Home / Devices / BitLocker

BitLocker Recovery & Decryption Staines

A blue screen demanding a 48-digit key you've never seen, standing between you and a drive that holds everything. We recover BitLocker-locked drives for homes and businesses across Staines and Surrey — finding keys, decrypting estates of drives, and rescuing failing disks through their encryption.

Free diagnostic on every bitlocker job. One fixed quote in writing before any work begins.

No fix, no fee all jobs except electronic and mechanical failures, chip level work, DVR and Forensic jobs. Full pricing is on the data recovery cost page.

// top 12 faults we recover from

The twelve ways they fail

Every bitlocker job starts by matching the symptoms to the fault — these twelve cover almost everything that reaches the bench.

Stuck on the recovery-key screen

Some hardware, firmware or update change has tipped BitLocker into recovery mode — nothing is lost, the key simply has to be found or recovered.

Lost or never had the 48-digit key

Almost always the key was escrowed along the way — to a Microsoft or work account, a file or a printout — or it can be pulled from the TPM or a memory image.

Forgotten BitLocker password or PIN

A password-protected volume responds to accelerated recovery: quick when the password is weak, honestly-quoted odds when it's strong.

Key stopped working after a hardware change

Swap the motherboard, clear the TPM, update the BIOS or touch Secure Boot and the seal breaks — Windows then demands the recovery key.

Windows was reinstalled over it

An encrypted data partition left stranded by a reinstall comes back with the key, or through key recovery when there isn't one.

Drive failing AND BitLocker-locked

The double-trouble case: a dying drive that's also encrypted gets imaged gently while still locked, before decryption is even discussed.

BitLocker To Go USB / external locked

Sticks and externals lock exactly the same way — and open with the key, the password or forensic key recovery.

Business estate of ex-staff drives

Leavers' machines and retired stock, decrypted in bulk against whatever keys the organisation escrowed.

Moved the drive to another PC

Taking a drive out of its original machine is precisely what BitLocker is designed to notice — expected, and recoverable with the key.

Corrupted BitLocker metadata

Damaged encryption headers on a drive that's otherwise fine are rebuilt first, then the volume is decrypted.

TPM cleared by a BIOS / UEFI update

A firmware update that clears or reseals the TPM forces the recovery key — retrieved from escrow or the TPM state.

Dual-boot or bootloader change tripped lock

A dual-boot install or GRUB/bootloader update trips BitLocker into recovery — the key is recovered and the volume decrypted.

One name, two very different jobs

Under the single label of 'BitLocker recovery' live two separate disciplines. The first is tracking down keys people never realised they had: BitLocker rarely switches on without escrowing a recovery key somewhere — a Microsoft account, an organisation's Azure AD or Active Directory, an exported file or a printout. Modern Windows laptops enable device encryption silently and stash the key the first time you sign in, so the answer to most lockouts is a methodical hunt through every account the machine has ever touched. The second discipline is the hard one: a drive that's failing and encrypted at the same time.

Passware Kit Forensic does the decrypting

Business drives and lawful investigations go through Passware Kit Forensic, the decryption suite the industry standardises on. It doesn't break BitLocker — properly implemented AES encryption without the key is designed to be unbreakable, and anyone claiming otherwise is misleading you. What Passware does is recover the key: pulling it from a captured memory image or hibernation file, extracting it from the TPM, or mounting GPU-accelerated dictionary and brute-force attacks against the password where one guards the volume. BitLocker and BitLocker To Go are the staples, while the same suite opens FileVault, VeraCrypt, TrueCrypt and LUKS should you have those as well. Estates of leavers' and retired-machine drives arrive from businesses all the time for bulk decryption against escrowed keys.

When the drive is dying as well as locked

The compound case is the one we see most from businesses: a BitLocker drive that's also failing — bad sectors sitting in encrypted space, a laptop crashed into recovery-key purgatory because the disk beneath it is sick. Order of operations is everything. The drive is imaged gently in its encrypted state on hardware imagers first, and only then is the stable image decrypted with the recovered key — never the other way round. Every unlock attempt on a failing encrypted drive is an expensive read that spends its remaining life, which is exactly why the honest advice is to stop and send it in.

// the equipment we use

A professional lab, not software guesswork

There's no code-breaking in honest BitLocker work — it's key recovery plus careful imaging, and the bench is set up for exactly that:

Passware Kit Forensic

The decryption suite the industry standardises on: BitLocker keys pulled from memory images, hibernation files or the TPM, or the password recovered by accelerated attack. What it recovers is the key — the AES itself is never broken.

Memory & hibernation capture

If the machine still runs, the live encryption key can be lifted from RAM or the hibernation file — frequently the quickest way into a locked volume.

GPU acceleration cluster

Banks of NVIDIA and AMD GPUs, backed by rainbow tables, throw tens of thousands of dictionary and brute-force guesses per second at a BitLocker password.

Hardware imagers + write-blockers

A failing encrypted drive is captured in its locked state behind a write-blocker before anything else; decryption then runs on that copy, never the original.

Key-escrow investigation

A patient, systematic hunt through Microsoft accounts, Azure AD / Active Directory, exported files and printouts — because that's where most lockouts actually end.

Multi-format decryption

Beyond BitLocker and BitLocker To Go, the same suite opens FileVault, VeraCrypt, TrueCrypt and LUKS volumes, along with 400+ password-protected file types.

// manufacturers & models

Encryption types we decrypt

BitLockerBitLocker To GoWindows Device EncryptionVeraCryptTrueCryptFileVault 2LUKS / LUKS2PGP / SymantecMcAfee Drive EncryptionDell Data Protection

Where your key really comes from

BitLocker done properly cannot be broken without its key — so reputable work means getting the key back, never 'cracking' the cipher. Passware Kit Forensic is our tool for it, and we're straight with you about what's achievable.

// before you post it

Sending it in — remove the drive if you can

Posting a BitLocker drive in for decryption? Put every piece of key material you have in with it — the 48-digit recovery key, the Microsoft or work account it might be escrowed under, any exported key files or PINs. Each item you supply makes the decryption quicker and cheaper. A bare drive out of a machine travels fine in an anti-static bag or foil wrap.

// getting your device to us

Post your device to us — it's simple

Most customers post their media to us tracked and insured.

Sending a drive from a computer, laptop, MacBook, iMac, CCTV / DVR or server? Please remove the internal hard drive or SSD and send us just the drive — we don't provide an internal drive-removal service. We don't recover storage soldered to a motherboard (e.g. Apple Silicon Macs and some thin laptops) — only drives that can be removed and sent to us.

  • Wrap the device in bubble wrap or a padded envelope — no need to include cables or power supplies.
  • Print and enclose the booking-in & shipping form (PDF) with your name, phone number and a brief description of what happened.
  • Send by Royal Mail Special Delivery, or a tracked courier of your own choosing, for full insurance in transit.
  • Prefer to hand it over in person? You can drop it in at reception at the address shown, Mon–Fri 9:00am–5:30pm.
// send your device to your nearest location

Guildford Data Recovery

Building 2, Ground Floor
Guildford Business Park
Guildford, GU2 8XH

↓ Print the booking-in & shipping form (PDF)

Mark the package for the attention of Guildford Data Recovery and we'll call you as soon as we diagnose your media.

Not sure what to send? Call 0800 689 0668 first or use the free online diagnostic.

// bitlocker recovery questions

Common questions

Very often, yes. Somewhere along the line the key was probably escrowed — to a Microsoft or work account, Azure AD, or a saved file — and when it genuinely wasn't, Passware Kit Forensic frequently recovers it from the TPM, a memory image or the password. Whatever you do, hold off resetting or reinstalling: either can destroy recoverable key material.
No — and nobody reputable can. BitLocker implemented correctly is engineered to resist everything short of the key, the password or the TPM's cooperation. What forensic tooling does is retrieve the key — the AES cipher itself is never cracked. If your password is weak or known, GPU-accelerated recovery is fast; if it's strong and genuinely lost, we'll tell you so honestly.
Yes, this is routine work. Send the drives along with any recovery keys, Azure AD or account details you hold and we'll decrypt them in the lab. The more key material you can give us, the faster and cheaper the turnaround.
Power it off. A failing encrypted drive has to be imaged before anything else — we image it encrypted on hardware imagers, then decrypt the stable copy with your key. Repeated unlock attempts on a dying drive only hasten the end.
// related services

Also recovered here

Ready when you are.

Free diagnostic, fixed quote, no fix no fee — start now or call the freephone.