Data Recovery Case File · Trust, Practice & Honest Limits · The Honest No, With One Lead
Encryption Nobody Switched On
His enquiry describes something that happens to people who never chose it. After an update, his laptop restarted and asked for a recovery key: "I had never heard of this before and was unaware that it was on the laptop. I have since checked and can see that both the internal SSD and the second hard drive are locked. I have searched every account I can think of associated with the family, but I cannot find my recovery key. The laptop was purchased second-hand five years ago as an ex-display model." He also asks whether we can bypass it. The answer to that is no, and it will be no everywhere — but there is one lead in his message that he has not spotted, and it is the best chance he has.
| Media | Laptop with two internal drives, both protected by full-disk encryption — recovery key demanded following a system update; key not held by the owner |
| Reported situation | Encryption enabled without the owner's knowledge · system update triggering a recovery key prompt on restart · both internal drives locked · owner unable to locate a key across known accounts · machine acquired second-hand as an ex-display unit |
| Fault class | Cryptographic lock with key unavailable to the owner — no defect present; enrolment likely predating the owner's possession |
| Equipment used | Drive health verified independently of the lock · encryption state confirmed · no bypass attempted or offered · imaging held pending production of a valid key |
The decode: why it switched itself on, and where the key probably is
Why encryption was on without him choosing it: modern systems enable device encryption automatically on supported hardware, typically the first time an account signs in. There is no prompt, no ceremony and nothing to agree to. The key is then stored automatically in whichever online account was used at that moment. So an owner can use a machine for years without knowing it is encrypted, because the storage unlocks silently at every boot.
Why an update triggered it: the key is held in the machine's security chip, which releases it only when the boot environment matches what it recorded at enrolment. A firmware or system update changes that environment — and the chip, doing precisely its job, declines to release the key and falls back to asking for the recovery key instead. Nothing is broken. The machine is behaving correctly and inconveniently.
The lead he has not spotted, and it is the important part: he bought the laptop second-hand, as an ex-display model. If encryption enrolled itself when an account first signed in, that may have happened before he owned it — in the shop, on a display unit, under a retailer's or a previous owner's account. That would explain perfectly why the key is in none of his family's accounts. It is worth contacting the seller or the retailer and asking whether the machine was ever signed in before sale, and whether they hold a recovery key against that serial number. It is a long shot after five years, but it is a real one and nobody has suggested it to him.
The other places to look, properly: the recovery-key page of every account he has ever used, including old and abandoned ones, checked directly rather than from memory — keys are listed against device names and serial numbers, so an unfamiliar account may still hold his. Any printed copy filed at purchase. And, if the machine was ever used for work or study, the organisation's IT directory, which stores keys centrally.
Why the second drive is worth a separate look: a secondary data drive is often protected with its own key, sometimes with an automatic unlock tied to the system drive, and occasionally not encrypted at all. It should be assessed separately rather than assumed lost with the first.
Why no bypass exists: the data is mathematically transformed and the key is the only route back. There is no defect to exploit — the encryption is working exactly as designed, which is the entire point of it. Anyone offering to break it is describing something they cannot do. No bypass is attempted or offered here.
On the bench
Drive health was verified independently of the lock, since a locked drive and a failing drive are different problems and the distinction matters if a key is later found. The encryption state was confirmed on both drives, and the secondary drive assessed separately rather than assumed to share the fate of the system drive. No bypass was attempted or offered. Imaging was held pending production of a valid key, so that the moment one is found the drives are known-healthy and ready.
The outcome
Drive health confirmed, both volumes assessed separately and the position stated plainly with no bypass attempted or offered. Free assessment, and no charge where no recovery is possible. The decode, and the honest answer: modern systems switch on device encryption automatically when an account first signs in, with no prompt — and the key goes to that account. An update changes the boot environment, so the security chip declines to release it and asks for the recovery key instead; nothing is broken. If the machine was bought second-hand or ex-display, the enrolment may predate your ownership, which is why the key is in none of your accounts — ask the seller or retailer against the serial number. Without the key there is no bypass, here or anywhere.
Recovery key demanded for encryption you never enabled
If you bought the machine second-hand or ex-display, contact the seller — that's the lead most people miss. Modern systems turn on device encryption automatically the first time an account signs in, with no prompt and nothing to agree to, and the key is stored in whichever account was used at that moment. If that happened in a shop, on a display unit, before you owned it, the key sits in someone else's account and no amount of searching your own will find it. Ask the retailer whether they hold a key against the serial number. Meanwhile check the recovery-key page of every account you've ever used, including abandoned ones, since keys are listed by device name. Have any second drive assessed separately, as it may have its own key or none. And be wary of anyone offering to bypass it, because nobody can.
Check where the machine came from — call Newcastle Data Recovery on 0191 406 1051; drive health verified independently of the lock, both drives assessed separately, no bypass attempted or offered.
Request a quote online →
Our case files are drawn from genuine enquiries received by our laboratory over the past ten years, anonymised to protect client confidentiality. Each one describes the diagnostic and recovery procedure our engineers apply to that fault, using the equipment listed.