forensic

For business drives and lawful investigations we run Passware Kit Forensic, the industry-standard decryption suite. It doesn't break BitLocker — properly implemented AES encryption without the key is designed to be unbreakable, and anyone claiming otherwise is misleading you. What Passware does is recover the key: pulling it from a captured memory image or hibernation file, extracting it from the TPM, or mounting GPU-accelerated dictionary and brute-force attacks against the password where one guards the volume. We decrypt BitLocker and BitLocker To Go, and the same suite handles FileVault, VeraCrypt, TrueCrypt and LUKS if you have those too. Businesses regularly send us estates of ex-staff and retired-machine drives to decrypt in bulk against escrowed keys.

When the drive is dying as well as locked

The compound case is the one we see most from businesses: a BitLocker drive that's also failing — bad sectors sitting in encrypted space, a laptop crashed into recovery-key purgatory because the disk beneath it is sick. Order of operations is everything. The drive is imaged gently in its encrypted state on hardware imagers first, and only then is the stable image decrypted with the recovered key — never the other way round. Every unlock attempt on a failing encrypted drive is an expensive read that spends its remaining life, which is exactly why the honest advice is to stop and send it in.

// the equipment we use

A professional lab, not software guesswork

BitLocker work is key recovery and careful imaging — not code-breaking. The bench reflects that:

Passware Kit Forensic

The industry-standard decryption suite — recovers BitLocker keys from memory images, hibernation files, the TPM, or the password via accelerated attack. It recovers the key; it does not break the AES.

Memory & hibernation capture

Where a machine can be run, the live encryption key is captured from RAM or the hibernation file — often the fastest route into a locked volume.

GPU acceleration cluster

NVIDIA and AMD GPUs and rainbow tables drive dictionary and brute-force attacks against BitLocker passwords at tens of thousands of guesses per second.

Hardware imagers + write-blockers

Failing encrypted drives are imaged in their locked state through write-blockers first — the original is never altered, and decryption runs on the copy.

Key-escrow investigation

Methodical recovery of keys escrowed to Microsoft accounts, Azure AD / Active Directory, exported files and printouts — where most lockouts are actually solved.

Multi-format decryption

The same suite opens BitLocker To Go, FileVault, VeraCrypt, TrueCrypt and LUKS volumes, plus 400+ password-protected file types.

// manufacturers & models

Encryption types we decrypt

BitLockerBitLocker To GoWindows Device EncryptionVeraCryptTrueCryptFileVault 2LUKS / LUKS2PGP / SymantecMcAfee Drive EncryptionDell Data Protection

How your key is actually recovered

Properly implemented BitLocker is unbreakable without the key — reputable recovery means recovering the key, not cracking the encryption. We use Passware Kit Forensic and tell you honestly what's achievable.

// before you post it

Sending it in — remove the drive if you can

Sending a BitLocker drive for decryption? Include every scrap of key material you hold — the 48-digit recovery key, the Microsoft or work account it may be escrowed to, any exported key files or PINs. The more you can supply, the faster and cheaper the decryption. For a drive removed from a machine, an anti-static bag or foil wrap is fine.

// getting your device to us

Post or courier your device — it's simple

Most customers post or courier their media to us.

Sending a drive from a computer, laptop, MacBook, iMac, CCTV / DVR or server? Please remove the internal hard drive or SSD and send us just the drive — we don't provide an internal drive-removal service. We don't recover storage soldered to a motherboard (e.g. Apple Silicon Macs and some thin laptops) — only drives that can be removed and sent to us.

  • Wrap the device in bubble wrap or a padded envelope — no need to include cables or power supplies.
  • Print and enclose the booking-in & shipping form (PDF) with your name, phone number and a brief description of what happened.
  • Send by Royal Mail Special Delivery or any tracked courier for full insurance in transit.
  • Prefer to hand it over in person? You can drop it in at reception at the address shown, Mon–Fri 9:00am–5:30pm.
// send your device to your nearest location

Guildford Data Recovery

Building 2, Ground Floor
Guildford Business Park
Guildford, GU2 8XH

↓ Print the booking-in & shipping form (PDF)

Mark the package for the attention of Guildford Data Recovery and we'll call you as soon as we diagnose your media.

Not sure what to send? Call 0800 689 0668 first or use the free online diagnostic.

// bitlocker recovery questions

Common questions

Very often, yes. The key is usually escrowed somewhere — a Microsoft or work account, Azure AD, or a saved file — and where it isn't, we can frequently recover it from the TPM, a memory image or the password using Passware Kit Forensic. Don't reset or reinstall in the meantime, as that can destroy recoverable key material.
No — and nobody reputable can. Correctly implemented BitLocker is designed to be unbreakable without the key, the password or TPM cooperation. Forensic tools recover the key; they don't crack the AES itself. If your password is weak or known, GPU-accelerated recovery is fast; if it's strong and genuinely lost, we'll tell you so honestly.
Yes, this is routine work. Send the drives along with any recovery keys, Azure AD or account details you hold and we'll decrypt them in the lab. The more key material you can give us, the faster and cheaper the turnaround.
Power it off. A failing encrypted drive has to be imaged before anything else — we image it encrypted on hardware imagers, then decrypt the stable copy with your key. Repeated unlock attempts on a dying drive only hasten the end.
// related services

Also recovered here

Ready when you are.

Free diagnostic, fixed quote, no fix no fee — start now or call the freephone.