Call us — 0191 406 1051
Mon–Fri · 9am–5:30pm · No fix, no fee
Start a free diagnostic →

Data Recovery Case File · Solid State & Flash · The Lock Works, the Room Does Not

The Encryption Is Fine and the Filesystem Is Not

This enquiry came from an IT professional acting for a client and it separates two things that are usually confused. An encrypted solid-state drive: "we are able to see the drive on Windows and Mac, and can unlock the drive, but we are unable to access any data. We cannot turn off the encryption either. Seems like a non-hardware issue and we could wipe and reset, but the owner would quite like the data to be recovered." Unlocking successfully is the most important fact in the message — it proves the key is correct and the encryption layer is working, which means the damage is somewhere else entirely.

MediaNVMe solid-state drive with full-volume encryption — unlocking successfully with the correct credential; no contents accessible; decryption also failing to proceed
Reported situationDrive detected on multiple platforms · encryption unlocking successfully · no data accessible after unlock · decryption unable to be turned off · hardware fault not suspected · owner requiring the contents rather than a reset
Fault classFilesystem damage within a functioning encrypted volume — encryption layer intact, structures beneath it unreadable
Equipment usedNo wipe, reset or decryption attempted on the original · volume unlocked and imaged at block level in its decrypted state · structures rebuilt on the image including surviving backup copies · signature carving alongside · files validated by opening

The decode: two layers, and which one failed

What an encrypted volume actually is: two things stacked. The encryption layer sits underneath, turning ciphertext into plaintext as data passes through, and it is what the password or key operates on. The filesystem sits on top of that, inside the decrypted space, describing where files are. Both must work for anything to be readable, and they fail independently.

Why unlocking successfully is such a strong finding: it means the credential is right, the volume's encryption metadata is intact, and the layer is doing its job. Every case in this archive where an encrypted drive could not be opened turned on the key being unavailable — and here the key is fine. That eliminates the entire category of problem people fear most about encryption.

So what has failed: the filesystem inside. Once unlocked, the system presents a volume and reads its structures — and finds them unreadable. That is the same fault as any damaged volume on any unencrypted drive; it simply happens to be sitting behind a lock that works perfectly.

Why the decryption will not turn off, and this fits rather than being a second problem: decrypting a volume means reading every region and writing it back in the clear. That process needs to traverse the volume, and it cannot do so while the structures describing it are damaged — so it declines to start or fails immediately. The inability to decrypt is a symptom of the filesystem damage, not an additional fault.

What that makes this, practically: a straightforward filesystem reconstruction with one extra step. The volume is unlocked, imaged at block level in its decrypted state — so the image is plain data with no encryption to work around — and the structures are then rebuilt against that image exactly as they would be on any other drive. Filesystems keep backup copies of their key structures at known positions, which is what usually returns files with folders and names intact.

Why the reset must not happen first: the suggestion to wipe and reset is entirely reasonable from a support perspective and it is the one thing that would end this. Everything above depends on the encrypted volume remaining as it is, with its metadata and its key relationship intact.

The one thing worth confirming before starting: that the recovery key is recorded somewhere independent of the machine, so that if anything interrupts the process the volume can be unlocked again.

On the bench

No wipe, reset or decryption was attempted on the original — the decryption failing being a symptom of the filesystem damage rather than a separate fault, and a reset being the one action that would end the case. The volume was unlocked with the owner's credential and imaged at block level in its decrypted state, so that the working image was plain data with no encryption layer to traverse repeatedly. Structures were rebuilt on the image including their surviving backup copies, with signature carving alongside, and files validated by opening.

The outcome

The volume unlocked and imaged in its decrypted state, structures rebuilt against the image and files validated. Free assessment, one fixed written figure including VAT; where a chip has to be removed, 50% of parts and labour is payable upfront with the balance only on success — otherwise no recovery, no fee. The decode, for anyone whose encrypted drive unlocks and shows nothing: those are two separate layers and only one has failed. Unlocking proves the key is right and the encryption metadata is intact, which removes the problem people most fear. What is damaged is the filesystem inside the decrypted space — an ordinary reconstruction that happens to sit behind a working lock. The decryption refusing to run is a symptom of that, not another fault.

Encrypted drive that unlocks but shows no files

Don't wipe and reset it — that's the reasonable-sounding suggestion that would end this, and everything depends on the volume staying as it is. Take real encouragement from the unlock working: an encrypted volume is two layers stacked, with the encryption underneath and the filesystem inside the decrypted space, and they fail independently. Unlocking successfully proves your key is correct and the encryption metadata is intact, which removes the entire category of problem people fear most about encryption. What's damaged is the filesystem inside — an ordinary reconstruction that happens to sit behind a working lock. And the decryption refusing to switch off fits that: turning it off means traversing the whole volume, which it can't do through damaged structures.

Encrypted volume that opens onto nothing?
Don't reset it — call Newcastle Data Recovery on 0191 406 1051; unlocked and imaged in its decrypted state, structures rebuilt against the image, files checked by opening.
Request a quote online →

Our case files are drawn from genuine enquiries received by our laboratory over the past ten years, anonymised to protect client confidentiality. Each one describes the diagnostic and recovery procedure our engineers apply to that fault, using the equipment listed.