Data Recovery Case File · Trust, Practice & Honest Limits · One Place Left to Look
Where a Recovery Key Was Probably Saved
This enquiry carries as much weight as any in the archive and asks for something that may not be possible. An encrypted USB stick: "I locked it using encryption years ago, I don't know the password and have a different laptop so I can't do the recovery thing — my work IT team did try and find it for me. The stick has all my family photos on including all my son's baby photos, so without this the last 10 years of photos are gone." Without the key there is no way in, and nobody can change that. But there is a specific place that key was almost certainly written when the stick was encrypted, and it is not one she has searched.
| Media | USB flash drive protected by full-volume encryption enabled several years previously — password not known; recovery key not located; approximately ten years of family photographs held |
| Reported situation | Stick encrypted by the owner several years ago · password not remembered · original machine no longer in use · workplace IT directory searched without result · family photographs spanning approximately ten years held |
| Fault class | Cryptographic lock with the key not in the owner's possession — no defect present; access contingent on producing a valid recovery key |
| Equipment used | Device health verified independently of the lock · encryption state confirmed · no bypass attempted or offered · imaging held pending production of a valid key |
The decode: what happened when she encrypted it, and where to look
What the process required at the time: this is the lead. Encrypting removable media does not simply ask for a password — it generates a recovery key and requires you to save it before it will proceed. There is no way to complete the process without doing something with that key. The options presented are typically to save it to a file, print it, or store it in an online account, and the default action for most people in a hurry is to save it to a file and move on.
So where that file will be: on the machine she used to encrypt the stick. It is a plain text file with a distinctive automatic name — the words that describe what it is, followed by a long identifier — and it will have gone to whatever folder was offered by default, most often Documents or the Desktop. She would have no reason to remember saving it, because it was a step to be got past rather than a thing she wanted.
Which makes the old laptop the object of the search: if she still has it, or has sold it, or has any backup of it, or migrated its contents to the current machine when she changed over, that file may still exist. Searching by the first word of that standard filename across every drive, every backup and every cloud folder she has is the single most promising action available — and it costs an evening.
The other places worth checking properly: any online account she was signed into on that machine, since storing the key to an account is one of the offered options and is silent afterwards. Printouts filed with documents. And email, since some people mail the key to themselves.
Why the workplace search covered less than it seems: keys are escrowed to an organisation's directory only when the volume is encrypted on a managed device under that organisation's policy. If she encrypted a personal stick on a personal machine, no key would ever have gone there — so their search failing does not close the question, it only rules out that one route.
The honest part, stated plainly: if no key is found, the position is final. The photographs are mathematically transformed and the key is the only route back. There is no defect to exploit, because the encryption is working exactly as designed. No bypass is attempted or offered here, and anyone claiming otherwise is describing something that cannot be done.
What is worth doing regardless: having the stick's health verified, so that if a key does turn up in a month the device is known to be readable and ready.
On the bench
Device health was verified independently of the lock, so that a key produced later would meet a device known to be readable rather than a second problem. The encryption state was confirmed. No bypass was attempted or offered. Imaging was held pending production of a valid recovery key, and the search was directed at the machine used to perform the original encryption — since the process requires a key to be saved before it will proceed, and a file is the default way most people satisfy that.
The outcome
Device health confirmed, the position stated plainly and no bypass attempted or offered. Free assessment, and no charge where no recovery is possible. The decode, and the lead worth pursuing: encrypting removable media generates a recovery key and will not proceed until you save it — so a key was created and stored somewhere at the time, most often as a plain text file with a standard automatic name, in whatever folder was offered by default. Search the machine you encrypted it on, and any backup or migration of it. A workplace directory only holds keys from managed devices, so that search rules out one route rather than all of them.
Encrypted drive with no password and no key
Search the computer you encrypted it on — that's the lead most people miss. The process doesn't just ask for a password: it generates a recovery key and won't let you continue until you've saved it, and the quickest option, which almost everyone takes, is saving it to a file. That file has a standard automatic name — a short description followed by a long identifier — and goes to whatever folder was offered by default, usually Documents or the Desktop. You'd have no reason to remember doing it. So look on that machine, any backup of it, anywhere its contents were migrated, and any cloud folder that synced from it. Also check any online account you were signed into then. A workplace directory only holds keys from managed devices.
Search the machine you encrypted it on — or call Newcastle Data Recovery on 0191 406 1051; device health verified independently of the lock, no bypass attempted or offered, free assessment.
Request a quote online →
Our case files are drawn from genuine enquiries received by our laboratory over the past ten years, anonymised to protect client confidentiality. Each one describes the diagnostic and recovery procedure our engineers apply to that fault, using the equipment listed.