Data Recovery Case File · Solid State & Flash · The Container Is Intact
Locked Out by an Update
His enquiry described a lockout with an unusual cause. A password-protected SanDisk memory stick: "the software updated and I can no longer access my files. It still says there is content there, but I can't access it. It's a password protected device and nothing is working." Two details are encouraging and worth separating from the frustration. The stick still reports that content exists, which means the device is healthy and the encrypted container is present. And the cause is a software change rather than a failure — which puts this in a different category from a broken stick, and one where the answer depends almost entirely on a single question: does he still have the password?
| Media | SanDisk USB flash drive with vendor password protection — device enumerating and reporting content; encrypted volume no longer accessible following a software update |
| Reported situation | Stick protected by manufacturer security software · access lost following a software update · device still reporting stored content · password protection in place · access attempts unsuccessful |
| Fault class | Access-layer failure over an intact encrypted container — vendor software compatibility rather than device or data fault; credential required |
| Equipment used | Device imaged write-blocked before any access attempt · encrypted container located and its format identified on the image · unlock strictly against the owner's own credential · contents verified by opening |
The decode: how these sticks work, and what an update broke
What password protection on a stick usually is: not a feature of the hardware but a vendor application shipped on the device. It creates an encrypted container — sometimes a separate partition, sometimes a large file — and the application prompts for a password, decrypts on the fly, and presents the contents as a drive. The stick itself is an ordinary flash device; the protection is software sitting on top.
Why an update breaks it: several ways, all of them mundane. The vendor's application may have been updated to a version that no longer opens containers made by the old one. The operating system may have been updated to a version the old application will not run on — a very common cause where 32-bit applications stopped being supported. Or the application may have been removed during an upgrade and the replacement does not recognise the container. In every one of those, nothing has happened to the data. The lock is intact, the contents are intact, and the key-turning mechanism has stopped working.
Why "it still says there is content there" matters: it confirms the device is enumerating, reporting its capacity and presenting a volume — so power, controller and memory are all fine. This is not a failing stick. It is a working stick whose front door has been changed.
What the answer depends on: the password. If he has it, this is very tractable: the encrypted container can be identified on an image, and opened against his own credential using tooling appropriate to that container format rather than the broken application. If he does not have it, the honest position is a wall — the container is encrypted, and this bench turns lawfully-held keys only. No bypass exists and none is offered.
Two things worth trying first, free: installing an older version of the vendor application, which frequently opens containers a newer one refuses; and trying the stick on an older machine or an older operating system, where the original application still runs. Both are ordinary compatibility remedies and both cost nothing.
What not to do: reformat it, accept any offer to initialise it, or run repair tools. The container is a structure on the device, and anything that writes over it removes the thing that is being recovered. And the stick should not be used for anything else in the meantime.
On the bench
The device was imaged write-blocked before any access attempt, so that every subsequent step happened against a copy and no application could write to the original. The encrypted container was located on the image and its format identified — distinguishing a separate protected partition from a container file, since the two are opened differently — and unlocking ran strictly against the owner's own credential using tooling appropriate to that format rather than the application that had stopped working. The contents were verified by opening.
The outcome
The container located and identified on a write-blocked image, opened against the owner's own password and the contents verified. Free assessment, one fixed written figure including VAT; where a chip has to be removed, 50% of parts and labour is payable upfront with the balance only on success — otherwise no recovery, no fee. The decode, for anyone locked out by an update: password protection on a memory stick is usually a vendor application creating an encrypted container rather than a hardware feature, so an update that changes the application, or an operating system that will no longer run it, breaks the access while leaving the lock and the contents entirely intact; the device still reporting content confirms it is healthy. Try an older version of the software or an older machine first, and never reformat it.
Encrypted stick that stopped opening after an update
Nothing has happened to your files — try the compatibility routes first, because they're free. Password protection on a memory stick is nearly always a vendor application that creates an encrypted container on an otherwise ordinary flash device, so what breaks is the software rather than the data. An updated application may refuse containers made by an older version, and an updated operating system may simply not run the old application at all, which is very common where older software stopped being supported. Install an older version of the vendor's tool if you can find it, or try the stick on an older computer. The fact that it still reports content is genuinely good news: the device is healthy and the container is intact. Don't reformat it, don't accept any offer to initialise, and make sure you still know the password.
Try an older version of the software first — then call Newcastle Data Recovery on 0191 406 1051; imaged write-blocked, container identified on the copy, opened with your own password only.
Request a quote online →
Our case files are drawn from genuine enquiries received by our laboratory over the past ten years, anonymised to protect client confidentiality. Each one describes the diagnostic and recovery procedure our engineers apply to that fault, using the equipment listed.