Home / Case Studies / Trust, Practice & Honest Limits
Trust, Practice & Honest Limits · case file

The Password and the Recovery Key Are Both Gone

Her encrypted USB stick has lost both of its keys. She has "forgotten my password" and the "recovery key is lost", and has been told the stick "would need to be formatted which would mean losing all the data it has" She asks whether recovery is possible. This is the honest hard case, and the answer has to lead with truth: when both the password and the recovery key to sound encryption are genuinely gone, no laboratory unlocks it — but before accepting that, it is worth confirming the encryption type and searching properly for any surviving trace of either key, because "lost" is not always as final as it feels.

USB FlashEncryption / BitLocker
// case at a glance
MediaEncrypted USB flash stick — the password forgotten and the recovery key lost; a prior suggestion that only formatting (and total data loss) remains.
Reported situationUSB stick protected by encryption · password no longer remembered · recovery key not available · advice received that formatting is the only option · owner seeking any recovery route before accepting the loss.
Fault classEncrypted media with both credentials missing — recovery contingent entirely on the encryption type and on finding any surviving key material, with sound encryption otherwise unrecoverable.
Equipment usedStick imaged under a hardware write-blocker before anything, so no format or write can occur · the encryption type identified from a PC-3000 assisted image — sound full-disk encryption versus a weaker or vendor scheme with known limitations · any surviving key material, remembered password fragments, or backups of the key searched for · where the encryption is sound and no key survives, an honest statement that the data is sealed, and confirmation that formatting is destructive.
// the decode

The decode

Formatting would indeed destroy the data, so her instinct to ask first is right. The advice she received is technically true — formatting the stick would give a usable device but erase the encrypted contents. Her reluctance to accept that without checking is exactly the correct instinct, because formatting is the one irreversible step, and it should never be taken while any recovery avenue remains unexplored. Preserving the stick as-is keeps every option open.

The honest headline is that sound encryption with no keys is unrecoverable, and that must be said. Strong encryption is designed so that without the password or recovery key, the data cannot be reached — that is the entire point of it. When both credentials are genuinely gone, no laboratory technique unlocks it, and any service claiming to break arbitrary encryption is not being truthful. She deserves that plainly, so she does not pay for a false promise.

But two questions are worth answering before accepting the loss, and they can change the outcome. First, the encryption type: not all "encryption" is equally strong. Some vendor schemes, older methods, or weaker implementations have known limitations that a laboratory can sometimes work with, unlike properly-implemented full-disk encryption. Identifying exactly how the stick is encrypted determines whether it falls into the genuinely-unbreakable category or one with a real avenue. That is established from an image before any conclusion.

Second, the keys may not be as lost as they feel. A forgotten password sometimes returns in fragments — a remembered length, a structure, a partial recollection — which, on a small defined space, can be searchable. A "lost" recovery key was written somewhere when the encryption was set up: a saved file, a printout, an account, a note. Searching properly for surviving traces of either credential is genuine work with a real, if uncertain, chance, and it is worth doing before declaring the data gone.

The honest close is delivered without false hope. If the encryption is sound and no key material survives, the truthful answer is that the data is sealed — the same protection that would keep a thief out keeps everyone out — and formatting would only reclaim the device, not the data. If the encryption has a known weakness, or a trace of a key is found, that avenue is pursued fully. Which applies is established honestly, and stated plainly, before any charge.

// on the bench

On the bench

The stick was imaged under a hardware write-blocker before anything, so no format or write could occur. The encryption type was identified from the image — distinguishing sound full-disk encryption from weaker or vendor schemes with known limitations — and any surviving key material, remembered password fragments, or backups of the key searched for. Where the encryption was sound and no key survived, an honest statement was given that the data is sealed, with confirmation that formatting is destructive.

// the outcome

The outcome

Encryption type identified, every surviving trace of a key searched for, and an honest verdict delivered on whether the data is reachable. The diagnostic costs nothing and completes within two working days of arrival, and the quote is one fixed written figure with VAT already in it; if the data can't be brought back, no charge is made. The decode: sound encryption with both keys gone can't be broken — and you were right that formatting would only lose the data. But before accepting that, we confirm the encryption type and hunt for any surviving trace of a key, because that is the one real chance and it deserves checking.

An encrypted drive with the password and recovery key both lost

Don't format the drive — that destroys the data and should be a last resort, only after every recovery avenue is exhausted. Understand the honest limit: sound encryption with no keys can't be broken, so treat any service promising to unlock arbitrary encryption as untrustworthy. But check two things first — the exact encryption type, since some weaker schemes have real avenues, and any surviving trace of the recovery key, which was written somewhere when you set it up. Preserve the drive untouched while those are explored.

Sending this in from Swansea? Every case opens with the free diagnostic — completed within 2 working days of your media arriving — and one fixed written quote before any work: logical jobs run no fix, no fee; invasive drive-opening work takes 50% of the quote upfront; forensic-classed work is payable upfront in full. If the data is inside a laptop, PC, Mac or server, remove the hard drive or SSD and send us just the drive; we don’t provide an internal drive-removal service, and we don’t recover storage soldered to a motherboard (e.g. Apple Silicon Macs) — only drives that can be removed and sent to us. Post or courier tracked and insured to Bristol Data Recovery, Castlemead, Lower Castle Street, Bristol, BS1 3AG — full sending instructions and the shipping form are here.
Start a free diagnostic

Our case files are written up from genuine enquiries our lab has handled for customers across Swansea and South Wales, anonymised to protect client confidentiality. Each one describes the diagnostic and recovery approach our engineers apply to that fault, using the equipment listed.

// related case files

More cases like this one

Browse all case studies →

Got a device with a story like this?

Free diagnostic, fixed quote, no fix no fee — start now or call the freephone.