
Encrypted SSD: When Data Can and Cannot Be Recovered
Encrypted SSD: When Data Can and Cannot Be Recovered
Most modern SSDs are encrypted – possibly yours too, without you knowing. On many Samsung, Crucial and Intel models, hardware encryption runs automatically in the background.
Encryption protects your data from unauthorised access. But it has a dark side: if the drive fails and you don't have a recovery key, your data may be lost for good.
Types of SSD encryption
Hardware encryption (SED – Self-Encrypting Drive)
What it is: The SSD encrypts all data automatically, directly in its controller, using AES-256. It is always active, even if you never enabled encryption.
How it works:
- Data is encrypted on write and decrypted on read
- The encryption key is stored in the controller
- It is transparent to the user (you don't see it)
Common in:
- Samsung (EVO, PRO series)
- Crucial (MX series)
- Intel enterprise SSDs
- Most NVMe drives
Consequence for recovery: If the controller fails, the encryption key may be lost. Even though the data physically still exists on the NAND chips, it is unreadable without the key.
Software encryption
BitLocker (Windows 10/11 Pro, Enterprise)
- Encryption at operating system level
- Key bound to the TPM (Trusted Platform Module) or a password
- The recovery key can be saved to your Microsoft account
FileVault (macOS)
- Default encryption on Mac computers
- Key bound to your Apple ID or a local recovery key
- Enabled automatically on newer Macs
VeraCrypt (cross-platform)
- Open source, successor to TrueCrypt
- Full user control
- Rescue disk for emergencies
LUKS (Linux)
- Standard for Linux systems
- Full-drive or partition encryption
Hardware and software combined
Some systems use both:
- The SSD has hardware encryption
- BitLocker or FileVault is added on top
Consequence: Double encryption means double the problems during recovery. You need both keys.
Not sure whether your drive is encrypted?
Many users don't realise their drive is encrypted. Here's how to check.
Windows – BitLocker
- Open Control Panel → System and Security → BitLocker Drive Encryption
- Or type "BitLocker" into the search box
- You'll see the status of each drive
Alternatively, from the command line:
manage-bde -status
macOS – FileVault
- System Settings → Privacy & Security → FileVault
- You'll see whether FileVault is turned on
Alternatively, in Terminal:
fdesetup status
Hardware encryption
Detecting hardware encryption is more difficult:
- Check the specifications of your SSD model
- Most modern SSDs have it built in
Practical test: If your SSD shows no visible encryption (BitLocker/FileVault off) but the manufacturer lists "hardware encryption" or "SED", it is active on your drive.
When data recovery IS possible
Scenario 1: The controller works and you have the password
Situation: The SSD works and you can enter the password or PIN.
Solution: Standard recovery, as with an unencrypted drive. Encryption is not an obstacle.
Chances: High (depending on other factors)
Scenario 2: Firmware problem and you have the recovery key
Situation: The drive isn't visible because of a firmware problem. You have saved your recovery key.
Procedure:
- We regain access to the drive at firmware level using specialised tools
- The drive is unlocked with your recovery key
- The data is accessible again
Chances: High
Scenario 3: Software encryption and a readable drive
Situation: The drive works physically, but the system won't boot. You have the recovery key.
Procedure:
- We connect the drive as a secondary drive
- It is unlocked with your recovery key
- We copy the data
Chances: Very high
When data recovery is IMPOSSIBLE
Hardware encryption + dead controller + no key
Situation: The controller is dead. Hardware encryption was active. The key was stored in the controller.
Problem:
- The key existed only in the controller
- Dead controller = lost key
- Chip-off yields only encrypted (unreadable) data
Result: The data exists but is permanently unreadable without the key.
CANNOT BE BYPASSED – AES-256 cannot be broken with today's technology.
BitLocker/FileVault + lost recovery key
Situation: The system asks for the recovery key, but you don't have it.
Problem:
- The recovery key is the only way to unlock the data
- Neither Microsoft nor Apple can restore it
- There is no "back door"
Result: The data is permanently inaccessible.
CANNOT BE BYPASSED – the encryption is working exactly as intended.
TPM-bound encryption + faulty TPM
Situation: The BitLocker key was bound to the TPM chip. The TPM is faulty or has been cleared.
Problem:
- The key existed only in the TPM
- Faulty TPM = lost key
- No decryption is possible without the key
CANNOT BE BYPASSED
Recovery keys – CRITICALLY IMPORTANT
When something goes wrong with an encrypted drive, the recovery key is your only lifeline. Without it, the data is lost.
BitLocker recovery key
Where to find it:
Microsoft account – if you were signed in
- Visit: account.microsoft.com/devices/recoverykey
Azure AD – company computers
- Contact your IT department
USB flash drive – if you saved it there
- Look for a file with the .BEK extension
Printout – if you printed it
- 48-digit numeric code
Active Directory – domain environments
- Your IT administrator has access
FileVault recovery key
Where to find it:
iCloud – if you chose to store it there
- appleid.apple.com → Sign in → Devices
Printout – if you printed it when enabling FileVault
MDM system – company Macs
- Contact your IT department
VeraCrypt
Where to find it:
Rescue disk – did you create one when encrypting?
- Saved as an ISO file or burned to CD
Header backup – if you created one
What to do NOW (prevention)
If you're reading this article without an acute problem, you have a chance to prepare.
1. Find out whether you use encryption
Use the guides above to find out what is active on your computer.
2. Find your recovery key
- Sign in to your Microsoft or Apple account
- Check whether the key is stored there
- If not, find out where it is
3. Store the recovery key in several places
We recommend:
- Cloud (Microsoft/Apple account)
- A printout in a safe
- A USB drive kept in a secure place
- A password manager
NEVER:
- Only on the encrypted drive itself (dead end)
- Only a single copy
4. Test the recovery key
Make sure the key works:
- Try unlocking the drive with the recovery key (not the password)
- Verify that you have the correct key
5. Document it
Keep a record of:
- Which encryption you use
- Where the recovery keys are stored
- The date of the last check
Corporate environments
In companies, managing encryption keys is critical. Our recommendations:
Central key management
- Azure AD for BitLocker
- Jamf for FileVault
- Automatic key escrow on activation
Escrow policies
Set up policies so that recovery keys are saved automatically to a central location.
MDM solutions
Mobile Device Management systems (Intune, Jamf, Kandji) enable:
- Remote encryption management
- Central key storage
- Audit logs
IT should have access
Make sure IT can obtain the recovery key for every company device. Otherwise, an employee leaving can mean lost data.
Practical examples
Successful recovery
Situation: A customer sent us an SSD with a firmware problem. The drive wasn't visible in the system. BitLocker was active.
What the customer had:
- The recovery key, saved in their Microsoft account
Procedure:
- Diagnostics – firmware problem identified
- Firmware-level work using PC-3000 SSD
- Drive visible again
- Drive unlocked with the customer's recovery key
- Data accessible and copied
Result: All data recovered
Unsuccessful recovery
Situation: A Samsung SSD with hardware encryption. The controller was completely dead.
Problem:
- The key was stored only in the controller
- The controller could not be brought back to life
- Chip-off was possible, but the data would still be encrypted
Result:
- Chip-off would yield only encrypted, unreadable data
- Recovery impossible
Lesson:
- Backups are the only real protection
- For hardware-encrypted SSDs, controller failure is fatal
FAQ
Can encryption be "bypassed" or "cracked"?
No. Modern encryption (AES-256) cannot be broken with today's technology. There are no "back doors" for manufacturers, the police or us.
Is hardware encryption more secure?
From a security perspective, yes – the key never leaves the controller. From a data recovery perspective, it's worse – if the controller fails, the key may be lost.
What if I don't know the password but have the recovery key?
The recovery key overrides the password. With the recovery key you can unlock the drive even without knowing the password.
Can DataHelp find out my recovery key?
No. Only whoever saved the recovery key knows it. Neither Microsoft, Apple nor we can "find" or "restore" it.
Should I disable encryption because of the risk?
No. Encryption protects your data from theft or loss. The right approach is:
- Keep your recovery key stored safely
- Make regular backups
Need to recover data from an encrypted SSD?
If you have the recovery key, the situation can usually be solved. If not, we can at least determine whether there is another way.
Register your case online – the initial assessment is free and you receive a binding quote before any recovery work starts. No Data, No Fee.
Email: info@datahelp.eu